This is our old Q&A Site. Please post any new questions and answers at ask.wireshark.org.

Hi,

i tried to check my network security be monitoring packet on my computer (with win10), but i found that my computer exchange nbns packet with every website that i open facebook, google ...

this a screenshot from wireshark session

alt text

my computer is clean from malicious software, also i tried with a clean vm with win10 and i found the same packets. with my computer in work i found the same packets exchange with any website that i browse.

just wanna know what is the story of these packets.

thanks.

asked 24 Oct '17, 12:44

Huolsam's gravatar image

Huolsam
6113
accept rate: 0%

Not quite an answer but I'm just seeing exactly the same, apart from IP addresses but they are all public as well:

(24 Oct '17, 13:38) patkszen

yeah it's the same, for example in ur case the ip 66.110.49.38 is belong to kaspersky

https://www.whois.com/whois/66.110.49.38

(25 Oct '17, 12:11) Huolsam

I would disable NetBios altogether unless you have a specific need for it.

Check a previous answer: https://ask.wireshark.org/questions/2824/unexplained-netbios-traffic

permanent link

answered 25 Oct '17, 08:48

Papa%20Packet's gravatar image

Papa Packet
63
accept rate: 0%

edited 25 Oct '17, 08:49

Your answer
toggle preview

Follow this question

By Email:

Once you sign in you will be able to subscribe for any updates here

By RSS:

Answers

Answers and Comments

Markdown Basics

  • *italic* or _italic_
  • **bold** or __bold__
  • link:[text](http://url.com/ "title")
  • image?![alt text](/path/img.jpg "title")
  • numbered list: 1. Foo 2. Bar
  • to add a line break simply add two spaces to where you would like the new line to be.
  • basic HTML tags are also supported

Question tags:

×4

question asked: 24 Oct '17, 12:44

question was seen: 1,366 times

last updated: 25 Oct '17, 12:11

p​o​w​e​r​e​d by O​S​Q​A