A Windows XP help forum. PCbanter

If this is your first visit, be sure to check out the FAQ by clicking the link above. You may have to register before you can post: click the register link above to proceed. To start viewing messages, select the forum that you want to visit from the selection below.

Go Back   Home » PCbanter forum » Microsoft Windows XP » Windows XP Help and Support
Site Map Home Register Authors List Search Today's Posts Mark Forums Read Web Partners

Unknown download activity in background - how to determine what it is?



 
 
Thread Tools Display Modes
  #1  
Old July 28th 07, 08:51 AM posted to microsoft.public.windows.mediacenter,microsoft.public.windowsxp.general,microsoft.public.windowsxp.help_and_support,microsoft.public.security.virus
Doc
external usenet poster
 
Posts: 95
Default Unknown download activity in background - how to determine what it is?

I'm using WinXP Media Center, the last few days I've noticed that
there's some kind of d/l actitivity showing even when I'm doing
nothing online even with the Windows firewall up as well as
ZoneAlarm. I'm on 56k dialup. How do I determine what this is? I
don't have Windows update on automatic. I ran AdAware with the latest
definitions but it's still doing it.

Thanks.

  #2  
Old July 28th 07, 08:58 AM posted to microsoft.public.windows.mediacenter,microsoft.public.windowsxp.general,microsoft.public.windowsxp.help_and_support,microsoft.public.security.virus
Vanguard[_2_]
external usenet poster
 
Posts: 116
Default Unknown download activity in background - how to determine what it is?

"Doc" wrote in message
ups.com...
I'm using WinXP Media Center, the last few days I've noticed that
there's some kind of d/l actitivity showing even when I'm doing
nothing online even with the Windows firewall up as well as
ZoneAlarm. I'm on 56k dialup. How do I determine what this is? I
don't have Windows update on automatic. I ran AdAware with the latest
definitions but it's still doing it.


Use a software firewall that shows you the current connections and level
of traffic. Comodo has a good firewall for free.


  #3  
Old July 28th 07, 09:35 AM posted to microsoft.public.windows.mediacenter,microsoft.public.windowsxp.general,microsoft.public.windowsxp.help_and_support,microsoft.public.security.virus
John[_2_]
external usenet poster
 
Posts: 14
Default Unknown download activity in background - how to determine whatit is?

Vanguard wrote:

Use a software firewall that shows you the current connections and level
of traffic. Comodo has a good firewall for free.



I'm not sure that will show the poster what they want to know. It will
only confirm what they already know surely.

John.
  #4  
Old July 28th 07, 09:48 AM posted to microsoft.public.windows.mediacenter,microsoft.public.windowsxp.general,microsoft.public.windowsxp.help_and_support,microsoft.public.security.virus
Vanguard[_2_]
external usenet poster
 
Posts: 116
Default Unknown download activity in background - how to determine what it is?

"John" wrote in message ...

Vanguard wrote:

Use a software firewall that shows you the current connections and
level of traffic. Comodo has a good firewall for free.


I'm not sure that will show the poster what they want to know. It will
only confirm what they already know surely.


Mine shows which which process (by applications) is using what port and
to where it connects and on what port along with how many bytes came in
or went out. Seems what the OP wants to know.

I'm using the Comodo firewall (free) right now. As I recall when using
the Sygate Pro firewall, it also had decent logging.


  #5  
Old July 28th 07, 10:24 AM posted to microsoft.public.windows.mediacenter,microsoft.public.windowsxp.general,microsoft.public.windowsxp.help_and_support,microsoft.public.security.virus
John[_2_]
external usenet poster
 
Posts: 14
Default Unknown download activity in background - how to determine whatit is?

Vanguard wrote:

Mine shows which which process (by applications) is using what port and
to where it connects and on what port along with how many bytes came in
or went out. Seems what the OP wants to know.

I'm using the Comodo firewall (free) right now. As I recall when using
the Sygate Pro firewall, it also had decent logging.



That's nice to know, thanks.

John.
  #6  
Old July 28th 07, 02:41 PM posted to microsoft.public.windows.mediacenter,microsoft.public.windowsxp.general,microsoft.public.windowsxp.help_and_support,microsoft.public.security.virus
John John
external usenet poster
 
Posts: 3,149
Default Unknown download activity in background - how to determine whatit is?

Surely Zone Alarm should tell you that, doesn't it? Reset all your ZA
rules to allow nothing and start reapplying the rules as asked when
applications want to establish connections.

John

Doc wrote:

I'm using WinXP Media Center, the last few days I've noticed that
there's some kind of d/l actitivity showing even when I'm doing
nothing online even with the Windows firewall up as well as
ZoneAlarm. I'm on 56k dialup. How do I determine what this is? I
don't have Windows update on automatic. I ran AdAware with the latest
definitions but it's still doing it.

Thanks.

  #7  
Old July 28th 07, 02:55 PM posted to microsoft.public.windows.mediacenter,microsoft.public.windowsxp.general,microsoft.public.windowsxp.help_and_support,microsoft.public.security.virus
BoaterDave
external usenet poster
 
Posts: 82
Default Unknown download activity in background - how to determine what it is?

Hi Doc

I've been led to believe that, just like one should only ever have a single
active antivirus programme, one should only have a single software firewall
operative. In other words, disable MS Windows firewall if you are using Zone
Alarm.

HTH

David

__________________________________________________ ____________________________________________
"Doc" wrote in message
ups.com...
I'm using WinXP Media Center, the last few days I've noticed that
there's some kind of d/l actitivity showing even when I'm doing
nothing online even with the Windows firewall up as well as
ZoneAlarm. I'm on 56k dialup. How do I determine what this is? I
don't have Windows update on automatic. I ran AdAware with the latest
definitions but it's still doing it.

Thanks.



  #8  
Old July 28th 07, 03:48 PM posted to microsoft.public.windows.mediacenter,microsoft.public.windowsxp.general,microsoft.public.windowsxp.help_and_support,microsoft.public.security.virus
JW[_2_]
external usenet poster
 
Posts: 2
Default Unknown download activity in background - how to determine what it is?

Could it be Media Center updating your EPG?
If you go to task manager you should be able to see what programs are
consuming CPU power when the downloading occurs.
"BoaterDave" wrote in message
...
Hi Doc

I've been led to believe that, just like one should only ever have a
single active antivirus programme, one should only have a single software
firewall operative. In other words, disable MS Windows firewall if you are
using Zone Alarm.

HTH

David

__________________________________________________ ____________________________________________
"Doc" wrote in message
ups.com...
I'm using WinXP Media Center, the last few days I've noticed that
there's some kind of d/l actitivity showing even when I'm doing
nothing online even with the Windows firewall up as well as
ZoneAlarm. I'm on 56k dialup. How do I determine what this is? I
don't have Windows update on automatic. I ran AdAware with the latest
definitions but it's still doing it.

Thanks.




  #9  
Old July 29th 07, 12:05 AM posted to microsoft.public.windows.mediacenter,microsoft.public.windowsxp.general,microsoft.public.windowsxp.help_and_support,microsoft.public.security.virus
Kayman
external usenet poster
 
Posts: 57
Default Unknown download activity in background - how to determine what it is?

"BoaterDave" wrote in message
...
Hi Doc

I've been led to believe that, just like one should only ever have a
single active antivirus programme,

One should only ever have a single *real- time* AV program, if you wish you
can have several *on-demand* AV apps.
one should only have a single software firewall operative. In other
words, disable MS Windows firewall if you are using Zone Alarm.

Uninstalling ZA would be an even better solution. It's Phoney-Baloney ware;
It gives you a false sense of security.
Go to:
http://www.microsoft.com/technet/tec...s/default.aspx
and scroll down to:
Myth: Host-Based Firewalls Must Filter Outbound Traffic to be Safe.

Then read this:
("...the typical form of outbound protection in client firewalls is just
security theater.)
http://www.microsoft.com/technet/tec...l/default.aspx

And this:
http://www.samspade.org/d/firewalls.html

Read and impelement this:
http://www.ntsvcfg.de/ntsvcfg_eng.html
http://www.dingens.org/index.html.en

And consider implemening Hardening your OS:
http://www.5starsupport.com/tutorial...ng-windows.htm

Good luck


  #10  
Old July 29th 07, 01:40 AM posted to microsoft.public.windows.mediacenter,microsoft.public.windowsxp.general,microsoft.public.windowsxp.help_and_support,microsoft.public.security.virus
John John
external usenet poster
 
Posts: 3,149
Default Unknown download activity in background - how to determine whatit is?

Kayman wrote:


and scroll down to:
Myth: Host-Based Firewalls Must Filter Outbound Traffic to be Safe.


That article itself is baloney. It is true that any malware can
circumvent a firewall's outbound protection but it is also true that a
lot of malware is detected by firewall outbound monitoring. The
outbound monitoring also alerts you when otherwise legitimate software
is trying to call home. Perhaps you like it better when things like
Media player call home without your knowledge, a pesky annoyance that
you should be aware of things like that.

The article states:

"Speaking of host firewalls, why is there so much noise about outbound
filtering? Think for a moment about how ordinary users would interact
with a piece of software that bugged them every time a program on their
computer wanted to communicate with the Internet..." What a pile of
baloney!"

Firewall have rules, it appears no one at Microsoft knows this, which
isn't really surprising to tell you the truth. Microsoft's logic is
that "you don't need seat belts if you have airbags". And you don't
need to know what it is that things like Media Player doing. Baloney
indeed!

John
  #11  
Old July 29th 07, 02:19 AM posted to microsoft.public.windows.mediacenter,microsoft.public.windowsxp.general,microsoft.public.windowsxp.help_and_support,microsoft.public.security.virus
Kerry Brown
external usenet poster
 
Posts: 851
Default Unknown download activity in background - how to determine what it is?

"John John" wrote in message
...
Kayman wrote:


and scroll down to:
Myth: Host-Based Firewalls Must Filter Outbound Traffic to be Safe.


That article itself is baloney. It is true that any malware can
circumvent a firewall's outbound protection but it is also true that a lot
of malware is detected by firewall outbound monitoring. The outbound
monitoring also alerts you when otherwise legitimate software is trying to
call home. Perhaps you like it better when things like Media player call
home without your knowledge, a pesky annoyance that you should be aware of
things like that.

The article states:

"Speaking of host firewalls, why is there so much noise about outbound
filtering? Think for a moment about how ordinary users would interact with
a piece of software that bugged them every time a program on their
computer wanted to communicate with the Internet..." What a pile of
baloney!"

Firewall have rules, it appears no one at Microsoft knows this, which
isn't really surprising to tell you the truth. Microsoft's logic is that
"you don't need seat belts if you have airbags". And you don't need to
know what it is that things like Media Player doing. Baloney indeed!



There is no way a software firewall can guarantee it will stop outbound
traffic on the computer it is running on regardless of the OS. Software
firewalls can be useful for stopping programs communicating outbound through
normal channels. That's it, period. The fact that some firewalls notify you
about malware communicating out is a function of how poorly the malware is
programmed not the firewall. Intel motherboards can communicate though the
onboard NICs at the BIOS level with no OS present. Rootkits can easily
modify all traffic going through any NIC in the computer. Malware running in
Windows can easily corrupt traffic from legitimate programs. Malware can
even create it's own TCP/IP stack and bypass Windows (or other OS')
networking stack altogether. Virtual server software is capable of spoofing
a MAC and getting multiple IP addresses for one NIC from a DHCP server. What
makes you think malware can't do the same type of thing?

--
Kerry Brown
Microsoft MVP - Shell/User
http://www.vistahelp.ca


  #12  
Old July 29th 07, 03:50 AM posted to microsoft.public.windows.mediacenter,microsoft.public.windowsxp.general,microsoft.public.windowsxp.help_and_support,microsoft.public.security.virus
John John
external usenet poster
 
Posts: 3,149
Default Unknown download activity in background - how to determine whatit is?

Kerry Brown wrote:

"John John" wrote in message
...

Kayman wrote:


and scroll down to:
Myth: Host-Based Firewalls Must Filter Outbound Traffic to be Safe.



That article itself is baloney. It is true that any malware can
circumvent a firewall's outbound protection but it is also true that a
lot of malware is detected by firewall outbound monitoring. The
outbound monitoring also alerts you when otherwise legitimate software
is trying to call home. Perhaps you like it better when things like
Media player call home without your knowledge, a pesky annoyance that
you should be aware of things like that.

The article states:

"Speaking of host firewalls, why is there so much noise about outbound
filtering? Think for a moment about how ordinary users would interact
with a piece of software that bugged them every time a program on
their computer wanted to communicate with the Internet..." What a
pile of baloney!"

Firewall have rules, it appears no one at Microsoft knows this, which
isn't really surprising to tell you the truth. Microsoft's logic is
that "you don't need seat belts if you have airbags". And you don't
need to know what it is that things like Media Player doing. Baloney
indeed!



There is no way a software firewall can guarantee it will stop outbound
traffic on the computer it is running on regardless of the OS. Software
firewalls can be useful for stopping programs communicating outbound
through normal channels. That's it, period. The fact that some firewalls
notify you about malware communicating out is a function of how poorly
the malware is programmed not the firewall. Intel motherboards can
communicate though the onboard NICs at the BIOS level with no OS
present. Rootkits can easily modify all traffic going through any NIC in
the computer. Malware running in Windows can easily corrupt traffic from
legitimate programs. Malware can even create it's own TCP/IP stack and
bypass Windows (or other OS') networking stack altogether. Virtual
server software is capable of spoofing a MAC and getting multiple IP
addresses for one NIC from a DHCP server. What makes you think malware
can't do the same type of thing?


All that you say is true and I never said or argued otherwise. But
software firewalls that monitor outbound connections can be useful and
can help to keep some applications in check, just because the Microsoft
firewall can't do it doesn't mean that all others are not good.

John
  #13  
Old July 29th 07, 06:14 AM posted to microsoft.public.windows.mediacenter,microsoft.public.windowsxp.general,microsoft.public.windowsxp.help_and_support,microsoft.public.security.virus
Peter Foldes
external usenet poster
 
Posts: 2,444
Default Unknown download activity in background - how to determine what it is?



--
Peter

Please Reply to Newsgroup for the benefit of others
Requests for assistance by email can not and will not be acknowledged.

"BoaterDave" wrote in message ...
Hi Doc

I've been led to believe that, just like one should only ever have a single
active antivirus programme, one should only have a single software firewall
operative. In other words, disable MS Windows firewall if you are using Zone
Alarm.

HTH

David

__________________________________________________ ____________________________________________
"Doc" wrote in message
ups.com...
I'm using WinXP Media Center, the last few days I've noticed that
there's some kind of d/l actitivity showing even when I'm doing
nothing online even with the Windows firewall up as well as
ZoneAlarm. I'm on 56k dialup. How do I determine what this is? I
don't have Windows update on automatic. I ran AdAware with the latest
definitions but it's still doing it.

Thanks.



  #14  
Old July 29th 07, 09:06 AM posted to microsoft.public.windows.mediacenter,microsoft.public.windowsxp.general,microsoft.public.windowsxp.help_and_support,microsoft.public.security.virus
BoaterDave
external usenet poster
 
Posts: 82
Default Unknown download activity in background - how to determine what it is?

Had you intended to comment, Peter?

Nothing seen here.

BD

******************************
"Peter Foldes" wrote in message
...


--
Peter

Please Reply to Newsgroup for the benefit of others
Requests for assistance by email can not and will not be acknowledged.

"BoaterDave" wrote in message
...
Hi Doc

I've been led to believe that, just like one should only ever have a
single
active antivirus programme, one should only have a single software
firewall
operative. In other words, disable MS Windows firewall if you are using
Zone
Alarm.

HTH

David

__________________________________________________ ____________________________________________
"Doc" wrote in message
ups.com...
I'm using WinXP Media Center, the last few days I've noticed that
there's some kind of d/l actitivity showing even when I'm doing
nothing online even with the Windows firewall up as well as
ZoneAlarm. I'm on 56k dialup. How do I determine what this is? I
don't have Windows update on automatic. I ran AdAware with the latest
definitions but it's still doing it.

Thanks.





  #15  
Old July 29th 07, 08:50 AM posted to microsoft.public.windows.mediacenter,microsoft.public.windowsxp.general,microsoft.public.windowsxp.help_and_support,microsoft.public.security.virus
witan
external usenet poster
 
Posts: 227
Default Unknown download activity in background - how to determine what it is?

On Jul 28, 12:51 pm, Doc wrote:
I'm using WinXP Media Center, the last few days I've noticed that
there's some kind of d/l actitivity showing even when I'm doing
nothing online even with the Windows firewall up as well as
ZoneAlarm. I'm on 56k dialup. How do I determine what this is? I
don't have Windows update on automatic. I ran AdAware with the latest
definitions but it's still doing it.

Thanks.


A long shot: A couple of months back, I had downloaded and installed a
free "flash video player" that was seen on Firefox. The same day, I
found that my Internet account had been drained out, because some 2GB
was "downloaded" in the matter of a few hours, although I had shut
down the program after using it for just a few minutes. I could not
locate any downloaded files even in the "Temporary Internet Files"
folder to account for that size, and my hard disk space was not
decreased. Apparently, the program continued to run in the background
even after I shut it off. When I opened the "Local Area Connection
Status" by clicking on the double-computer icon in system tray area, I
saw that heavy downloading was gong on. I am not absolutely sure that
the Flash Video Player was the culprit, but I after I uninstalled the
program, the unknown internet activity also stopped.
I suggest that you check for something similar on your computer.

 




Thread Tools
Display Modes

Posting Rules
You may not post new threads
You may not post replies
You may not post attachments
You may not edit your posts

vB code is On
Smilies are On
[IMG] code is Off
HTML code is Off






All times are GMT +1. The time now is 10:48 AM.


Powered by vBulletin® Version 3.6.4
Copyright ©2000 - 2024, Jelsoft Enterprises Ltd.
Copyright ©2004-2024 PCbanter.
The comments are property of their posters.