This is a static archive of our old Q&A Site. Please post any new questions and answers at ask.wireshark.org.

How to protect wireshark from termination?

0

Some application shutdown after start using wireshark or terminate wireshark after it launced. How to protect wireshark from termination?

Thank you.

asked 01 Nov '10, 18:35

TSSENE's gravatar image

TSSENE
1111
accept rate: 0%

It's not a virus or trojan. I was try to rename wireshark before posting this but it's can't help. Yes, It's prevent wireshark to capture, I know. So, How to protect wirehark from terminate?

(02 Nov '10, 19:52) TSSENE

3 Answers:

1

Is Wireshark is terminated immediately after you launch it? If so, your system may be infected with a trojan. Conficker and the fake Wireshark Antivirus will both kill any instances of Wireshark they find running, and I'd assume other malware does the same thing.

If that is the case you might be able to work around the problem by renaming the wireshark.exe executable but that won't fix the more serious underlying issue.

answered 02 Nov '10, 11:38

Gerald%20Combs's gravatar image

Gerald Combs ♦♦
3.3k92258
accept rate: 24%

0

Are you up to something shady?????????

If something is hunting down WireShark specifically then it's probably trying to prevent you from gathering a capture. You can try to rename the WireShark.exe to something else before running it.

answered 02 Nov '10, 11:29

GeonJay's gravatar image

GeonJay
4705922
accept rate: 5%

0

I've seen this one as well - definitely a trojan.

Start off by using an up-to-date malware killer; I used Malwarebytes free anti-malware package. I then used Spybot S&D to double-check and immunize.

answered 03 Nov '10, 19:35

wesmorgan1's gravatar image

wesmorgan1
411101221
accept rate: 4%