How can I use Wireshark to determine that a rogue program (malware) silently sent an email from my computer?

asked 24 Jun '12, 18:45

Dee's gravatar image

Dee
1111
accept rate: 0%

edited 25 Jun '12, 19:34

helloworld's gravatar image

helloworld
2.6k21739


You can sniff on your computer, but Wireshark will only show that there is something sending an e-mail, however it will not show the process name.

Your options are:

  1. Use Microsoft Network Monitor 3.4. It will show the process name in some cases.
  2. Use a desktop firewall to block AND log any application that tries to send an e-mail

Regards
Kurt

link

answered 26 Jun '12, 00:05

Kurt%20Knochner's gravatar image

Kurt Knochner
8.3k41875
accept rate: 15%

Your answer
toggle preview

Follow this question

By Email:

Once you sign in you will be able to subscribe for any updates here

By RSS:

Answers

Answers and Comments

Markdown Basics

  • *italic* or _italic_
  • **bold** or __bold__
  • link:[text](http://url.com/ "Title")
  • image?![alt text](/path/img.jpg "Title")
  • numbered list: 1. Foo 2. Bar
  • to add a line break simply add two spaces to where you would like the new line to be.
  • basic HTML tags are also supported

Tags:

×11

Asked: 24 Jun '12, 18:45

Seen: 515 times

Last updated: 26 Jun '12, 00:05

powered by OSQA