Microsoft NDIS Capture (NdisCap) Service Defaults in Windows 11
Microsoft NDIS Capture.
Default Settings
| Startup type: | System |
| Display name: | Microsoft NDIS Capture |
| Service name: | NdisCap |
| Service type: | kernel |
| Error control: | normal |
| Group: | NDIS |
| Path: | %SystemRoot%\System32\drivers\ndiscap.sys |
| Registry key: | HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\NdisCap |
Default Behavior
Microsoft NDIS Capture is a kernel driver. In Windows 11 it starts at Kernel initialization. If Microsoft NDIS Capture fails to start, the failure details will be recorded into Event Log. Then Windows 11 should boot up and notify the user about the NdisCap service startup failure.
Restore Default Startup Configuration of Microsoft NDIS Capture
1. Run the Command Prompt as an administrator.
2. Copy the commands below, paste them into the command window and press ENTER:
sc config NdisCap start= system
sc start NdisCap
3. Close the command window and restart the computer.
The NdisCap service is using the ndiscap.sys file that is located in the C:\Windows\System32\drivers directory. If the file is removed or corrupted, read this article to restore its original version from Windows 11 installation media.