Microsoft NDIS Capture (NdisCap) Service Defaults in Windows 11

Microsoft NDIS Capture.

Default Settings

Startup type: System
Display name:Microsoft NDIS Capture
Service name:NdisCap
Service type:kernel
Error control:normal
Group:NDIS
Path:%SystemRoot%\System32\drivers\ndiscap.sys
Registry key:HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\NdisCap

Default Behavior

Microsoft NDIS Capture is a kernel driver. In Windows 11 it starts at Kernel initialization. If Microsoft NDIS Capture fails to start, the failure details will be recorded into Event Log. Then Windows 11 should boot up and notify the user about the NdisCap service startup failure.

Restore Default Startup Configuration of Microsoft NDIS Capture

1. Run the Command Prompt as an administrator.

2. Copy the commands below, paste them into the command window and press ENTER:

sc config NdisCap start= system
sc start NdisCap

3. Close the command window and restart the computer.

The NdisCap service is using the ndiscap.sys file that is located in the C:\Windows\System32\drivers directory. If the file is removed or corrupted, read this article to restore its original version from Windows 11 installation media.