Welcome to Experts Exchange

Add your voice to the tech community where 5M+ people, just like you, are talking about what matters.

  • Help others & share knowledge
  • Earn cash & points
  • Learn & ask questions
Solved

Excessive Outbound Traffic on UDP Port 137

Posted on 2008-06-23
3
3,266 Views
Last Modified: 2013-12-04
I've been noticing in my firewall logs an excessive amount of outbound traffic on udp port 137 from a single workstation. This port is blocked in my firewall, so it's not getting through, but I wanted to know if anyone could help me find the source of this traffic.

I have run CA AntiVirus and Anti Spyware as well as Spybot. The AV scan was clean and the spyware/adware scan only came up with a handful of cookies that have been removed. Netstat and Nbtstat both seem clean as well.

Thanks for the help.
0
Comment
Question by:Luis_Romero
3 Comments
 
LVL 12

Accepted Solution

by:
alikaz3 earned 500 total points
ID: 21850393
udp port 137 is used for NetBIOS. You could try changing the NetBIOS setting on that workstation and see what you get.
>>>>>>>>>>>>
NetBIOS name service (UDP)

firewalls: Firewall administrators will frequently see large numbers of incoming packets to port 137. This is due to the behavior of Windows servers that use NetBIOS (as well as DNS) to resolve IP addresses to names using the "gethostbyaddr()" function. As users behind the firewalls surf Windows-based web sites, those servers will frequently respond with NetBIOS lookups.
>>>>>>>>>>>>
0
 
LVL 32

Expert Comment

by:r-k
ID: 21851063
Please post a HJT log from the suspect workstation just in case:

Download HijackThis from http://www.hijackthis.de/
(use the "direct download" link in the upper-right corner)
Unzip to any folder on your hard drive (other than the desktop)
Run the program by double-clicking on the HijackThis.exe file.
Click on "Do a System Scan.."
Copy-and-paste the resulting log here.
Optionally, you can post back to that same web page, and click "Analyze"
0
 

Author Closing Comment

by:Luis_Romero
ID: 31470272
Thanks. Your response actually reminded me that I've had this problem before but added a new NIC that used the default NetBios settings. Once I turned off NetBios over TCP/IP the problem was resolved.

Thanks for your help!
0

Featured Post

The Eight Noble Truths of Backup and Recovery

How can IT departments tackle the challenges of a Big Data world? This white paper provides a roadmap to success and helps companies ensure that all their data is safe and secure, no matter if it resides on-premise with physical or virtual machines or in the cloud.

Question has a verified solution.

If you are experiencing a similar issue, please ask a related question

A brand new malware strain was recently discovered by security researchers at Palo Alto Networks dubbed “AceDeceiver.” This new strain of iOS malware can successfully infect non-jailbroken devices and jailbroken devices alike.
Ransomware continues to be a growing problem for both personal and business users alike and Antivirus companies are still struggling to find a reliable way to protect you from this dangerous threat.

860 members asked questions and received personalized solutions in the past 7 days.

Join the community of 500,000 technology professionals and ask your questions.

Join & Ask a Question