How to stop scanning subnets that are no longer in use

NetScanner keeps scanning a subnet that the PC is no longer a part of.

The IP of the PC running NetScanner was 192.168.14.22. Now it is 10.0.6.35. My firewall logs persistently show a denial from the PC new IP scanning the entire 192.168.14.0 subnet.

How do I prevent this?
SoftPerfect Support forum - Ann avatar image
Ann

Re: How to stop scanning subnets that are no longer in use   10 May 2026, 18:36

Network Scanner doesn't initiate scans on its own. It only runs when you explicitly start a scan, or when a scheduled task fires. So the traffic you are seeing is almost certainly coming from one of the following:
  • A scheduled scan in Network Scanner.
    Open the app and go to Options - Scheduler. If there's a saved task targeting 192.168.14.0/24, disable or delete it.
  • An auto-start scan.
    If Network Scanner is launched from a shortcut with command-line parameters, or from Windows Task Scheduler, the old range may be hard-coded there.
    Check the shortcut target and any Task Scheduler entries.
  • A saved range that re-runs on launch.
    Check the IP range field in the main window. If it still shows 192.168.14.x and you have "start scan on launch" behaviour configured, that would be the reason.
  • Something other than Network Scanner.
    It's worth confirming the source process. Many environments have other tools that probe networks (asset inventory agents, monitoring software, antivirus discovery scans). If your firewall logs the source process or PID, that should tell you whether it's the Network Scanner or not.
Thank you for responding. I am running v2.5. It does not have the option to schedule. The program is not running in foreground or background. It is not auto started, Task Scheduled, etc. There is no saved range. The firewall entries stop only when I disconnect the NIC or power down the PC.
SoftPerfect Support forum - Ann avatar image
Ann

Re: How to stop scanning subnets that are no longer in use   10 May 2026, 18:53

Are you saying the PC is sending traffic to those addresses, but Network Scanner isn't running? If so, then it's almost certainly something else, not Network Scanner. A program can send packets only when it's actually running.

Your firewall logs the source IP but not the source program, so it's worth identifying which process on the PC is generating the traffic. TCPView from Microsoft Sysinternals (free) is the easiest way; it shows every process with active network activity in real time. Alternatively, netstat -ano in an elevated Command Prompt lists connections with PIDs you can match to Task Manager.

Common culprits for this kind of leftover subnet traffic are Windows network discovery (SSDP/NetBIOS/LLMNR/mDNS), printer drivers searching for a printer on the old subnet, or asset management/AV/backup agents doing periodic discovery against cached addresses.

Reply to this topic

Sometimes you can find a solution faster if you try the forum search, have a look at the knowledge base, or check the software user manual to see if your question has already been answered.

Our forum rules are simple:

  • Be polite.
  • Do not spam.
  • Write in English. If possible, check your spelling and grammar.

Author:

Email:

Subject

A brief and informative title for your message, approximately 4–8 words:

     

Spam prevention: please enter the following code in the input field below.

 ********   *******    *******   **    **  **       
    **     **     **  **     **  ***   **  **       
    **            **  **     **  ****  **  **       
    **      *******    ********  ** ** **  **       
    **            **         **  **  ****  **       
    **     **     **  **     **  **   ***  **       
    **      *******    *******   **    **  ******** 

Message: