Wireshark can't do that, but Microsoft's Network Monitor or (newer) Microsoft Message Analyzer can match packets to process. So you can first capture with one of the above tools, save a capture to file and open it with wireshark.