Want to protect your cyber security and still get fast solutions? Ask a secure question today.Go Premium


How to get 'rid' of this constant broadcast message my laptop keeps doing ...

Posted on 2009-02-08
Medium Priority
Last Modified: 2012-05-06
I have attached a wireshark .JPG to this question, so you can see exactly what I'm talking about.

It is hard to describe the problem, but I'll try ...

For about 2 weeks last year, I was contracting at a site as a daily IT helper ...
The netBIOS name of each PC on site was something like this:


The AL was the company name ... the number is the location of the PC ... and the last part is the OS on the system.

Since that time ... I always see these DARN broadcast messages from my laptop when I do any Wireshark work (I've cleared my DNS cache dozens of times ... I'm using DHCP 99.99% of the time, and I've check all the TABS for network configuration (even the advance TABS ... etc.)

I simply cannot find 'where' on my laptop this reference to the old company is located at.

I hope this make sense.

I have not been back to the site where this started at in nearly 6 months ...

I have no idea why, how, or where this is 'stuck' in my networking configuration process.

Question by:pugdog_fan

Expert Comment

ID: 23587923
Could be something left over in my network places
LVL 12

Expert Comment

ID: 23588225
go to a cmd prompt and do a 'net use' and see if anything is still registered for the old network..

it looks like a DNS name query on an old share that hasnt been removed..

Accepted Solution

ionut_mir earned 2000 total points
ID: 23590936
I captured a few minutes and I got those broadcasts about an computer in my network.
I searched for that name in my registry and I found that name under my Antivirus directory.

Try to search your registry entries and see if that computer name appears somewhere. Maybe you will find something that you can erase.
Who's Defending Your Organization from Threats?

Protecting against advanced threats requires an IT dream team – a well-oiled machine of people and solutions working together to defend your organization. Download our resource kit today to learn more about the tools you need to build you IT Dream Team!


Author Comment

ID: 23596646
ionut mir:

Good suggestion ... I did exactly what you said, and I found three entries in my Windows XP registry files for that NBMS 'name'.  I removed the entries ... rebooted my PC ... and I've run Wireshark a bunch of times.  They are GONE.

I get different NBMS broadcasts now (they don't bother me because they look like 'normal' stuff for announcements and browser election related ...).

I'll close this question in a bit ... and award you the points, but I wanted to put in another screen shot of a capture I got to see if anyone has any pointers on it ...


Author Comment

ID: 23596665
After getting the NBNS stuff to 'stop' showing 'false' stuff ... I rebooted my PC (to get my Windows registry to reload fresh).  I kept the CAT-5e Ethernet cable out of the NIC card, so I could get control of my desktop 1st (to relaunch Wireshark with a clean capture).

When I that, I noticed some 'incoming' Internet traffic from Microsoft that I'm not sure why/how my PC would have 'asked' or generated it.

NOTE:  The picture below is like after the 2nd or 3rd reboot and Wireshark capture.  It might show my PC 1st 'asking' for traffic from the 65.x.x.x network ... but in the earlier captures ... the 65.x.x.x network traffic came in without my launching any Internet stuff (so maybe something in the registry is asking Microsoft for information)????

Can you tell what the traffic in this picture is about?


Assisted Solution

ionut_mir earned 2000 total points
ID: 23598008
If you paste that IP in Internet explorer... and if you have connection to internet it will go to update.microsoft.com, so I hope this will answer your question :).

Featured Post

Become an Android App Developer

Ready to kick start your career in 2018? Learn how to build an Android app in January’s Course of the Month and open the door to new opportunities.

Question has a verified solution.

If you are experiencing a similar issue, please ask a related question

SSL is a very common protocol used these days when browsing the web.  The purpose is to provide security to communication, but how does it do it?  There are several pieces at work that have to be setup before SSL will even work and it requires both …
Creating an OSPF network that automatically (dynamically) reroutes network traffic over other connections to prevent network downtime.
After creating this article (http://www.experts-exchange.com/articles/23699/Setup-Mikrotik-routers-with-OSPF.html), I decided to make a video (no audio) to show you how to configure the routers and run some trace routes and pings between the 7 sites…
After creating this article (http://www.experts-exchange.com/articles/23699/Setup-Mikrotik-routers-with-OSPF.html), I decided to make a video (no audio) to show you how to configure the routers and run some trace routes and pings between the 7 sites…
Suggested Courses
Course of the Month11 days, 10 hours left to enroll

564 members asked questions and received personalized solutions in the past 7 days.

Join the community of 500,000 technology professionals and ask your questions.

Join & Ask a Question