This is our old Q&A Site. Please post any new questions and answers at ask.wireshark.org.

How can I use Wireshark to determine that a rogue program (malware) silently sent an email from my computer?

asked 24 Jun '12, 18:45

Dee's gravatar image

Dee
1111
accept rate: 0%

edited 25 Jun '12, 19:34

helloworld's gravatar image

helloworld
3.1k42041


You can sniff on your computer, but Wireshark will only show that there is something sending an e-mail, however it will not show the process name.

Your options are:

  1. Use Microsoft Network Monitor 3.4. It will show the process name in some cases.
  2. Use a desktop firewall to block AND log any application that tries to send an e-mail

Regards
Kurt

permanent link

answered 26 Jun '12, 00:05

Kurt%20Knochner's gravatar image

Kurt Knochner ♦
24.8k1039237
accept rate: 15%

Your answer
toggle preview

Follow this question

By Email:

Once you sign in you will be able to subscribe for any updates here

By RSS:

Answers

Answers and Comments

Markdown Basics

  • *italic* or _italic_
  • **bold** or __bold__
  • link:[text](http://url.com/ "title")
  • image?![alt text](/path/img.jpg "title")
  • numbered list: 1. Foo 2. Bar
  • to add a line break simply add two spaces to where you would like the new line to be.
  • basic HTML tags are also supported

Question tags:

×27

question asked: 24 Jun '12, 18:45

question was seen: 2,018 times

last updated: 26 Jun '12, 00:05

p​o​w​e​r​e​d by O​S​Q​A