what is the traffic where is it going?
I did netstat they all say tor except these two
tcp 0 0 127.0.0.1:4101 0.0.0.0:* LISTEN 215/brltty
tcp 0 0 10.137.3.1:9052 0.0.0.0:* LISTEN 902/python
tcp 0 0 0.0.0.0:8082 0.0.0.0:* LISTEN 925/tinyproxy
all the rest are: with ports in 9100s which I assume is tor.
tcp 0 0 10.137.3.1:9181 0.0.0.0:* LISTEN 997/tor
You should also check from sysnet to see what is leaving your pc.
you can use wireshark, tcpdump, or etherape. but all are extremely vulnerable. lol
your network card is in sys-net. sys-firewall is the in between proxy. Its considered trusted so I wouldn't run any monitoring programs in it. better to run them in sys-net or make another proxy.