Forum Home
Press F1
 
Thread ID: 113912 2010-11-09 12:35:00 Uploads gone nuts!!! Coffeeluva (16069) Press F1
Post ID Timestamp Content User
1151690 2010-11-09 12:35:00 Hey guys,

I need some serious help, in the last two weeks my uploads have gone from about 4GB a month to 15GB in one week. Telescum tell me its a problem at my end. But what??

I don't have any P2P programmes, I have AVG and nothing is showing on scans, I have been advised its probably a virus or worm of some description, how do I hunt it out and get rid of it??

Would a system restore back a fair way help?? At a complete loss now. At the moment I have been reduced to dial up speeds but even on that my uploads exceed my downloads but a significant margin.

Thanks for any assistance you can offer.

Coffeeluva (debs)
Coffeeluva (16069)
1151691 2010-11-09 14:37:00 Welcome to PressF1.
Sounds like your computer is being used as a zombie (en.wikipedia.org) and is part of a botnet (en.wikipedia.org).
Download and run HijackThis (en.wikipedia.org) (program link (free.antivirus.com)), run a scan and post it here, Speedy will check and advise.
Don't use System Restore, it's probably infected too, in fact turn it off (to clear your restore points), and turn it back on once the machine is clean.
Remove AVG, and install Microsoft Security Essentials (www.microsoft.com) (much better), also install MalwareBytes (http://www.malwarebytes.org/), and do full scans.
feersumendjinn (64)
1151692 2010-11-09 18:02:00 Don't know that I'd dump System Restore before investigating whether or not the other strategies will work.

If you've got kids in the house, then there's a very strong chance they've done some file sharing, although even then the downloads would typically be higher than the uploads initially.

Do you recognise the purpose of every icon in your taskbar? What have you got running there?
Paul.Cov (425)
1151693 2010-11-09 18:24:00 What are you doing normally that uses and uploads 4GB a month.
Most people would not even use up 4GB for downloads
If you don't have P2P there must be something else in use there to upload 4GB per month.
Anyone gaming, using skype, are you on a wireless connection.
Safari (3993)
1151694 2010-11-09 18:30:00 you could also right click on the task bar and start task manager then look through the application and processes list for anything obviously dodgy. the hijack this scan as suggested would show this up also but this is something easy you can do yourself.

If anyone has installed any p2p software unknown to yourself it could be running in the background sharing stuff. Otherwise something more malicicous as suggested.

Another place to look is the add / remove program list in control panel ( just called Unistall a program under WIN7 ) look thorugh it for any programs that shouldn't be there - will only work for properly installed software of course not virus's etc.
dugimodo (138)
1151695 2010-11-09 19:45:00 I okay, I have a wireless network at home here, my daughter spends a lot of time on Facebook and youtube, I mean a lot.

The p2p programme that was on the computer was frostwire, however I removed that when I was first trouble shooting this issue.

When is was installed uploads were restricted to 12kbps and slot allocated was 1, it also was NOT set to run automatically. And I remove almost everything from the "library" location upon download completion.

in the taskbar, I can see that AVG is running
my email is on
open office
family safety but off
network
windows sidebar
daemon tools lite
msn not signed in and
google desktop.
Coffeeluva (16069)
1151696 2010-11-09 19:46:00 Post a hijackthis log. We'll soon find out what maybe causing it. Watching vids on youtube will probably chew it up Speedy Gonzales (78)
1151697 2010-11-09 19:53:00 Is your wireless network secure, like no one sitting outside with a laptop and using it, or even the next door neighbors. You should have your security set to WPA2.
:)
Trev (427)
1151698 2010-11-09 20:06:00 How many computers do you have? CYaBro (73)
1151699 2010-11-09 20:19:00 We have two desktops. and my wireless is secured with very random serial number off the TV Coffeeluva (16069)
1 2 3 4 5