See: http://www.winpcap.org/misc/faq.htm and search for the word malware on the page.

Inside the Windows kernel, WinPcap runs as a protocol driver. In order to intercept the packets before the TCP/IP stack, you must create an intermediate driver.

Q-20: I installed Zx Sniffer on my PC, and after that, WinPcap based applications fail to work.

This program gives the possibility to convert Packet.lib and wpcap.lib (which are in the Visual C++ standart, COFF) to the OMF standart, the one of C++ Builder. As it is open source it may also be used by others.

It's not possible to capture on PPP/VPN connections on this operating system. The Installer for Windows supports modern Windows operating systems.2.3.7.Update WiresharkBy default the offical Windows package will check for new versions and notify you when they are available.

Q-18: Is it possible to start WinPcap automatically when the system boots? If that's the cause of the problem, you will have to remove the VPN software in order to make the application see outgoing packets.

Only physical interfaces are supported. WinPcap is left installed by default in case other programs need it.2.3.10.Uninstall WinPcapYou can uninstall WinPcap independently of Wireshark using the WinPcap entry in the Programs and Features control panel.

For more information type COFF2OMF in the Help of C++ Builder. If WinPcap is there by itself then it can be safely uninstalled.

WinPcap as you have found is a capturing engine for capturing packets. Updating Wireshark is done the same way as installing it.

Windows 7/2008R2: WinPcap 4.1 or newer is required.

Windows XP/2003: WinPcap 2.3 or newer is required. That string (version of WinPcap) was not found in the source code (using grep in cygwin). No support for IPv6 (update: WinPcap 4.0 beta3). Winpcap Should I Remove It share|improve this answer edited Jun 17 '14 at 10:26 answered Jun 17 '14 at 7:50 Kimm0no 212 This fixed my issue as well - I had some crummy Netgear

On the Choose Components page of the installer you can select from the following: Wireshark - The network protocol analyzer. NOTES: it is possible to capture control packets (LCP and NCP) using the "Generic Dialup" or "Generic NdisWan" adapter (which is always listed even if no dialup connections are available).

Please note that - these two APIs usually return the same version because we *usually* ship driver and packet.dll with the same exact version.