Want to win a PS4? Go Premium and enter to win our High-Tech Treats giveaway. Enter to Win


i don't have wireshark installed. why is winpcap trying to run?

Posted on 2014-12-26
Medium Priority
Last Modified: 2014-12-26
I am getting the following repeatedly in my event logs, but wireshark is not installed.  Does anyone have any insight?  Am I being attacked?

Event ID 7000: The WinPcap Packet Driver (NPF) service failed to start due to the following error:  The system cannot find the file specified.

Event ID 61703: Mbamchameleon Failed to obtain file name information - C00000BE
Question by:mkraemer11
Welcome to Experts Exchange

Add your voice to the tech community where 5M+ people just like you are talking about what matters.

  • Help others & share knowledge
  • Earn cash & points
  • Learn & ask questions
  • 3
  • 3
  • 2
  • +1
LVL 71

Accepted Solution

Qlemo earned 668 total points
ID: 40518653
The latter message is an issue with MalwareBytes' Auto-Protect feature.

PCap might still be "installed", at least as a service,  but the binaries removed already. Simple solution is to set the service to disabled.  But I would remove the service entry, either by re-installing and uninstalling again, or by removing the entry in registry,  or removing it with sc,  ...
LVL 98

Assisted Solution

by:John Hurst
John Hurst earned 668 total points
ID: 40518671
Also, WinPCap is a separate install from Wireshark. So if you had Wireshark installed and then uninstalled it, WinPCap would stay installed.

Look in Programs and Features for WinPCap and uninstall it.
LVL 15

Assisted Solution

ZabagaR earned 664 total points
ID: 40518673
Run msinfo32.exe and go to Software Environment -> system drivers
do you see npf listed?

You probably have winpcap left over in part.

you can manually delete packet.* and wpcap.dll as well as npf.sys, see:

They're trying to manually remove in order to install a newer version of winpcap but same thing...

How about this from a command prompt?
sc config npf start= disabled

you should get "success" after running that line. then reboot. or do sc stop npf from command line
When ransomware hits your clients, what do you do?

MSPs: Endpoint security isn’t enough to prevent ransomware.
As the impact and severity of crypto ransomware attacks has grown, Webroot fought back, not just by building a next-gen endpoint solution capable of preventing ransomware attacks but also by being a thought leader.


Author Comment

ID: 40518709
Wireshark and WinPCap is not currently nor has it ever been installed on this PC therefore could not be uninstalled to leave anything behind.  both event IDs started  on 12/17 and have been filling up my logs ever since.  

- npf.sys is not present
- winpcap is not in Programs and Features list
- packet.dll is not present in windows/system32
- wpcap.dll is not present in windows/system32
- full search of C: produces no results for either as well.

Any other advice?  Why would it be trying to run when WinPCap is not and has not been installed on this PC?
LVL 98

Expert Comment

by:John Hurst
ID: 40518718
Look for the Cain Agent install. Maybe someone tried to install the Agent on your computer. This has never happened to me (although I know and have used Cain (oxid.it) ) . Cain uses WinPCap which is what brings it to mind.

I cannot understand why your system would reference WinPCap if never installed. WinPCap is not a virus, nor is Cain.
LVL 71

Expert Comment

ID: 40518734
As has been said, WinPcap is used for several products, and probably came with once of them. That you cannot find the files belonging to it does not come as a surprise. But the service might still be there.
And I cannot see how both eventlog entries should be connected.

Author Comment

ID: 40518744
I don't recall installing anything other than C Cleaner in the past month, but I will take a closer look to see if I just overlooked something.

Thank you all for your quick replies.

Author Comment

ID: 40518748
Although I don't recall installing anything other than C Cleaner (aside from Microsoft updates) in the past month and can't find any of the associated files all replies have made me feel better about knowing that I am not under some sort of attack.  Split points across the three replies as they were all similar.
LVL 98

Expert Comment

by:John Hurst
ID: 40518749
Thanks for the update and I was happy to help.

Featured Post

Free Tool: IP Lookup

Get more info about an IP address or domain name, such as organization, abuse contacts and geolocation.

One of a set of tools we are providing to everyone as a way of saying thank you for being a part of the community.

Question has a verified solution.

If you are experiencing a similar issue, please ask a related question

If you're a modern-day technology professional, you may be wondering if certifications are really necessary. They are. Here's why.
Ransomware, the malware that locks down its victim’s files until they pay up, has always been a frustrating issue to deal with. However, a recent mobile ransomware will make the issue a little more personal… by sharing the victim’s mobile browsing h…
This Micro Tutorial will give you a introduction in two parts how to utilize Windows Live Movie Maker to its maximum capability. This will be demonstrated using Windows Live Movie Maker on Windows 7 operating system.
This Micro Tutorial will give you a basic overview of Windows Live Photo Gallery and show you various editing filters and touches to photos you can apply. This will be demonstrated using Windows Live Photo Gallery on Windows 7 operating system.

604 members asked questions and received personalized solutions in the past 7 days.

Join the community of 500,000 technology professionals and ask your questions.

Join & Ask a Question