ANNOUNCEMENT: Live Wireshark University & Allegro Packets online APAC Wireshark Training Session
April 17th, 2024 | 14:30-16:00 SGT (UTC+8) | Online

Wireshark-dev: [Wireshark-dev] Npf.sys startup

From: Gerald Combs <gerald@xxxxxxxxxxxxx>
Date: Fri, 14 Sep 2007 17:26:05 -0700
A recent thread on the winpcap-users mailing list touched on a problem with
Wireshark on Vista.  When a user doesn't have elevated privileges (the default
under Vista), and npf.sys has to be started manually (the default everywhere),
npf.sys fails to load on demand and you can't see any interfaces or capture traffic.

I'd like to get this resolved before the next release, since it's becoming an
issue for more and more users.  I've checked in a change that warns users in
TShark and Wireshark on Vista if npf.sys isn't running.  Should we also enable
automatic NPF startup in the NSIS package by default, at least for Vista?