This is our old Q&A Site. Please post any new questions and answers at ask.wireshark.org.

Just upgraded to the latest version, 2.0.1 according to the Properties of the .exe file, the one with the "legacy"version attached and the new USPcap addition. Well, for the first time since I started using Wireshark YEARS ago, neither version will load. The non-Legacy version starts with a window, shows the components being loaded up to what seems to be the last piece, then becomes "Not responding", and I must kill the process. Then I tried the legacy version, which seems to start as the the older versions did with a small window showing the components loading, again seems to get to the last piece then also becomes "not responding" and must be killed. Is this the first version by this Riverbed company? I used the "check for upgrade" from within the last version, even though it was Secunia PSI that tipped me off an upgrade was available.

Any ideas folks?

asked 02 Jan '16, 15:16

survivor7812's gravatar image

survivor7812
21113
accept rate: 0%


Do you have a configuration directory (%APPDATA%\Wireshark) left over from the last time you used Wireshark? If so, can you try renaming it?

permanent link

answered 02 Jan '16, 15:27

Gerald%20Combs's gravatar image

Gerald Combs ♦♦
3.3k92258
accept rate: 24%

edited 02 Jan '16, 15:29

This is generally a symptom of an issue in WinPcap, the mechanism used to capture traffic on Windows. Wireshark uses WinPcap at startup to query the list of interfaces that can be used for captures.

The actual issue has never been resolved, but uninstalling Wireshark, uninstalling WinPcap, if it remains, ensuring that there is no copy of npf.sys in %WINDIR%\system32\drivers\, reboot, and then reinstalling Wireshark (installing WinPcap when offered) usually does the trick. Make sure you run the installer as Administrator, it should do this automatically, but if you don't get asked for permissions, cancel, then right-click the installer and select "Run as Administrator".

Riverbed has been sponsoring Wireshark for some time, but Wireshark is still produced and maintained by volunteers led by @Gerald Combs.

permanent link

answered 03 Jan '16, 07:35

grahamb's gravatar image

grahamb ♦
19.8k330206
accept rate: 22%

edited 22 Apr '16, 03:22

Thanks, folks, but the problem self resolved after a reboot or three, as tech problems are wont to do. I have now gotten both the legacy and non-legacy versions to work.

Thanks, again! Good to see the program is still maintained by the author, so I hope Riverbed pays him well! :-)

permanent link

answered 03 Jan '16, 14:37

survivor7812's gravatar image

survivor7812
21113
accept rate: 0%

Same for me ...

(22 Apr '16, 01:00) robert_
Your answer
toggle preview

Follow this question

By Email:

Once you sign in you will be able to subscribe for any updates here

By RSS:

Answers

Answers and Comments

Markdown Basics

  • *italic* or _italic_
  • **bold** or __bold__
  • link:[text](http://url.com/ "title")
  • image?![alt text](/path/img.jpg "title")
  • numbered list: 1. Foo 2. Bar
  • to add a line break simply add two spaces to where you would like the new line to be.
  • basic HTML tags are also supported

Question tags:

×32
×7
×1

question asked: 02 Jan '16, 15:16

question was seen: 3,278 times

last updated: 22 Apr '16, 03:22

p​o​w​e​r​e​d by O​S​Q​A