You can use Port reporter to log traffic
http://support.microsoft.com/kb/837243
and sysinternals process explorer/tcpview
for real time view of what is doing what.
http://technet.microsoft.com/en-us/sysinternals/default.aspx
From:
wireshark-users-bounces@xxxxxxxxxxxxx
[mailto:wireshark-users-bounces@xxxxxxxxxxxxx] On Behalf Of Jon Ziminsky
Sent: Wednesday, October 01, 2008
4:10 PM
To: Community support list for
Wireshark
Subject: Re: [Wireshark-users] Unexplained
Netbios Traffic
The packets are coming
from the "System" process.