The WinPcap libraries are a standardized interface that enables the use of an Ethernet device as a network analyzer. Microsoft removed it from SP2 as a security measure. This change prevents attackers from using a simple break of the system to manipulate WinPcap for sniffing the network.
Now, of course, a miscreant can always install the WinPcap libraries, as can any user who wants to do it themselves. But it does make life a little harder for the people who create networks of bot computers and use them to spam and do other bad things.
So, WinPcap is one of SP2's small changes, but it's a good one. Users who want to install WinPcap can find still find it on the net.
For more information on this topic, visit these SearchSecurity.com resources:
This was first published in October 2004