Wireshark puts network adapters into promiscuos mode - which again has its own side effects.
Are you sure you detect real traffic or just artefacts of the monitoring ?
Also how exactly do you shut the VMware network adapters off ? - which mode do they use ? - bridged or hostonly or guestonly ?
________________________________________________
Do you need support with a VMFS recovery problem ? - send a message via skype "sanbarrow"
I do not support Workstation 16 at this time ...