Ethereal-users: Re: [Ethereal-users] Ethereal Question

Note: This archive is from the project's previous web site, ethereal.com. This list is no longer active.

From: Andrew Hood <ajhood@xxxxxxxxx>
Date: Sat, 24 Dec 2005 12:52:11 +1100
Row, Chad (Chad) wrote:
> I am noticing some questionable traffic originating from my Windows XP
> system (maybe a virus).   How can I determine which application
> or service is generating the traffic?   (Ethereal is being run from the
> computer in question)

Your best bet is a tool like Tcpview from sysinternals.

http://www.sysinternals.com/Utilities/TcpView.html

ethereal/tethereal/windump will let you collect the traffic but won't
tell you who sent it.

-- 
There's no point in being grown up if you can't be childish sometimes.
                -- Dr. Who