usbpcap.sys

USBPcap Sniffer Driver

Wireshark Foundation, Inc.

It runs as a Windows kernel mode device driver named “USBPcap Capture Service”.
Publisher:
USBPcap  (signed by Wireshark Foundation, Inc.)

Product:
USBPcap Sniffer Driver

Description:
USBPcap Driver

Version:
1.1.0.0-g794bf26

MD5:
67a98077a9a449ff60c0f56a673c56f2

SHA-1:
a6598b65ad9d7fc5b300fba608f532bae6ae23c3

SHA-256:
c22269448c16e7ba06f2396a0b9ffe17bb1b5a7189cc8fcf083eb37d14e2deb8

Scanner detections:
1 / 68

Status:
Clean  (1 probable false positive detection)

Explanation:
This is mosty likely a false positive detection, the file is probably clean.

Analysis date:
6/24/2025 11:13:48 AM UTC  (today)

Scan engine
Detection
Engine version

Avira AntiVirus
W32/Ramnit.C
7.11.30.172

File size:
31.7 KB (32,456 bytes)

Product version:
1.1.0.0-g794bf26

Copyright:
(c) 2013-2015 Tomasz Mon

Original file name:
USBPcap

File type:
Driver (Win32 SYS)

Language:
English (United States)

Common path:
C:\Windows\System32\drivers\usbpcap.sys

Digital Signature
Authority:
DigiCert Inc

Valid from:
7/21/2015 1:00:00 AM

Valid to:
7/27/2016 1:00:00 PM

Subject:
CN="Wireshark Foundation, Inc.", O="Wireshark Foundation, Inc.", L=Davis, S=California, C=US, PostalCode=95618, STREET=338 Madson Pl, SERIALNUMBER=C3061103, OID.1.3.6.1.4.1.311.60.2.1.2=California, OID.1.3.6.1.4.1.311.60.2.1.3=US, OID.2.5.4.15=Private Organization

Issuer:
CN=DigiCert EV Code Signing CA (SHA2), OU=www.digicert.com, O=DigiCert Inc, C=US

Serial number:
0B49E2E7A42940E43EDAC36D6386A3FC

File PE Metadata
Compilation timestamp:
10/2/2015 10:05:29 AM

OS version:
6.1

OS bitness:
Win32

Subsystem:
Native (none required)

Linker version:
9.0

CTPH (ssdeep):
384:v6OgaEAZgM86ahtnUCwGMIAqEkgTpy1S5YFNh+Juq4a9uiZgDZsHLEGoAHKn4o:SaE4gMy5UoMIEkgTpUaYFfYsmucBm4

Entry address:
0x4C3E

Entry point:
8B, FF, 55, 8B, EC, E8, BD, FF, FF, FF, 5D, E9, AE, C8, FF, FF, CC, CC, B4, 4C, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 02, 51, 00, 00, 14, 2A, 00, 00, A0, 4C, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 10, 51, 00, 00, 00, 2A, 00, 00, AC, 4C, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 24, 54, 00, 00, 0C, 2A, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, CE, 4D, 00, 00, F6, 4D, 00, 00, 00, 00, 00, 00, FE, 53, 00, 00, 00, 00, 00, 00, 22, 4E, 00, 00, 34, 4E, 00, 00, 54, 4E...
 
[+]

Entropy:
6.7862

Code size:
18.4 KB (18,816 bytes)

Driver
Display name:
USBPcap Capture Service

Service name:
USBPcap

Type:
Kernel device driver (KernelDriver)


Scan usbpcap.sys - Powered by Reason Core Security