I have a Windows XP/SP2 Pro box that sends out a single UDP packet every
2 to 7 minutes. Even running netstat in a continuous loop never sees the
packet, so I have been having problems trying to find what process is
sending the packet. Also, TCPView has been of no help.

Whereas there is a good chance this box is rooted, and I would never be
able to find the process originating the packet, for now, I want to
presume it has not been compromised.

(Why such an assumption? 1: The box would take over a man-week to
rebuild and would require outside vendor support to do so. 2: The box
owner has been known to load unauthorized software, and there is a good
chance that is what we are dealing with. 3: Have run several
anti-rootkit packages, and they have found nothing.)

Question: Is there a 'netflow-like' tool that will run on XP at log
every single flow originating from the box, including PID? If not, how
would you go about finding the process sending packets?

