Suspicious wireless activity

Hi MBAM Team

Unusual activity on our laptop (only) noticed today but perhaps prevalent for a few days.

What we are seeing in Windows Task Manager (WTM) is that data is being sent and received (in "equal" amounts) between our laptop (with inbuilt wireless modem) and wireless router. The same behaviour is not noticed with our wirelessly connected PC.

I have run MBAM, Spybot and Norton 360 scans but no malware shows up. On the wireless router, a Netgear DGN3500, only the wireless "beacon" LED is flashing while this is happening rather than the internet activity LED. My ISP internet usage stats also do not indicate any unusual internet usage to reflect what I am seeing on the WTM graphs and stats ... I'm just concerned about the (apparent) data flow through the laptop. Attached is what we are seeing on WTM.

Yes, we are on a secure password encrypted home wireless network and this type of activity has not been noticed before.

Please find attached the HijackThis log for the relevant laptop initiated while the unusual behaviour was being noticed:

Logfile of Trend Micro HijackThis v2.0.4

Scan saved at 4:09:51 PM, on 8/07/2011

Platform: Windows XP SP3 (WinNT 5.01.2600)

MSIE: Internet Explorer v8.00 (8.00.6001.18702)

Boot mode: Normal

I look forward to your feedback on the logs.




Hi Chris

Thanks for your response.

I checked the 2 PCs that are part of this home network: one direct LAN and the other via USB wireless. Neither of these (nor the laptop itself) showed any issues with MBAM, Spybot S&D, Norton 360 or WinPatrol. The only symptom is that described in my original post. As noted it did not appear that data was being sent/received on the internet per se, although I did suspect that perhaps the laptop was being used as a "mule" with external data passing through my laptop/router. For all other intents and purposes the laptop was working fine and accessed the internet without redirects or noticeable issues.

Having spent most of the weekend on this I can confirm that the issue seems to be solely between the laptop with inbuilt Intel PRO/Set Wireless WiFi and its connection to the Netgear DGN3500 router. I spent the weekend trying different things in terms of configuring (a) the router and (b) the laptop settings. It appears that either (a) increased wireless usage in our neighbourhood perhaps causing interference, and/or (b) a recent firmware upgrade to the router may be the cause RATHER THAN any malware or virus. By trial and error changing the wireless channel and communications protocol mode from "up to 270Mbps" to "up to 130Mbps" the problem now appears to have been solved.

So unless you can see anything "odd" in the HijackThis log that needs to be addressed I suggest this thread be closed as solved.

Apologies for distracting the MBAM team from more serious real malware issues others may be having.



