WinPcap - Who installed it?

glennc

New member
Power User
VIP
Local time
1:20 PM
Messages
1,024
Howdy fellow members,
While attempting to delete a program (still pending), I came across the application WinPcap 4.1.2 installed on my machine. I don't recall installing it, or even have hearing of it until I saw it. What program might have installed that as part of a package (don't have Wireshark) and is it necessary. Want to delete if not.
Hoping for some good info the program and really appreciate y'alls help.
glennc
 

My Computer

Computer type
PC/Desktop
Computer Manufacturer/Model Number
Self-Built
OS
Windows 7 Ultimate
CPU
AMD Phenom-II X4 965
Motherboard
Gigabyte GA-MA785GM-US2H
Memory
8192 MB DDR2-SDRAM
Graphics Card(s)
ATI Radeon HD 4200
Sound Card
ATI Radeon HD 4200 High Definition Audo
Monitor(s) Displays
LG Electronics W1943
Screen Resolution
1360 X 768
Hard Drives
C: 500 GB Caviar Black SATA
E: 500 GB Caviar Black SATA
PSU
Ultra LSP 750
Case
Ultra XBlaster
Cooling
2 Fans, CPU Fan, PS Fan
Keyboard
Acer
Mouse
Logitech
Internet Speed
6 MB
If you don't want it, I don't see where it would be an issue to uninstall it.

More on WinCap...

As to what application installed it without your knowledge, I don't know...
ScreenShot00063.jpg

Also, look here to see if you have installed any of the listed programs you might want to keep.

Been Wardriving lately? ;)
 
Last edited:

My Computer

Computer Manufacturer/Model Number
Toshiba L355D
OS
Windows 7 Ultimate x64 SP1
CPU
Core2 Duo
Motherboard
Intel
Memory
4 GB
Graphics Card(s)
GM965 on-board
Sound Card
RealTek on-board
Monitor(s) Displays
19"+17"(laptop)
Screen Resolution
1440x900 (x 2)
Hard Drives
500GB Ext. 200GB Internal
PSU
N/A
Case
N/A
Cooling
N/A
In my knowledge such application could be installed by many other applications that has anything to do with monitoring/reading/downloading Internet Packets, my guess would be if you had installed program that would say download video clips from Youtube as example, then chances are that you going to have WinPcap installed as support application.
 

My Computer

Computer Manufacturer/Model Number
XGS PII Dragon "Asus"
OS
windows 7 Pro x64
CPU
AMD Phenom II X4 955 Deneb 45nm Technology
Motherboard
ASUSTeK Computer INC. M4A78 PRO (AM2)
Memory
8.0GB Dual-Channel DDR2 @ 401MHz (5-5-5-18)
Graphics Card(s)
ATI Radeon HD 4800 Series (ATI
Sound Card
VIA High Definition Audio
Monitor(s) Displays
DELL 1908FP @ 1280x1024
Screen Resolution
1280x1024
Hard Drives
977GB SAMSUNG SAMSUNG HD103SI ATA Device (IDE)
Keyboard
HID Keyboard Device
Mouse
HID-compliant mouse
Internet Speed
2 Mb/s so far...
Thanks Gentlemen,
I don't have any of those programs. But if it is doing no harm, maybe I should leave it?
Appreciate your help.
glennc
 

My Computer

Computer type
PC/Desktop
Computer Manufacturer/Model Number
Self-Built
OS
Windows 7 Ultimate
CPU
AMD Phenom-II X4 965
Motherboard
Gigabyte GA-MA785GM-US2H
Memory
8192 MB DDR2-SDRAM
Graphics Card(s)
ATI Radeon HD 4200
Sound Card
ATI Radeon HD 4200 High Definition Audo
Monitor(s) Displays
LG Electronics W1943
Screen Resolution
1360 X 768
Hard Drives
C: 500 GB Caviar Black SATA
E: 500 GB Caviar Black SATA
PSU
Ultra LSP 750
Case
Ultra XBlaster
Cooling
2 Fans, CPU Fan, PS Fan
Keyboard
Acer
Mouse
Logitech
Internet Speed
6 MB
I dunno. If it were me and I didn't know why the program is on my computer and I don't use it...I'd uninstall it.
 

My Computer

Computer Manufacturer/Model Number
Toshiba L355D
OS
Windows 7 Ultimate x64 SP1
CPU
Core2 Duo
Motherboard
Intel
Memory
4 GB
Graphics Card(s)
GM965 on-board
Sound Card
RealTek on-board
Monitor(s) Displays
19"+17"(laptop)
Screen Resolution
1440x900 (x 2)
Hard Drives
500GB Ext. 200GB Internal
PSU
N/A
Case
N/A
Cooling
N/A
That's like I randomly had a nokia cellphone driver install on my computer..... It was reimaged 2 days ago and the driver was installed yesterday... No one in my appt has a Nokia cell phone.... Very simple solution remove it. That happened to me a while back... I honestly think it gets installed when I install one of my asus support apps....
 

My Computer

Computer Manufacturer/Model Number
SMN-Productions
OS
Windows 7 x86/x64, Server 2008r2, Web Server 2008
CPU
i7 v2 3930K Steping stone 2
Motherboard
ASUS Rampage IV Extreme
Memory
G.SKILL Ripjaws Z Series 32GB
Graphics Card(s)
AMD HD 5770
Monitor(s) Displays
Acer 21" and Samsung 20"
Hard Drives
Patriot Pyro 80GB
PSU
1000 Watt
Case
HAF-X
Cooling
4 Fans
Keyboard
Black Widow Ultimate
All Right, it is getting off now. Now we will see the consequences. Heck it is a learning experience. Thanks all!
glennc
 

My Computer

Computer type
PC/Desktop
Computer Manufacturer/Model Number
Self-Built
OS
Windows 7 Ultimate
CPU
AMD Phenom-II X4 965
Motherboard
Gigabyte GA-MA785GM-US2H
Memory
8192 MB DDR2-SDRAM
Graphics Card(s)
ATI Radeon HD 4200
Sound Card
ATI Radeon HD 4200 High Definition Audo
Monitor(s) Displays
LG Electronics W1943
Screen Resolution
1360 X 768
Hard Drives
C: 500 GB Caviar Black SATA
E: 500 GB Caviar Black SATA
PSU
Ultra LSP 750
Case
Ultra XBlaster
Cooling
2 Fans, CPU Fan, PS Fan
Keyboard
Acer
Mouse
Logitech
Internet Speed
6 MB

My Computer

Computer type
PC/Desktop
Computer Manufacturer/Model Number
Bruce ... somewhere in his 40's
OS
Windows 7 Ultimate 32bit SP1
CPU
Intel(R) Core(TM)2 Quad CPU @ 2.40GHz, 2400 MHz
Motherboard
INTEL/D975XBX2
Memory
4 GB
Graphics Card(s)
ATI Radeon HD 2600 Pro
Monitor(s) Displays
Samsung SyncMaster 914v
Screen Resolution
1280 x 1024
Hard Drives
2/500GB each ... ST3500630AS ATA Device.
One is not connected
PSU
Rocketfish 700 W
Case
G.Skill Gigabyte Chassis
Keyboard
Standard PS/2 Keyboard
Mouse
Microsoft PS/2 Mouse
Internet Speed
DSL
Antivirus
Avira Internet Security
Browser
IE 11
Other Info
ATI HDMI Audio

Well Jaycee,
If I understood what that meant, I might be really convinced of it's value. I don't and haven't ever run WinPcap knowingly. Just noticed it in the programs while deleting another. In your opinion is it worth keeping, even if I don't use it manually and maybe some software is using it??? :confused::confused: Thanks for your help.
glennc
 

My Computer

Computer type
PC/Desktop
Computer Manufacturer/Model Number
Self-Built
OS
Windows 7 Ultimate
CPU
AMD Phenom-II X4 965
Motherboard
Gigabyte GA-MA785GM-US2H
Memory
8192 MB DDR2-SDRAM
Graphics Card(s)
ATI Radeon HD 4200
Sound Card
ATI Radeon HD 4200 High Definition Audo
Monitor(s) Displays
LG Electronics W1943
Screen Resolution
1360 X 768
Hard Drives
C: 500 GB Caviar Black SATA
E: 500 GB Caviar Black SATA
PSU
Ultra LSP 750
Case
Ultra XBlaster
Cooling
2 Fans, CPU Fan, PS Fan
Keyboard
Acer
Mouse
Logitech
Internet Speed
6 MB
I don't know much about it, but some programs use it without you even knowing about it.. I play around with educational hacking stuff and the program Cane and Abel is bundled with it, so you may have downloaded something and not even noticed! :)
 

My Computer

Computer Manufacturer/Model Number
Custom built
OS
Windows 7 ultimate 32 bit
CPU
Intel Core 2 Duo Processor T7400 (2.16GHZ)
Motherboard
dont know
Memory
2gb
Graphics Card(s)
NVIDIA GeForce Go 7400 GPU
Hey lavEy,
It appears so. Don't know where, don't know when (Dr. Strangelove reference). The pictures of it running have never been seen. You must be correct.
glennc
 

My Computer

Computer type
PC/Desktop
Computer Manufacturer/Model Number
Self-Built
OS
Windows 7 Ultimate
CPU
AMD Phenom-II X4 965
Motherboard
Gigabyte GA-MA785GM-US2H
Memory
8192 MB DDR2-SDRAM
Graphics Card(s)
ATI Radeon HD 4200
Sound Card
ATI Radeon HD 4200 High Definition Audo
Monitor(s) Displays
LG Electronics W1943
Screen Resolution
1360 X 768
Hard Drives
C: 500 GB Caviar Black SATA
E: 500 GB Caviar Black SATA
PSU
Ultra LSP 750
Case
Ultra XBlaster
Cooling
2 Fans, CPU Fan, PS Fan
Keyboard
Acer
Mouse
Logitech
Internet Speed
6 MB
Sorry to bump such an old thread.

But am slightly concerned about just finding WinPcap 4.1.2 on my laptop.

It looks like it was installed with the software Powerline Utility, that came with TP-Link PA411KIT AV500 500 Mbps Powerline Adapter, last week.

It did not say anything in the documentation about this, unless there is some sort of hidden documentation lols.

I realise that it is most likely necessary for packet capture & encryption over the power-line in my home, but, I cannot find this program anywhere on my KIS 2012 firewall.

What with them being a Chinese company, albeit a very popular one, I am slightly concerned it could be used for packet capture / transmitting to Chinese servers somewhere.

Should I be concerned? If I should be, then 100,000s of others should be. Thank-you in advance.
 

My Computer

OS
Windows 7 Home Premium 64bit
Freemake or a flash video downloader program

My WinPcap folder was created when I downloaded one of the following: IE add-ons Video Capture, Freemake's Video Downloader or some similar type download. I ditched Realplayer and was looking for a 'right-click to download' video app.
 

My Computer

OS
7 Ultimate 32 bitsy's
My WinPcap folder was created when I downloaded one of the following: IE add-ons Video Capture, Freemake's Video Downloader or some similar type download. I ditched Realplayer and was looking for a 'right-click to download' video app.

It's from one of the Freemake Video software downloads, I downloaded and installed Freemake Video downloader and WinPcap appeared on my system, it is safe to uninstall, actually you SHOULD uninstall it, you'll see why below.

When you download Freemake products you are essentially just downloading the downloader, after you double click the file and go through the process of denying all the garbage that it comes with and setting a install destination folder, Freemake then downloads the installer from the web and automatically installs the product, in the process it sneaks WinPcap onto your system. Basically what WinPcap is, is a network sniffer, read below from Yahoo Answers ......

"WinPcap is software that allows your network interface card to (NIC) operate in "promiscuous" mode. Normally if a NIC sees traffic addressed to another NIC on the network, it ignores it. If you are running a network sniffer application, you may have a need to capture that traffic for inspection. Putting a NIC in promiscuous mode allows your NIC to capture traffic addressed to another machine and pass it to the sniffer application.

Normally you should not find WinPcap on your machine unless you also have a network sniffer such as WireShark also installed. If the machine was previously used by a network administrator or a network engineer they may have simply forgot to uninstall it when they uninstalled the sniffer app.

It is also possible that it is there for some nefarious purpose. It's conceivable that your machine may have been hijacked in order to sniff other network traffic on your network and report that to an outside attacker. This would be an advanced case of cracking and while I've never seen it personally, it's conceivable -- and rather scary.

Unless you are also running a network sniffer application or other network analysis tools, you have no need for WinPcap. Remove it from your machine if you can. It should be listed in the Add & Remove Programs listing. If it isn't, you can just delete the parent folder (unless it's residing in a system folder!) or delete the executable itself. It's a Unix port application and does not normally weave itself into the Windows OS very deeply."


After uninstalling the program you may want to run a malware scan and hijackthhis just to make sure everything is on the up and up.
 

My Computer

Computer type
PC/Desktop
Computer Manufacturer/Model Number
HP
OS
Windows 8 Pro / Windows 7 Home Premium x64 dual boot
Memory
6 gigs
Graphics Card(s)
Nvidia GEForce 9400 GT
Screen Resolution
1600 x 900
Hard Drives
Internal - Western Digital 600 gb HDD
Internal - Western Digital 250 gb HDD
External - Western Digital 1 TB HDD
Antivirus
Avast!
Browser
Pale Moon
Back
Top