[Winpcap-users] How Why is WinPcap in my machine? Is someonesniffing me? Or?

Gianluca Varenni gianluca.varenni at gmail.com
Mon May 23 03:12:59 GMT 2005


----- Original Message ----- 
From: "Jay" <twelves at softhome.net>
To: <winpcap-users at winpcap.org>
Sent: Sunday, May 22, 2005 10:52 AM
Subject: [Winpcap-users] How Why is WinPcap in my machine? Is 
someonesniffing me? Or?


> If someone could please take the time to help me out.
>
> I found WinPcap in my startup services.

Actually I think you found the remote capture daemon, which is installed by 
default by winpcap, but it's not active by default.

>
>
>
> O23 - Service: Remote Packet Capture Protocol v.0 (experimental) 
> (rpcapd) - Unknown owner - %ProgramFiles%\WinPcap\rpcapd.exe" -d -f 
> "%ProgramFiles%\WinPcap\rpcapd.ini (file missing)
>
>
> I did not install any of the packet sniffers nor did I find any,
>
> I ran all scanners.
>
> My question,
>
> If it was on my box, is someone sniffing me?

Possible, but not so common.

>
> Are commercial apps using this?

More probable. There are a lot of both free and commercial apps based on 
winpcap, the most comprehensive list that I have is the one on the winpcap 
web site, which however does not include most of the commercial ones (as we 
don't actually know who is using winpcap)

http://www.winpcap.org/misc/links.htm

>
> I cant be sure, but the rpcapd.ini (file missing) tells me its not fully 
> installed?
>
> It was in my add remove program list, and I don't know where how it came 
> from.
>
>
> It is uninstalled now.
>
> Thanks for your help,  I did look all over on google.
>
> I know this is a network tool,  but can this also be used as a Trojan?

Yes, it can. And some virus/adware/... scanners (including the Microsoft 
one, I don't remember its name) sometimes report winpcap as "evil"...


Have a nice day
GV


>
> thanks, and sorry for the intrusion.  I just cant get any info on
> this.
>
>
>
>
>
> _______________________________________________
> Winpcap-users mailing list
> Winpcap-users at winpcap.org
> https://www.winpcap.org/mailman/listinfo/winpcap-users 




More information about the Winpcap-users mailing list