Networking Forums

Networking Forums > Network Hardware > Network Routers > Router Activity

Reply
Thread Tools Display Modes

Router Activity

 
 
G-Manski
Guest
Posts: n/a

 
      09-29-2005, 05:16 PM
I have a Linksys BEFW11S4 v2.5 router. Why is there always activity,
indicated by the flashing lights on the router, when I know none of my
networked computers are downloading/uploading or exchanging files between
them?

The network connection indicator, next to the clock, always flashes as if I
were on the internet. When I check the status of the connection the "sent"
and "received" numbers are increasing.

I am using Verizon DSL on WinXP (2) computers. One Win 98 machine and a
WinXP Pro machine.

Thanks!


 
Reply With Quote
 
 
 
 
David H. Lipman
Guest
Posts: n/a

 
      09-29-2005, 06:29 PM
From: "G-Manski" <(E-Mail Removed)>

| I have a Linksys BEFW11S4 v2.5 router. Why is there always activity,
| indicated by the flashing lights on the router, when I know none of my
| networked computers are downloading/uploading or exchanging files between
| them?
|
| The network connection indicator, next to the clock, always flashes as if I
| were on the internet. When I check the status of the connection the "sent"
| and "received" numbers are increasing.
|
| I am using Verizon DSL on WinXP (2) computers. One Win 98 machine and a
| WinXP Pro machine.
|
| Thanks!
|

Possible becuase you are infected with malware !

For non-viral malware...

Please download, install and update the following software...

Ad-aware SE v1.06
http://www.lavasoft.de/
http://www.lavasoftusa.com/

SpyBot Search and Destroy v1.4
http://security.kolla.de/

After the software is updated, I suggest scanning the system in Safe Mode.

I also suggest downloading, installing and updating BHODemon for any Browser Helper Objects
that may be on the PC.

BHODemon
http://www.definitivesolutions.com/bhodemon.htm


For viral malware...

Download MULTI_AV.EXE from the URL --
http://www.ik-cs.com/programs/virtools/Multi_AV.exe

It is a self-extracting ZIP file that contains the Kixtart Script Interpreter {
http://kixtart.org Kixtart is CareWare } three batch files, five Kixtart scripts, one Link
(.LNK) file, a PDF instruction file and two utilities; UNZIP.EXE and WGET.EXE. It will
simplify the process of using; Sophos, Trend and McAfee Anti Virus Command Line Scanners to
remove viruses, Trojans and various other malware.

C:\AV-CLS\StartMenu.BAT -- { or Double-click on 'Start Menu' in C:\AV-CLS}
This will bring up the initial menu of choices and should be executed in Normal Mode. This
way all the components can be downloaded from each AV vendor’s web site.
The choices are; Sophos, Trend, McAfee, Exit the menu and Reboot the PC.

You can choose to go to each menu item and just download the needed files or you can
download the files and perform a scan in Normal Mode. Once you have downloaded the files
needed for each scanner you want to use, you should reboot the PC into Safe Mode [F8 key
during boot] and re-run the menu again and choose which scanner you want to run in Safe
Mode. It is suggested to run the scanners in both Safe Mode and Normal Mode.

When the menu is displayed hitting 'H' or 'h' will bring up a more comprehensive PDF help
file.

To use this utility, perform the following...
Execute; Multi_AV.exe { Note: You must use the default folder C:\AV-CLS }
Choose; Unzip
Choose; Close

Execute; C:\AV-CLS\StartMenu.BAT
{ or Double-click on 'Start Menu' in C:\AV-CLS }

NOTE: You may have to disable your software FireWall or allow WGET.EXE to go through your
FireWall to allow it to download the needed AV vendor related files.

* * * Please report back your results * * *



--
Dave
http://www.claymania.com/removal-trojan-adware.html
http://www.ik-cs.com/got-a-virus.htm


 
Reply With Quote
 
Marc
Guest
Posts: n/a

 
      09-29-2005, 09:55 PM
It could be harmless "background" traffic. Before you panic I would suggest
downloading Ethereal - a free network analyzer, this will allow you to
capture the data that is being sent by your PC's network card. If you have
trouble understanding the information once you have captured it, post here
again and I will contact you directly and review the captue for you.

Good luck

Marc
"David H. Lipman" <DLipman~nospam~@Verizon.Net> wrote in message
news:UnW_e.5620$211.3604@trnddc08...
> From: "G-Manski" <(E-Mail Removed)>
>
> | I have a Linksys BEFW11S4 v2.5 router. Why is there always activity,
> | indicated by the flashing lights on the router, when I know none of my
> | networked computers are downloading/uploading or exchanging files
> between
> | them?
> |
> | The network connection indicator, next to the clock, always flashes as
> if I
> | were on the internet. When I check the status of the connection the
> "sent"
> | and "received" numbers are increasing.
> |
> | I am using Verizon DSL on WinXP (2) computers. One Win 98 machine and a
> | WinXP Pro machine.
> |
> | Thanks!
> |
>
> Possible becuase you are infected with malware !
>
> For non-viral malware...
>
> Please download, install and update the following software...
>
> Ad-aware SE v1.06
> http://www.lavasoft.de/
> http://www.lavasoftusa.com/
>
> SpyBot Search and Destroy v1.4
> http://security.kolla.de/
>
> After the software is updated, I suggest scanning the system in Safe Mode.
>
> I also suggest downloading, installing and updating BHODemon for any
> Browser Helper Objects
> that may be on the PC.
>
> BHODemon
> http://www.definitivesolutions.com/bhodemon.htm
>
>
> For viral malware...
>
> Download MULTI_AV.EXE from the URL --
> http://www.ik-cs.com/programs/virtools/Multi_AV.exe
>
> It is a self-extracting ZIP file that contains the Kixtart Script
> Interpreter {
> http://kixtart.org Kixtart is CareWare } three batch files, five Kixtart
> scripts, one Link
> (.LNK) file, a PDF instruction file and two utilities; UNZIP.EXE and
> WGET.EXE. It will
> simplify the process of using; Sophos, Trend and McAfee Anti Virus
> Command Line Scanners to
> remove viruses, Trojans and various other malware.
>
> C:\AV-CLS\StartMenu.BAT -- { or Double-click on 'Start Menu' in C:\AV-CLS}
> This will bring up the initial menu of choices and should be executed in
> Normal Mode. This
> way all the components can be downloaded from each AV vendor's web site.
> The choices are; Sophos, Trend, McAfee, Exit the menu and Reboot the PC.
>
> You can choose to go to each menu item and just download the needed files
> or you can
> download the files and perform a scan in Normal Mode. Once you have
> downloaded the files
> needed for each scanner you want to use, you should reboot the PC into
> Safe Mode [F8 key
> during boot] and re-run the menu again and choose which scanner you want
> to run in Safe
> Mode. It is suggested to run the scanners in both Safe Mode and Normal
> Mode.
>
> When the menu is displayed hitting 'H' or 'h' will bring up a more
> comprehensive PDF help
> file.
>
> To use this utility, perform the following...
> Execute; Multi_AV.exe { Note: You must use the default folder C:\AV-CLS }
> Choose; Unzip
> Choose; Close
>
> Execute; C:\AV-CLS\StartMenu.BAT
> { or Double-click on 'Start Menu' in C:\AV-CLS }
>
> NOTE: You may have to disable your software FireWall or allow WGET.EXE to
> go through your
> FireWall to allow it to download the needed AV vendor related files.
>
> * * * Please report back your results * * *
>
>
>
> --
> Dave
> http://www.claymania.com/removal-trojan-adware.html
> http://www.ik-cs.com/got-a-virus.htm
>
>



 
Reply With Quote
 
G-Manski
Guest
Posts: n/a

 
      09-30-2005, 11:01 PM
I ran AdAware v1.06 and had these items show up: IBIS Toolbar. I found the
registry key for this and tried to delete it. The IBIS would not delete for
me. The IBIS was "owned" by my son. I logged in as him and the registry key
for IBIS was deleted. I ran another AdAware scan and nothing showed up. I
ran an AVG Free edition scan and found a Keenval trojan. I found the
registry key for this and deleted it.

I still have the activity showing on my router. I am not familiar with
"background" traffic. Granted my computer shows no signs of being infected
with anything. The constant activity is annoying and I do not think it is
normal.

I have not tried the Ethereal yet. What does this program actually show me?

Thanks.

"Marc" <(E-Mail Removed)> wrote in message
news:433c62e0$0$49782$(E-Mail Removed)...
> It could be harmless "background" traffic. Before you panic I would

suggest
> downloading Ethereal - a free network analyzer, this will allow you to
> capture the data that is being sent by your PC's network card. If you have
> trouble understanding the information once you have captured it, post here
> again and I will contact you directly and review the captue for you.
>
> Good luck
>
> Marc
> "David H. Lipman" <DLipman~nospam~@Verizon.Net> wrote in message
> news:UnW_e.5620$211.3604@trnddc08...
> > From: "G-Manski" <(E-Mail Removed)>
> >
> > | I have a Linksys BEFW11S4 v2.5 router. Why is there always activity,
> > | indicated by the flashing lights on the router, when I know none of my
> > | networked computers are downloading/uploading or exchanging files
> > between
> > | them?
> > |
> > | The network connection indicator, next to the clock, always flashes as
> > if I
> > | were on the internet. When I check the status of the connection the
> > "sent"
> > | and "received" numbers are increasing.
> > |
> > | I am using Verizon DSL on WinXP (2) computers. One Win 98 machine and

a
> > | WinXP Pro machine.
> > |
> > | Thanks!
> > |
> >
> > Possible becuase you are infected with malware !
> >
> > For non-viral malware...
> >
> > Please download, install and update the following software...
> >
> > Ad-aware SE v1.06
> > http://www.lavasoft.de/
> > http://www.lavasoftusa.com/
> >
> > SpyBot Search and Destroy v1.4
> > http://security.kolla.de/
> >
> > After the software is updated, I suggest scanning the system in Safe

Mode.
> >
> > I also suggest downloading, installing and updating BHODemon for any
> > Browser Helper Objects
> > that may be on the PC.
> >
> > BHODemon
> > http://www.definitivesolutions.com/bhodemon.htm
> >
> >
> > For viral malware...
> >
> > Download MULTI_AV.EXE from the URL --
> > http://www.ik-cs.com/programs/virtools/Multi_AV.exe
> >
> > It is a self-extracting ZIP file that contains the Kixtart Script
> > Interpreter {
> > http://kixtart.org Kixtart is CareWare } three batch files, five Kixtart
> > scripts, one Link
> > (.LNK) file, a PDF instruction file and two utilities; UNZIP.EXE and
> > WGET.EXE. It will
> > simplify the process of using; Sophos, Trend and McAfee Anti Virus
> > Command Line Scanners to
> > remove viruses, Trojans and various other malware.
> >
> > C:\AV-CLS\StartMenu.BAT -- { or Double-click on 'Start Menu' in

C:\AV-CLS}
> > This will bring up the initial menu of choices and should be executed in
> > Normal Mode. This
> > way all the components can be downloaded from each AV vendor's web site.
> > The choices are; Sophos, Trend, McAfee, Exit the menu and Reboot the PC.
> >
> > You can choose to go to each menu item and just download the needed

files
> > or you can
> > download the files and perform a scan in Normal Mode. Once you have
> > downloaded the files
> > needed for each scanner you want to use, you should reboot the PC into
> > Safe Mode [F8 key
> > during boot] and re-run the menu again and choose which scanner you want
> > to run in Safe
> > Mode. It is suggested to run the scanners in both Safe Mode and Normal
> > Mode.
> >
> > When the menu is displayed hitting 'H' or 'h' will bring up a more
> > comprehensive PDF help
> > file.
> >
> > To use this utility, perform the following...
> > Execute; Multi_AV.exe { Note: You must use the default folder

C:\AV-CLS }
> > Choose; Unzip
> > Choose; Close
> >
> > Execute; C:\AV-CLS\StartMenu.BAT
> > { or Double-click on 'Start Menu' in C:\AV-CLS }
> >
> > NOTE: You may have to disable your software FireWall or allow WGET.EXE

to
> > go through your
> > FireWall to allow it to download the needed AV vendor related files.
> >
> > * * * Please report back your results * * *
> >
> >
> >
> > --
> > Dave
> > http://www.claymania.com/removal-trojan-adware.html
> > http://www.ik-cs.com/got-a-virus.htm
> >
> >

>
>



 
Reply With Quote
 
David H. Lipman
Guest
Posts: n/a

 
      09-30-2005, 11:24 PM
From: "G-Manski" <(E-Mail Removed)>

| I ran AdAware v1.06 and had these items show up: IBIS Toolbar. I found the
| registry key for this and tried to delete it. The IBIS would not delete for
| me. The IBIS was "owned" by my son. I logged in as him and the registry key
| for IBIS was deleted. I ran another AdAware scan and nothing showed up. I
| ran an AVG Free edition scan and found a Keenval trojan. I found the
| registry key for this and deleted it.
|
| I still have the activity showing on my router. I am not familiar with
| "background" traffic. Granted my computer shows no signs of being infected
| with anything. The constant activity is annoying and I do not think it is
| normal.
|
| I have not tried the Ethereal yet. What does this program actually show me?
|
| Thanks.

Unless you know how to read a protocol decode, it won't help.

Instead, download TCPVIEW from Sysinternals --
http://www.sysinternals.com/Utilities/TcpView.html

It will show a GUI based, dynamic view, of what program is opeing and communicating on what
port to what site on the Internet.

Based upon your finding the IBIS Tioolbar adware/spyware and a Trojan, the chances are still
high that there are other infectors.

Please download, install and update SpyBot Search and Destroy v1.4
http://security.kolla.de/

And use the the following Multi AV scanner. It is a friont end to; McAfee, Trend Micro and
Sophos AV scanners. None of which need to pre-exist on the PC. I usggest this becuase AVG
often misses amny infectors.

I suggest starting with the McAfee AV module, then Sophos then Trend Micro.

Use of Ad-aware SE, SpyBot S&D and the Multi AV scanning tool should be done on *all*
platforms on the lAN side of the Router.

Download MULTI_AV.EXE from the URL --
http://www.ik-cs.com/programs/virtools/Multi_AV.exe

It is a self-extracting ZIP file that contains the Kixtart Script Interpreter {
http://kixtart.org Kixtart is CareWare } three batch files, five Kixtart scripts, one Link
(.LNK) file, a PDF instruction file and two utilities; UNZIP.EXE and WGET.EXE. It will
simplify the process of using; Sophos, Trend and McAfee Anti Virus Command Line Scanners to
remove viruses, Trojans and various other malware.

C:\AV-CLS\StartMenu.BAT -- { or Double-click on 'Start Menu' in C:\AV-CLS}
This will bring up the initial menu of choices and should be executed in Normal Mode. This
way all the components can be downloaded from each AV vendor’s web site.
The choices are; Sophos, Trend, McAfee, Exit the menu and Reboot the PC.

You can choose to go to each menu item and just download the needed files or you can
download the files and perform a scan in Normal Mode. Once you have downloaded the files
needed for each scanner you want to use, you should reboot the PC into Safe Mode [F8 key
during boot] and re-run the menu again and choose which scanner you want to run in Safe
Mode. It is suggested to run the scanners in both Safe Mode and Normal Mode.

When the menu is displayed hitting 'H' or 'h' will bring up a more comprehensive PDF help
file.

To use this utility, perform the following...
Execute; Multi_AV.exe { Note: You must use the default folder C:\AV-CLS }
Choose; Unzip
Choose; Close

Execute; C:\AV-CLS\StartMenu.BAT
{ or Double-click on 'Start Menu' in C:\AV-CLS }

NOTE: You may have to disable your software FireWall or allow WGET.EXE to go through your
FireWall to allow it to download the needed AV vendor related files.

* * * Please report back your results * * *


--
Dave
http://www.claymania.com/removal-trojan-adware.html
http://www.ik-cs.com/got-a-virus.htm


 
Reply With Quote
 
David H. Lipman
Guest
Posts: n/a

 
      10-01-2005, 03:47 AM
From: "G-Manski" <(E-Mail Removed)>

| I ran AdAware v1.06 and had these items show up: IBIS Toolbar. I found the
| registry key for this and tried to delete it. The IBIS would not delete for
| me. The IBIS was "owned" by my son. I logged in as him and the registry key
| for IBIS was deleted. I ran another AdAware scan and nothing showed up. I
| ran an AVG Free edition scan and found a Keenval trojan. I found the
| registry key for this and deleted it.
|
| I still have the activity showing on my router. I am not familiar with
| "background" traffic. Granted my computer shows no signs of being infected
| with anything. The constant activity is annoying and I do not think it is
| normal.
|
| I have not tried the Ethereal yet. What does this program actually show me?
|
| Thanks.


Another psssibility just hit me like a Mack truck and I down'y know why I didn't think of it
before.

The Linksys BEFW11S4 is a wireless Router. Could it be you failed to secure your wireless
access point and thus you are the victim of "War Driving" and someone is using your wireless
network w/o your knowledge ?

--
Dave
http://www.claymania.com/removal-trojan-adware.html
http://www.ik-cs.com/got-a-virus.htm


 
Reply With Quote
 
GManski
Guest
Posts: n/a

 
      10-04-2005, 01:00 AM
I thought of the wireless being unsecured too. I just logged onto my router
setup and checked. All is secure. I also cranked up my laptop with wireless
and checked the wireless connection and it says "Security enabled wireless
network". The only ports that show the activity when there is none are #1
and #4. They both show the intermittent activity simultaneously. I also
updated the firmware for the router and scoured the Linksys website for
answers but there is no help there. Something else, this happened before
about six months ago. It just stopped one day. Then two weeks ago, after 4-5
months of no unusual activity the same thing starts again. Go figure!!


"David H. Lipman" <DLipman~nospam~@Verizon.Net> wrote in message
news:KFn%e.1490$097.49@trnddc01...
> From: "G-Manski" <(E-Mail Removed)>
>
> | I ran AdAware v1.06 and had these items show up: IBIS Toolbar. I found
> the
> | registry key for this and tried to delete it. The IBIS would not delete
> for
> | me. The IBIS was "owned" by my son. I logged in as him and the registry
> key
> | for IBIS was deleted. I ran another AdAware scan and nothing showed up.
> I
> | ran an AVG Free edition scan and found a Keenval trojan. I found the
> | registry key for this and deleted it.
> |
> | I still have the activity showing on my router. I am not familiar with
> | "background" traffic. Granted my computer shows no signs of being
> infected
> | with anything. The constant activity is annoying and I do not think it
> is
> | normal.
> |
> | I have not tried the Ethereal yet. What does this program actually show
> me?
> |
> | Thanks.
>
>
> Another psssibility just hit me like a Mack truck and I down'y know why I
> didn't think of it
> before.
>
> The Linksys BEFW11S4 is a wireless Router. Could it be you failed to
> secure your wireless
> access point and thus you are the victim of "War Driving" and someone is
> using your wireless
> network w/o your knowledge ?
>
> --
> Dave
> http://www.claymania.com/removal-trojan-adware.html
> http://www.ik-cs.com/got-a-virus.htm
>
>



 
Reply With Quote
 
 
 
Reply

Thread Tools
Display Modes

Posting Rules
You may not post new threads
You may not post replies
You may not post attachments
You may not edit your posts

BB code is On
Smilies are On
[IMG] code is On
HTML code is Off
Trackbacks are On
Pingbacks are On
Refbacks are Off


Similar Threads
Thread Thread Starter Forum Replies Last Post
Monitoring router's activity Wiseman Network Routers 8 04-23-2008 07:41 PM
how to monitor router activity Adams H Wireless Networks 12 04-02-2008 11:42 AM
how to monitor router activity Adams H Windows Networking 12 04-02-2008 11:42 AM
Unplugged all other PCs and router log still shows incoming activity . why?! Joey Wireless Internet 4 03-16-2006 11:51 AM
LAN activity light on router tns1 Wireless Internet 8 05-15-2005 05:18 PM



1 2 3 4 5 6 7 8 9 10 11