Question Background Internet Radiation (Read 897 times)

  • Avatar of Dale Gobbler
  • Meh.
  • PipPipPipPipPipPipPipPip
  • Group: Premium Member
  • Joined: Dec 24, 2003
  • Posts: 2079
I've noticed recently that my internet has constant activity, even when I don't have a browser open, or and kind of updates. The Generic Host Process for Win32 services is constantly active. And I noticed the blocked intrusions in ZoneAlarm keep going up every few seconds. Is there a way I can monitor exactly whats going on, or stop the background activity? I'm still using Dial-up and it's slowing down my internet.
m
ohap
  • Avatar of Chubby Skelly
  • Got the powerup and won the game
  • PipPipPipPipPipPip
  • Group: Premium Member
  • Joined: Apr 4, 2004
  • Posts: 947
Congrats! You're virused or spywared! Get cleaning.

You can use the Windows command "netstat -a" to see where all the connections are being made.
  • Avatar of Dale Gobbler
  • Meh.
  • PipPipPipPipPipPipPipPip
  • Group: Premium Member
  • Joined: Dec 24, 2003
  • Posts: 2079
I ran Spybot and AVG 7.5 (both updated) but nothing came up, any suggestions?
Last Edit: April 13, 2008, 08:54:45 pm by Aztec
m
ohap
  • BAA2U
  • PipPipPipPipPipPipPip
  • Group: Premium Member
  • Joined: Aug 7, 2007
  • Posts: 1403
Did 'netstat -a' show you anything? Doesn't zone alarm tell you where the attacks are coming from? Can you really notice that hit to dial up performance? what happens in safe mode?
Last Edit: April 13, 2008, 09:33:24 pm by goat
  • Avatar of Dale Gobbler
  • Meh.
  • PipPipPipPipPipPipPipPip
  • Group: Premium Member
  • Joined: Dec 24, 2003
  • Posts: 2079
netstat pops up for a split second then closes after listing a couple of things. I haven't seen anything in ZA that tell where attacks come from. It's not so much that it dramatically slows down my internet, but the fact that ZA is show that Generix Host has constant In and Out traffic. I'll try running in safe mode.

EDIT: And about ZA blocking things. I've been online today on and off an hour and a half. During that time about 400 Intrusions have been blocked and 40 of them have been high rated.

EDIT2: Now instead of constant background activity, if I stop all internet processes using ZA, then resume and use my browser to load pages the internet activity stops after the page loads. Then after a couple of minutes of no unwanted activity then it picks back up again. (This isn't in Safe Mode)
Last Edit: April 13, 2008, 09:53:20 pm by Aztec
m
ohap
  • Avatar of Chubby Skelly
  • Got the powerup and won the game
  • PipPipPipPipPipPip
  • Group: Premium Member
  • Joined: Apr 4, 2004
  • Posts: 947
netstat pops up for a split second then closes after listing a couple of things.

Open a shell with "cmd" and then do the netstat in order to be able to actually read it.
  • BAA2U
  • PipPipPipPipPipPipPip
  • Group: Premium Member
  • Joined: Aug 7, 2007
  • Posts: 1403
netstat pops up for a split second then closes after listing a couple of things. I haven't seen anything in ZA that tell where attacks come from. It's not so much that it dramatically slows down my internet, but the fact that ZA is show that Generix Host has constant In and Out traffic. I'll try running in safe mode.

EDIT: And about ZA blocking things. I've been online today on and off an hour and a half. During that time about 400 Intrusions have been blocked and 40 of them have been high rated.

EDIT2: Now instead of constant background activity, if I stop all internet processes using ZA, then resume and use my browser to load pages the internet activity stops after the page loads. Then after a couple of minutes of no unwanted activity then it picks back up again. (This isn't in Safe Mode)

This could be the keepalive signal your modem may be sending to the ISP so you don't timeout?
Last Edit: April 13, 2008, 11:53:27 pm by goat
  • Avatar of Dale Gobbler
  • Meh.
  • PipPipPipPipPipPipPipPip
  • Group: Premium Member
  • Joined: Dec 24, 2003
  • Posts: 2079
I doubt it's just a keepalive signal, because it's never done this before on my old computer. I ran netstat again, but it opened for a split second, so I did a quick Printscreen. It has me established with a(string of numbers ex.64-345-23-43).deploy.akamaitechnologies.com so I'm looking that up right now.

EDIT: Apparently it's not spyware or anything, it's a "giant webhoster, specialised in load-balanced hosting for companies so that you can everdownload (every) files at the best possible speed."
Last Edit: April 14, 2008, 03:08:30 pm by Aztec
m
ohap
  • Avatar of Brown
  • ブラウンの人
  • PipPipPipPipPipPipPip
  • Group: Premium Member
  • Joined: Jul 17, 2004
  • Posts: 1160
after doing netstat -a what can i do to close some of those connections? and also what do they mean  eg. snmp,  ntp, 1900? theres so many too. are they the cause for my slow internet connection?