WinPcap network monitoring malware?

mintydroid

Expert Member
Joined
Aug 8, 2013
Messages
1,872
I don't often go into start menu but I noticed an app I didn't install on my computer. When I go to the website it says the following

WinPcap is the industry-standard tool for link-layer network access in Windows environments: it allows applications to capture and transmit network packets bypassing the protocol stack, and has additional useful features, including kernel-level packet filtering, a network statistics engine and support for remote packet capture.

WinPcap consists of a driver, that extends the operating system to provide low-level network access, and a library that is used to easily access the low-level network layers. This library also contains the Windows version of the well known libpcap Unix API.

Thanks to its set of features, WinPcap is the packet capture and filtering engine of many open source and commercial network tools, including protocol analyzers, network monitors, network intrusion detection systems, sniffers, traffic generators and network testers. Some of these networking tools, like Wireshark, Nmap, Snort, ntop are known and used throughout the networking community.

Winpcap.org is also the home of WinDump, the Windows version of the popular tcpdump tool. WinDump can be used to watch, diagnose and save to disk network traffic according to various complex rules.

Is this malware?
 

TheGuy

Expert Member
Joined
Sep 14, 2009
Messages
2,971
No its a driver used by applications to mirror packets on your network interface card. What network utilities have you installed recently.
 

HibiscusTunes

Expert Member
Joined
May 13, 2008
Messages
1,619
Winpcap itself is not malware, it's simply a driver that can be used to capture network traffic. Comes as a prerequisite for some network monitoring software like Wireshark. It uses its own installer when required by software like Wireshark, so check add/remove programs or programs and features for the install date And check for any other software installed on that date.
 

mintydroid

Expert Member
Joined
Aug 8, 2013
Messages
1,872
Didn't think to check what else was installed on that date. Googled a bit and it seems like TP Links powerline software uses this as it was the only other software installed on the same day. That's a relief. Thanks guys :)
 
Top