S
Stefan G
Running Windows 7 Ultimate x64
In Task Manager, Networking tab, I see an almost constant stream of inbound
network traffic to my PC and I would like to know what is causing it. There
are other PCs on the LAN but even after rebooting all systems they all show
zero (or nearly zero) traffic except this one that starts pulling in traffic
at a fairly steady pace of 6 megabits/sec. Since I noticed it nearly two
weeks ago, I've been checking it very frequently and it's almost always
there. Sometimes it stops for 60-90 seconds, but then it starts again and
goes for hours before the next pause.
I have no network shares defined on this PC, so all I have are the default
administrative shares. Going to Computer/Manage/Sessions and/or Open Files
shows nothing at all.
I suspect malware, except that the traffic flow is always inbound, never
outbound, at least that I can see. I've updated and run both
SuperAntiSpyware and MalwareBytes, both of which found nothing but a few
tracking cookies (since deleted). I've run 'netstat -a' but I don't see
anything suspicious there.
What can I do next?
I only access the questionable computer remotely, so some of the traffic is
from my remote connection, but certainly not a steady 6Mb in a single
direction. Besides, another Windows 7 PC on the same LAN shows less than
10Kb of network traffic rather than 6Mb. Surely I'm missing something
obvious.
While I was typing this, it stopped for about 55 seconds, but now it has
started up again. After nearly two weeks, it can't be Windows updates or any
other updates since it seems to run nearly constantly 24/7.
Do I need to take packet captures with Wireshark?
In Task Manager, Networking tab, I see an almost constant stream of inbound
network traffic to my PC and I would like to know what is causing it. There
are other PCs on the LAN but even after rebooting all systems they all show
zero (or nearly zero) traffic except this one that starts pulling in traffic
at a fairly steady pace of 6 megabits/sec. Since I noticed it nearly two
weeks ago, I've been checking it very frequently and it's almost always
there. Sometimes it stops for 60-90 seconds, but then it starts again and
goes for hours before the next pause.
I have no network shares defined on this PC, so all I have are the default
administrative shares. Going to Computer/Manage/Sessions and/or Open Files
shows nothing at all.
I suspect malware, except that the traffic flow is always inbound, never
outbound, at least that I can see. I've updated and run both
SuperAntiSpyware and MalwareBytes, both of which found nothing but a few
tracking cookies (since deleted). I've run 'netstat -a' but I don't see
anything suspicious there.
What can I do next?
I only access the questionable computer remotely, so some of the traffic is
from my remote connection, but certainly not a steady 6Mb in a single
direction. Besides, another Windows 7 PC on the same LAN shows less than
10Kb of network traffic rather than 6Mb. Surely I'm missing something
obvious.
While I was typing this, it stopped for about 55 seconds, but now it has
started up again. After nearly two weeks, it can't be Windows updates or any
other updates since it seems to run nearly constantly 24/7.
Do I need to take packet captures with Wireshark?