This is our old Q&A Site. Please post any new questions and answers at ask.wireshark.org.

I have a client that is on a limited Bandwith residential ISP with a daily allocation of 250MB up/down. The user has a PC running WIN 7 Home Premium. She has turned off all known "automatic update" configurations in all of the programs that are installed. But the bandwidth is still being consumed at an unacceptable rate. The PC was recently restored back to its out of box new condition and fresh copies of Windows 7 and Avast Internet Security were installed.

Can Wireshark help her determine which Windows program(s) is the culprit?

For the record, only one PC is connected to the home network and the ISP is HughesNet in Texas.

Thanks.

This question is marked "community wiki".

asked 30 Aug '11, 10:37

wtg1953's gravatar image

wtg1953
1112
accept rate: 0%

edited 30 Aug '11, 12:20

helloworld's gravatar image

helloworld
3.1k42041


Wireshark could be used to identify what traffic is being transferred and at what rate, but doesn't directly point to the process that is causing the traffic. You may be able to infer that from the traffic content.

As you'll be likely to want this to run for some time, you may want to use dumpcap to do the capture so that the Wireshark UI isn't available for user "experimentation".

Microsoft's Network Monitor can show you the process causing the traffic, and you can also use other tools such as TCPView or netstat to find out what process is using a port.

permanent link

answered 30 Aug '11, 11:06

grahamb's gravatar image

grahamb ♦
19.8k330206
accept rate: 22%

edited 30 Aug '11, 13:36

I second TCPView.

(30 Aug '11, 11:30) helloworld
Your answer
toggle preview

Follow this question

By Email:

Once you sign in you will be able to subscribe for any updates here

By RSS:

Answers

Answers and Comments

Markdown Basics

  • *italic* or _italic_
  • **bold** or __bold__
  • link:[text](http://url.com/ "title")
  • image?![alt text](/path/img.jpg "title")
  • numbered list: 1. Foo 2. Bar
  • to add a line break simply add two spaces to where you would like the new line to be.
  • basic HTML tags are also supported

Question tags:

×254
×115
×103
×53

question asked: 30 Aug '11, 10:37

question was seen: 14,596 times

last updated: 30 Aug '11, 13:36

p​o​w​e​r​e​d by O​S​Q​A