cancel
Showing results for 
Search instead for 
Did you mean: 

Heavy Data Usage

HarryR
Newbie
Posts: 8
Registered: ‎27-04-2011

Heavy Data Usage

I am having a problem with a Laptop that is having a non explained very high usage of data. The problem first came to my attention when I was warned last month that I was close to my data limit. Several checks were made to try and identify the problem. Checks that have been done include:
- Run the wireless network with all computers switched off to see if anyone else was using the network, the result was no generated traffic (as expected since all security features are used).
- One computer was found to be generating the traffic. Carried out a full scan using the installed Norton Internet Security, without any malware being found.
- Carried out a more intense scan using Norton Power Eraser, but it did not find any malware either.
- Contacted Norton Support who carried out checks lasting over an hour and the conclusion reached was no malware on computer.
I was advised to install Wire Shark and send in some results. I did this and got the reply that this was not the best test for the problem with the computer. Plus net support suggested installing DU meter, I have tried this and can see traffic going in and out, there seems to be more inward traffic than outward traffic. When monitoring the internet traffic, there is not any other applications open, I have tried the tests using the computer connected wireless to the router and wired, the results are the same. The heavy traffic starts a few minutes after logging on to the computer.
Can you help?
30 REPLIES 30
Peter_Vaughan
Grafter
Posts: 14,469
Registered: ‎30-07-2007

Re: Heavy Data Usage

First uninstall norton as it is one of the worse packages around...  Your PC will thank you Wink Note: you may need to run the Norton removal tool to actually get rid of all the stuff the uninstaller leaves behind
Next run some of the much better anti-malware / anti-virus scanners around
Install and run Microsoft security essentials (far better than norton and much less resource hungry) and run a full scan
Run malwarebytes
Run spybot search and destroy
Install process explorer  - this allows you to see a lot more about what is running on your PC, including what network connections each process has open.
Your router may show active sessions which may give you IP and port numbers which you can check up on.
Some of the dos based tools can tell you what is using the network. Try netstat -ano which shows open / waiting ports. The -o also shows the PID which you can find the process in question in process explorer.
jelv
Seasoned Hero
Posts: 26,785
Thanks: 971
Fixes: 10
Registered: ‎10-04-2007

Re: Heavy Data Usage

I suggest you install ZoneAlarm on the PC: you will be prompted to allow every program that attempts to send data to the internet or accept data from the internet.
You could also try opening a cmd box (run it as administrator) and running the command
netstat -b
That will show you the executables associated with all the open ports.
jelv (a.k.a Spoon Whittler)
   Why I have left Plusnet (warning: long post!)   
Broadband: Andrews & Arnold Home::1 (FTTC 80/20)
Line rental: Pulse 8 Home Line Rental (£14.40/month)
Mobile: iD mobile (£4/month)
Oldjim
Resting Legend
Posts: 38,460
Thanks: 787
Fixes: 63
Registered: ‎15-06-2007

Re: Heavy Data Usage

Quote from: Peter
First uninstall norton as it is one of the worse packages around...  Your PC will thank you Wink Note: you may need to run the Norton removal tool to actually get rid of all the stuff the uninstaller leaves behind
Next run some of the much better anti-malware / anti-virus scanners around
Install and run Microsoft security essentials (far better than norton and much less resource hungry) and run a full scan

This is completely incorrect
The latest versions of Norton are not resource hungry and overall it gives better protection than MSE http://www.av-test.org/certifications.php
Peter_Vaughan
Grafter
Posts: 14,469
Registered: ‎30-07-2007

Re: Heavy Data Usage

I go by my personal experience of 100s of PC installations. Norton is the FIRST thing that gets removed before any investigations begin. You will be surprised at how many "problems" suddenly disappear after Norton is no more.
jelv
Seasoned Hero
Posts: 26,785
Thanks: 971
Fixes: 10
Registered: ‎10-04-2007

Re: Heavy Data Usage

When looking at the ratings remember one thing: an AV solution that broke everything such that you couldn't access anything on the internet would score full marks for protection.
jelv (a.k.a Spoon Whittler)
   Why I have left Plusnet (warning: long post!)   
Broadband: Andrews & Arnold Home::1 (FTTC 80/20)
Line rental: Pulse 8 Home Line Rental (£14.40/month)
Mobile: iD mobile (£4/month)
fxbronte
Grafter
Posts: 97
Thanks: 3
Registered: ‎09-06-2007

Re: Heavy Data Usage

I understand your irritation, I have spent three days with the same problem. See topic ‘Heavy Usage whilst idling’, earlier today.
With the help of some members of this forum, I narrowed the problem to the settings of the Google toolbar that somehow had reset to sent statistical information to Google. Your problem may be the same
ReedRichards
Seasoned Pro
Posts: 4,927
Thanks: 145
Fixes: 25
Registered: ‎14-07-2009

Re: Heavy Data Usage

Quote from: Oldjim
Quote from: Peter
First uninstall norton as it is one of the worse packages around...

This is completely incorrect
The latest versions of Norton are not resource hungry and overall it gives better protection than MSE http://www.av-test.org/certifications.php

I'd say the latest versions of Norton are not so resource-hungry as those of a few years ago but it's still not that great.  But I don't see that Norton is more data-hungry than other security software, which is the point at issue here.
If you are familiar with HijackThis http://free.antivirus.com/hijackthis/ you could run a scan and post the log file here so we could comment on what programs you are running in the background that might be causing the problem.
HarryR
Newbie
Posts: 8
Registered: ‎27-04-2011

Re: Heavy Data Usage

Thanks everyone for the suggestions, I am going to install “ Process Explorer” and will run ”netstat –b”, then report back my findings.
Note to fxbronte, unfortunately, this computer does not have the Google toolbar installed so I am looking for a different solution.
Since my first request for help I have carried out a scan with the computer in safe mode and there still has not been any malware found.
The results from running DU Meter show that the incoming traffic is averaging approximately 350Kbs all the time.
MJN
Pro
Posts: 1,318
Thanks: 161
Fixes: 5
Registered: ‎26-08-2010

Re: Heavy Data Usage

Quote from: HarryR
The results from running DU Meter show that the incoming traffic is averaging approximately 350Kbs all the time.

If that is happening consistently, even when you think it ought to be sitting idle, then just install Wireshark and capture a trace - from that you'll (we'll) be able to see where the traffic is coming from - possibly exactly what it contains - and from that determine what is pulling it in.
Mathew
HarryR
Newbie
Posts: 8
Registered: ‎27-04-2011

Re: Heavy Data Usage

I have attached a copy of a data dump created using “Process Explorer”, is there anything running that you would not expect to be running?
HarryR
Newbie
Posts: 8
Registered: ‎27-04-2011

Re: Heavy Data Usage

I have attached two screen captures of the results obtained when running “netstat –b”, hopefully they will help build a picture of the problem.
MJN
Pro
Posts: 1,318
Thanks: 161
Fixes: 5
Registered: ‎26-08-2010

Re: Heavy Data Usage

Try tagging -n on the end, and also shut Internet Explorer down to cut that list down. If you can also confirm that DU Meter still reports a constant download rate during the snapshot that would also be useful.
Mathew
HarryR
Newbie
Posts: 8
Registered: ‎27-04-2011

Re: Heavy Data Usage

This is the capture using “netstat – b –n" taken with all other windows closed. I can confirm that the DU meter did continue to show high data transfer during the capture.
ReedRichards
Seasoned Pro
Posts: 4,927
Thanks: 145
Fixes: 25
Registered: ‎14-07-2009

Re: Heavy Data Usage

I don't really know how to interpret netstat results but the foreign IP addresses belong to Akamai, http://www.akamai.com/html/about/index.html , if that means anything to you.