OK.
However as I said earlier, "the strange thing being that this is happening when royroy is connecting to send or receive email and not as would be the case if it were malware or as suggested by you P2P related as in the connection is established based on their settings.

So we need royroy to confirm that there was no P2P activity at the time this was going on at that time. I don’t know how he would do that as I don’t use P2p applications, though I would have thought that there would be some form of stats, etc.