Unusual NetBios Name Service entries on WireShark

Does this seem strange to anyone else?

Running packet capture on my network I see all these NBNS requests from one Windows XP workstation looking for names of people in alphabetical order. Hundreds of them. When it gets through the alphabet, it starts over again. We have about 23 devices on the network. None of them named after people.
Dictionary of people names NetBios requestsNaturally, I immediately ran MalwareBytes. Zero threats found. I shut that workstation down and the people name requests stop of course, just the usual computer name requests left behind from other workstations.

What gives?
LVL 38
Tom BeckAsked:
Who is Participating?

[Product update] Infrastructure Analysis Tool is now available with Business Accounts.Learn More

I wear a lot of hats...

"The solutions and answers provided on Experts Exchange have been extremely helpful to me over the last few years. I wear a lot of hats - Developer, Database Administrator, Help Desk, etc., so I know a lot of things but not a lot about one thing. Experts Exchange gives me answers from people who do know a lot about one thing, in a easy to use platform." -Todd S.

Definitely weird.  What happens when you run an "nbtstat -n" from that XP machine?
Tom BeckAuthor Commented:
I left it shut down for the weekend. I can try that on Monday. Thanks.
Qlemo"Batchelor", Developer and EE Topic AdvisorCommented:
This needs to be software-initiated. 00 and 20 are domain and file server IDs. Noone names their domain or servers like that; the software has to work on an address book or similar to get those names, and that can get you started in tracing down what it is. In no way is this something normal.

You can run SysInternals TcpView to see which application generates traffic, or MS NetMon doing the same in a WireShark manner.

Experts Exchange Solution brought to you by

Your issues matter to us.

Facing a tech roadblock? Get the help and guidance you need from experienced professionals who care. Ask your question anytime, anywhere, with no hassle.

Start your 7-day free trial
SolarWinds® VoIP and Network Quality Manager(VNQM)

WAN and VoIP monitoring tools that can help with troubleshooting via an intuitive web interface. Review quality of service data, including jitter, latency, packet loss, and MOS. Troubleshoot call performance and correlate call issues with WAN performance for Cisco and Avaya calls

Craig BeckCommented:
Long shot but I've seen Google Chrome DNS Prefetching cause similar issues.

See if this helps...

Tom BeckAuthor Commented:
@craigbeck, good information, thanks.

@Qlemo, TcpView showed what I already knew, that there was a lot of activity coming from NetBios NS. It also showed connections coming from a Kaspersky central management program that I formerly used to manage antivirus on the network but abandoned a few years ago. Decided to uninstall that program to simplify the system before continuing the NetBios issue. However, the weirdness stopped once that program was removed. I don't know what Kaspersky was doing looking for all those peoples' names and I guess I never will.
Qlemo"Batchelor", Developer and EE Topic AdvisorCommented:
To know that you will never know still enriches your knowledge :D.
It's more than this solution.Get answers and train to solve all your tech problems - anytime, anywhere.Try it for free Edge Out The Competitionfor your dream job with proven skills and certifications.Get started today Stand Outas the employee with proven skills.Start learning today for free Move Your Career Forwardwith certification training in the latest technologies.Start your trial today
Network Analysis

From novice to tech pro — start learning today.