T
Thomas Scheiderich
I am trying to figure out what is happening on my system. I am looking to
see if I have a virus on my system and have zonealarm telling me that there
is some talking going on and I am trying to make sure it is all kosher.
I periodically have my Win2000 sending broadcasts and one of my machines
will answer and then send a bunch of packets back and forth.
What I am getting is something like this - Trilobyte is my W2k Pro machine
and my wifes Mac will answer. If the Mac is off, another machine will
answer.
Here is the approximate packet requests (translated by my Observer program):
Trilobyte -> broadcast NetBios Name Service (Q)uery request -- UDP
(137->137)
Mac->Trilobyte NetBios Name Service (Q)uery response -- UDP
(137->137)
Trilobyte-Broadcast Arp Request (192.168.122.7 -> 192.168.122.44) --
802.2LLC [information poll on] S=0,R=0
Mac-Broadcast Arp Reply (192.168.122.44 -> 192.168.122.7) --
802.2LLC [information poll on] S=0,R=0
Trilobyte-Broadcast SMB_COM_TRANSACTION_REQUEST NetBios Datagram
Service Direct Group Datagram
It then does a couple more NetBios packets (Query requests and Transaction
requests)
Then it stops and does it again a little while later.
Why would it be doing this?
Thanks,
Tom
see if I have a virus on my system and have zonealarm telling me that there
is some talking going on and I am trying to make sure it is all kosher.
I periodically have my Win2000 sending broadcasts and one of my machines
will answer and then send a bunch of packets back and forth.
What I am getting is something like this - Trilobyte is my W2k Pro machine
and my wifes Mac will answer. If the Mac is off, another machine will
answer.
Here is the approximate packet requests (translated by my Observer program):
Trilobyte -> broadcast NetBios Name Service (Q)uery request -- UDP
(137->137)
Mac->Trilobyte NetBios Name Service (Q)uery response -- UDP
(137->137)
Trilobyte-Broadcast Arp Request (192.168.122.7 -> 192.168.122.44) --
802.2LLC [information poll on] S=0,R=0
Mac-Broadcast Arp Reply (192.168.122.44 -> 192.168.122.7) --
802.2LLC [information poll on] S=0,R=0
Trilobyte-Broadcast SMB_COM_TRANSACTION_REQUEST NetBios Datagram
Service Direct Group Datagram
It then does a couple more NetBios packets (Query requests and Transaction
requests)
Then it stops and does it again a little while later.
Why would it be doing this?
Thanks,
Tom