This is a static archive of our old Q&A Site. Please post any new questions and answers at ask.wireshark.org.

Can Wireshark detect a rogue program silently sending an email?

0

How can I use Wireshark to determine that a rogue program (malware) silently sent an email from my computer?

asked 24 Jun '12, 18:45

Dee's gravatar image

Dee
1111
accept rate: 0%

edited 25 Jun '12, 19:34

helloworld's gravatar image

helloworld
3.1k42041


One Answer:

0

You can sniff on your computer, but Wireshark will only show that there is something sending an e-mail, however it will not show the process name.

Your options are:

  1. Use Microsoft Network Monitor 3.4. It will show the process name in some cases.
  2. Use a desktop firewall to block AND log any application that tries to send an e-mail

Regards
Kurt

answered 26 Jun '12, 00:05

Kurt%20Knochner's gravatar image

Kurt Knochner ♦
24.8k1039237
accept rate: 15%