This is our old Q&A Site. Please post any new questions and answers at ask.wireshark.org.

hi, does wire-shark help track which application is connecting to the internet, just like geoip where we know which ip the os connects to, cause i think there is a rootkit installed in my laptop which connects to a "gay" network somewhere in Korea "175.41.3.0 to 255", i don't want to format and re-install cause all my office work is on the laptop, i tried to use free version of ad-aware but no joy. thanks if anyone knows how to do this.... debby.

asked 31 Jan '12, 21:47

debby%20dale's gravatar image

debby dale
1111
accept rate: 0%


No, as of this writing, Wireshark does not yet provide this capability. The feature has been requested in bug 1184; however, it has not yet been implemented by anyone.

You might look into using other tools instead, such as netstat or Microsoft's Network Monitor tool if you happen to be working on a Windows platform.

permanent link

answered 31 Jan '12, 22:57

cmaynard's gravatar image

cmaynard ♦♦
9.4k1038142
accept rate: 20%

1

Still, Wireshark can help to see which port and destination IP is used in conversations, and the port number helps to track down the application using that port when doing netstat -ano or netstat -anb

(01 Feb '12, 00:45) Jasper ♦♦

i will try ms network monitor cause im using win 7..many thanks for your help/

(02 Feb '12, 02:13) debby dale
Your answer
toggle preview

Follow this question

By Email:

Once you sign in you will be able to subscribe for any updates here

By RSS:

Answers

Answers and Comments

Markdown Basics

  • *italic* or _italic_
  • **bold** or __bold__
  • link:[text](http://url.com/ "title")
  • image?![alt text](/path/img.jpg "title")
  • numbered list: 1. Foo 2. Bar
  • to add a line break simply add two spaces to where you would like the new line to be.
  • basic HTML tags are also supported

Question tags:

×1,620
×26
×18

question asked: 31 Jan '12, 21:47

question was seen: 6,290 times

last updated: 02 Feb '12, 02:13

p​o​w​e​r​e​d by O​S​Q​A