Ask Your Question
0

How to Know Which Software is Calling Out?

asked 2025-12-14 02:23:39 +0000

I have a software from a company that is out of business that I am trying to get licensed, using a name and serial number, however the software is "calling out" and then giving me an error message saying the license is invalid. I've set-up Windows Firewall to block the executable, both inbound and outbound and despite that, the software still fails, even though I have uninstalled and reinstalled it several times (idea being that perhaps there are registry entries left behind). In any case, the firewall rules should be blocking the inbound webpage from telling me the license is invalid, but for some reason it is not, and I suspect that the main executable is not the one that is "calling out" to check the name and license number. I've blocked several other .exe files from the installed directory to no effect. It continues to fail, and so now I want to use Wireshark to identify which software is calling out. It happens when you first run the software, so within just a few second window. Should not be hard to spot.

However, I cannot figure out how to get Wireshark to list what programs are accessing the internet, and years ago I remember clearly that it used to and so now I assume this functionality has been buried beneath all the other features, and I just need help finding it.

Thanks in advance.

edit retag flag offensive close merge delete

2 Answers

Sort by ยป oldest newest most voted
0

answered 2025-12-14 18:36:36 +0000

grahamb gravatar image

There are a couple of options outside of Wireshark that can do this for you:

  1. As noted by @Chuckc, use Process Monitor from SysInternals.
  2. Use the built-in netsh trace command to capture packets and post-process the .etl files to .pcapng using the MS tool etl2pcapng. More info on netsh trace here.
edit flag offensive delete link more
0

answered 2025-12-14 14:33:29 +0000

Chuckc gravatar image

updated 2025-12-14 14:37:33 +0000

Current open issue: 1184: *Shark should support associating TCP and UDP packets with processes

Until then, search for "sysinternals" here on the Ask site for recommendations.
Examples: Get IP/host informations of an app. and UDP Port 889 Broadcast (ip.ttl "Time to Live" only 1)

Examples also on the former Q&A site: "sysinternals site:osqa-ask.wireshark.org"

edit flag offensive delete link more

Your Answer

Please start posting anonymously - your entry will be published after you log in or create a new account.

Add Answer

Question Tools

Stats

Asked: 2025-12-14 02:23:39 +0000

Seen: 38 times

Last updated: 16 hours ago