Thank you for the help with Windump, I couldn't figure out how to print it to a text file.
So instead I used Snagit to make images of the List, Details, and Bytes from 3 separate captures.
The link is here:
http://s268.photobucket.com/albums/jj23/eb001-captures/Capture 1 and Capture 2 have the LLC packets I was referring to.
Capture 3 is a capture during the time the host with the spoofed MAC address (0C0C0C0C0C01)
was online.
There is also a miscellaneous Capture list which has a lot of TCP Out of Order and Retransmission and Dup frames and I was hoping somebody can tell me something about that.
Thank you for your help.
EB