This is a read-only archive. No new posts or registrations. Privacy Page
Hardware

Unknown sending & receiving of packets

3 min read

This thread's last reply is from . Advice, software, and links below may be out of date — treat specific steps and download links with caution.

Looking for the outcome? Ask AI

My Windows XP Internet Connection Status is showing constant transmitting of packets (sending and receiving). I'm not sure why this is happening and it is causing me concern as even when I'm not browsing or downloading this activity seems to be taking place in the background. I'm using Norton Internet Security, and when I go into security statistics I can see a process called svchost.exe with the address 192.168.1.1.5431 responsible for the constant sending and receiving of these packets. There are actually four instances of the svchost.exe but its only the one I mentioned thats actively transmitting the data. After running netstat -ano | find "5431" I got the following: C:\Documents and Settings\Brian>netstat -ano | find "5431" TCP 192.168.1.101:1048 192.168.1.1:5431 ESTABLISHED 1440 Then after running tasklist /svc I got the following: Image Name PID Services ========================= ====== ==================================­ =========== System Idle Process 0 N/A System 4 N/A SMSS.EXE 952 N/A CSRSS.EXE 1044 N/A WINLOGON.EXE 1080 N/A SERVICES.EXE 1124 Eventlog, PlugPlay LSASS.EXE 1136 PolicyAgent, ProtectedStorage, SamSs ATI2EVXX.EXE 1268 Ati HotKey Poller SVCHOST.EXE 1292 DcomLaunch, TermService SVCHOST.EXE 1404 RpcSs SVCHOST.EXE 1440 AudioSrv, Browser, CryptSvc, Dhcp, dmserver, ERSvc, EventSystem, FastUserSwitchingCompatibility, helpsvc, Irmon, lanmanserver, lanmanworkstation, Netman, Nla, Schedule, seclogon, SENS, SharedAccess, ShellHWDetection, Themes, TrkWks, W32Time, winmgmt, wscsvc, wuauserv EvtEng.exe 1492 EvtEng S24EvMon.exe 1592 S24EventMonitor SVCHOST.EXE 1652 Dnscache SVCHOST.EXE 1800 LmHosts, RemoteRegistry, SSDPSRV, WebClient ZCfgSvc.exe 1836 N/A ATI2EVXX.EXE 1896 N/A EXPLORER.EXE 1952 N/A ccProxy.exe 360 ccProxy ccSetMgr.exe 508 ccSetMgr ISSVC.EXE 520 ISSVC SNDSrvc.exe 612 SNDSrvc SPBBCSvc.exe 624 SPBBCSvc ccEvtMgr.exe 640 ccEvtMgr 1XConfig.exe 1360 N/A SPOOLSV.EXE 1668 Spooler sqlservr.exe 160 MSSQL$SQLEXPRESS NAVAPSVC.EXE 444 navapsvc OProtSvc.exe 396 OwnershipProtocol RegSrvc.exe 584 RegSrvc ALG.EXE 2264 ALG HControl.exe 2556 N/A SOUNDMAN.EXE 2572 N/A ALU.EXE 2588 N/A WCOURIER.EXE 2596 N/A SynTPLpr.exe 2616 N/A SynTPEnh.exe 2624 N/A ccApp.exe 2640 N/A ATIPTAXX.EXE 2652 N/A BatteryLife.exe 2660 N/A iFrmewrk.exe 2696 N/A EOUWiz.exe 2716 N/A gcasServ.exe 2744 N/A MSMSGS.EXE 2756 N/A ATKOSD.EXE 2820 N/A gcasDtServ.exe 3092 N/A SVCHOST.EXE 3524 HTTPFilter NMain.exe 3844 N/A IAMSTATS.EXE 3392 N/A firefox.exe 3056 N/A cmd.exe 392 N/A tasklist.exe 3328 N/A wmiprvse.exe 2528 N/A As you can see, quite a lot seems to be listed under 1440. I hope someone can make sense of this.
Well this one problem here


I'm using Norton Internet Security


svchost.exe is supposed to be there, and usually 4 times. (its when you have like 6 or more that there usually always seems to be an issue). Kerio has a free version (2.0 or .4 ..or both maybe free) if you can find it some were and it will not only show you whats what on which ports but it will also allow you to write a rule and stop it from running..


(betchya if you stop norton that will cease as well)
hi looks like you have a router: 192.168.1.1 this may just be harmless broadcast traffic between your router and computer. they "communicate" all the time.
I do have a router on 192.168.1.1. Its a Linksys WRT54G. I have the MAC Address filtering enabled so only my Notebook can connect. My notebook is wirelessly connected for my internet needs. In terms of the broadcast traffic it occurs when I turn the notebook on, and then stops about 20 minutes later. Is there any way of knowing for sure if it is just harmless broadcast between the notebook and router?
hi beecee,

Is there any way of knowing for sure if it is just harmless broadcast between the notebook and router


short of having a sniffer, no. your router/computers/modem are constantly sending/recieving packets. you have MAC filtering enabled so somebody shouldnt be using your bandwidth. also make sure SPI is on if your router supports it.
do a search for broadcast traffic or ARP protocol if you want to fall asleep fast
————————————————————-

in order to rule out a virus/worm/trojan, do a online scan or two at one of these:

MicroWorld

Bitdefender

Norton

Panda Activescan

TrendMicro

also if you havent already, download, install and update these two:

spybot search and destroy:
http://www.safer-networking.org/en/index.html

ad aware:
http://www.lavasoftusa.com/software/adaware/
As the others have pointed out, there is a normal amount of traffic that any connected computer will recieve and transmit. Most of the time this is harmless broadcast traffic and needed, sometimes not tho.
One useful little tool to see whats connecting or listening is Active Ports
This is a free port sniffer for Windows and is useful for watching any activity in and out of your computer. It allows you to stop any suspicious activity instantly, or just become familiar with what is normal or not.

Dave

Ask AI

AI can make mistakes. Check the cited posts. Archived advice can be out-of-date

Don't include personal information. Questions and selected public posts go to OpenAI. About Ask AI