Security Basics mailing list archives

Re: How to find a process


From: levinson_k () securityadmin info
Date: 14 Jun 2007 00:53:57 -0000

To identify the Windows process that is sending out TCP/IP traffic... on the source system, you can install just about 
any free or not-free client-based / personal firewall software.  

You can also install Microsoft's free Port Reporter, though it doesn't say whether it is compatible with Windows Vista 
yet:

www.microsoft.com/downloads/details.aspx?FamilyID=69ba779b-bae9-4243-b9d6-63e62b4bcd2e

If the results come back that "System" or SVCHOST.EXE is generating the traffic, then you'll have to use a trick to try 
to find out which subordinate process is actually generating the traffic.

kind regards,

Karl Levinson
http://securityadmin.info



Current thread: