Interference when using Wireless Laptop near TV (1 Viewer)

robbo100

Retired Team Member
  • Premium Supporter
  • May 5, 2009
    1,290
    309
    UK
    Home Country
    United Kingdom United Kingdom
    Thanks for your offer,

    Not that I am worried about you, but is it a security risk posting wireshark logs on an open forum, surely advertising my MAC address' is not a good idea??

    Robbo100
     

    robbo100

    Retired Team Member
  • Premium Supporter
  • May 5, 2009
    1,290
    309
    UK
    Home Country
    United Kingdom United Kingdom
    Hi there,

    Looking in more detail, I think it might be that there is some spyware on my HTPC.

    If I look at my wireshark output in detail, it seems to be my HTPC (192.168.1.2) which transmits to my Macbook wireless adapter (192.168.1.3) - for example, from source port "sweetware - apps [1221] to destination post 31456 [SYN]" (shown as a TCP SYN/FIN type of transmission by wireshark). Then a couple of lines later there is a TCP RST return from the Macbook to the HTPC with the same port details.

    sweetware - apps is only one example of lots, such as "shockwave2", "tsdos390", "serialgateway" etc etc.

    I have AVG free installed but don't have a spyware detector installed. I have installed adaware and am running a scan now.

    Could it be that the spyware was completely happy with the old router, but with the new one installed (with better firewall) things are being blocked (to the dislike of the HTPC???

    Since it seems to be only a problem with the HTPC trying to transmit to 192.168.1.3, I have changed the IP address of the macbook routing table to 192.168.1.5 and it has instantly solved the problem. However, clearly I want to stop the HTPC from continually sending SYN packets on the the network to nothing!

    Does all of this sound sensible to people who understand much more about networking than me???

    Thanks

    Robbo100
     

    Furetto

    Moderator - Dutch Forums
    April 11, 2005
    664
    61
    53
    Brussels
    Home Country
    Belgium Belgium
    The traffic we could see in your logs does look suspect. But with only a screenshot it is hard to really judge what it is. Your suspicion of malware is very to the point though.

    In the recent months I recommend hitmanpro in such situations: Home - SurfRight

    They have an In-The-Cloud scanning system and it is very thorough ! You can install the program for free and keep using it for free as long as you want, in which case it only does detection. If you activate the program, it does removal as well. The first week or month (don't remember for sure) for free, afterwards you need a paid license.

    If you know enough about Windows, the detection will tell you enough to do the cleaning by hand (regedit and file remove in safe mode for instance). Reboot and rescan. If you're not so sure, activate the program.

    But whatever you do, just run it in free mode at first, just for diagnostics.
     

    Furetto

    Moderator - Dutch Forums
    April 11, 2005
    664
    61
    53
    Brussels
    Home Country
    Belgium Belgium
    Thanks for your offer,

    Not that I am worried about you, but is it a security risk posting wireshark logs on an open forum, surely advertising my MAC address' is not a good idea??

    Robbo100

    Being careful usually pays off. In this case there is no real security risk about your MAC address, as this is hidden from the Internet by your firewall/broadband router. This device does NAT (Network Address Translation) in which it substitutes the local internal (aka martian, 192.168.x.y) addresses by your WAN (delivered by your provider) address. The sender's MAC address will be your router's address.

    But with your analysis, no more need for your logs.
     

    robbo100

    Retired Team Member
  • Premium Supporter
  • May 5, 2009
    1,290
    309
    UK
    Home Country
    United Kingdom United Kingdom
    I have tracked down the problem.

    I am running a program called LEDcontrolled (a MP sort of plugin I got from this forum), which turns LEDs on and off via my COM port to tell me which of my TV cards is recording or being used for time shifting. It seems that when I changed my router, the HTPC IP address got changed and the program has been blind calling the TVServer on the old IP address (which is now that of the MacBook).

    I wanted to say thanks for the help from all that posted. Often people just don't reply when they fix things, but I always try to "give closure"

    Thanks all

    Robbo100
     

    Users who are viewing this thread

    Top Bottom