26050

Identifying PID source of DNS request (Windows XP)

I wish to identify the process that is making DNS requests. Looking at the query gives me a clue, but doesn't help me identify the exact process.

I can see the local port number in Wireshark, but the request is too transient to be picked up by TCPView.

Is there a logging tool which will catch DNS requests and PID?

Answer1:

Process Monitor from Sysinternals will give you what you want. Limit the capture to just network activity and you'll see the activity along with the PID and process name. The operation will be <strong>UDP Send</strong> and the path will read something like this: pc-host-name:port -> dns-server:domain (note ":domain" indicates port 53 for dns). The process name and pid will be on the left.

At first I was going to recommend using Netmon 3.4 (from Microsoft) as this will show the process name and pid (pid needs to be added as a column). However, this seemed to have trouble for me as most of the traffic was not tagged with with the process name/pid. I'm not sure why this was the case but it may work for you.

Recommend

  • Load Testing in VS2010 doesn't seem to report results
  • AddressAlreadyInUseException. Port is not released
  • IIS Express Web Server Port Is In Use
  • What are the difference between Cherry-pick and patch apply?
  • Rails 3 Link_to :remote is not triggering RJS
  • How does this compute ? I am trying to understand how the values of H get assigned in the list
  • SQL Server: preventing dirty reads in a stored procedure
  • How to add a user in a different Active Directory Domain in C#?
  • Can I Modify Hibernate/JPA Attribute Dynamically?
  • how to make NSManagedObjectContext dirty (hasChanges = YES) Manually
  • SecurityException Permission Denial MediaProvider READ_EXTERNAL_STORAGE
  • iPhone: 5 seconds video capture
  • Printing out Japanese (Chinese) characters
  • Is there a way to get the process ID of a console program I've just started in the background?
  • Find VMID for running instance
  • rewrite uppercase url to lowercase url htaccess
  • Click on button in another program - FindWindow, C#
  • VSCode change debug shell to bash on windows
  • Detecting null parameter in preprocessor macro
  • Does Apple allow the usage of sysctl.h within iOS applications?
  • Azure webjobs output logs indexing taking very long
  • ThreadStatic in asynchronous ASP.NET Web API
  • Android application: how to use the camera and grab the image bytes?
  • Converting a WriteableBitmap image ToArray in UWP
  • Moving mysql files across servers
  • Reading JSON from a file using C++ REST SDK (Casablanca)
  • Why value captured by reference in lambda is broken? [duplicate]
  • Linq Objects Group By & Sum
  • Using $this when not in object context
  • Ajax jQuery multiple calls at the same time - long wait for answer and not able to cancel
  • Optimizing database types to compact database (SQLite)
  • javascript inside java/jsp code
  • Perl system calls when running as another user using sudo
  • How to limit post in wp_query
  • Delete MySQLi record without showing the id in the URL
  • Rearranging Cells in UITableView Bug & Saving Changes
  • Buffer size for converting unsigned long to string
  • Hits per day in Google Big Query
  • reshape alternating columns in less time and using less memory