Pwcrack-aircrack malware?

Status
Not open for further replies.
Aircrack part of a software suite to capture wireless packets and analyze them for patterns that are used to decipher keys to a variety of different kinds of wireless encryption protocols. I've used it to do security audits with great success. It sends transmissions that cause connected computers to try and reconnect by resending their network key. When it has captured a set of packets (say 20,000 or more ACK transmissions) part of the suite uses an algorithm to find anomalous parts of the transmissions and extract a key. That last part will eat up some processor time for sure, which may be what you're seeing.

So, yeah, it's bad and you need it gone. Look in your tasks for an instance that's taking up alot of cpu time and that filename is the keyword you need to search for online to find a possible fix. For all this to work, a specialized driver must be installed to allow the computer to inject and listen for the packets mentioned above. I would uninstall your wireless device first, then find and reinsall the latest driver version on the manufacturer's site. That might do it, but it probably not going to be that easy.
 
Last edited:
I use airsnort
grin2.gif
 
Originally Posted By: PandaBear
As a rule, reduce your wireless transmit power to reduce its range, to reduce # of people able to see your network. If your router is on one edge/side of your home, foil the wall so that it block the signal.

To annoy the people who hack your network, turn off the router when you are not using it. This "unreliable network" will annoy most bandwidth thieves. Change the password on a regular basis will also be important.



I have a decoy G wireless that's full-open... Which happens to throw any connection attempt into an infinite loop. My real network is standard WEP-key, but hidden, and MAC-controlled.
 
Originally Posted By: PandaBear
As a rule, reduce your wireless transmit power to reduce its range, to reduce # of people able to see your network. If your router is on one edge/side of your home, foil the wall so that it block the signal.

To annoy the people who hack your network, turn off the router when you are not using it. This "unreliable network" will annoy most bandwidth thieves. Change the password on a regular basis will also be important.


Should I change my network to "not broadcasting" and filter mac addresses to allow only my two wireless devices to connect?
 
Originally Posted By: ZZman
Are you running your router firewall and computer firewall?


Windows firewall is on. Mcafee has a built in firewall. My linksys WRT160N firewall is on.
 
Originally Posted By: greenaccord02
Aircrack part of a software suite to capture wireless packets and analyze them for patterns that are used to decipher keys to a variety of different kinds of wireless encryption protocols. I've used it to do security audits with great success. It sends transmissions that cause connected computers to try and reconnect by resending their network key. When it has captured a set of packets (say 20,000 or more ACK transmissions) part of the suite uses an algorithm to find anomalous parts of the transmissions and extract a key. That last part will eat up some processor time for sure, which may be what you're seeing.

So, yeah, it's bad and you need it gone. Look in your tasks for an instance that's taking up alot of cpu time and that filename is the keyword you need to search for online to find a possible fix. For all this to work, a specialized driver must be installed to allow the computer to inject and listen for the packets mentioned above. I would uninstall your wireless device first, then find and reinsall the latest driver version on the manufacturer's site. That might do it, but it probably not going to be that easy.


I'm using windows xp built in wireless utility. I saw last night, I had 20k packets sent and 20k packets received. I notice one time that I had "you are now connected to your wireless network" several times over the past few days. Like I was being kicked off my network and windows xp automatically signed me back in. From what I understand, as long as I don't have a dictionary password, I have more of a phrase with a number on the end of it. btw, there is a wireless network that has a name of "kevin" but it is unsecured. So why would someone go through the trouble of changing their network name but leave their network unsecured? I wonder when I'm booted off my network, I automatically connected to his network and didn't see it.
 
Originally Posted By: firemachine69
Originally Posted By: PandaBear
As a rule, reduce your wireless transmit power to reduce its range, to reduce # of people able to see your network. If your router is on one edge/side of your home, foil the wall so that it block the signal.

To annoy the people who hack your network, turn off the router when you are not using it. This "unreliable network" will annoy most bandwidth thieves. Change the password on a regular basis will also be important.



I have a decoy G wireless that's full-open... Which happens to throw any connection attempt into an infinite loop. My real network is standard WEP-key, but hidden, and MAC-controlled.


I thought these network cracking utilities can "clone" your mac address?
 
Originally Posted By: Cutehumor
Originally Posted By: firemachine69
Originally Posted By: PandaBear
As a rule, reduce your wireless transmit power to reduce its range, to reduce # of people able to see your network. If your router is on one edge/side of your home, foil the wall so that it block the signal.

To annoy the people who hack your network, turn off the router when you are not using it. This "unreliable network" will annoy most bandwidth thieves. Change the password on a regular basis will also be important.



I have a decoy G wireless that's full-open... Which happens to throw any connection attempt into an infinite loop. My real network is standard WEP-key, but hidden, and MAC-controlled.


I thought these network cracking utilities can "clone" your mac address?


They can.

WPA2, hidden SSID and a MAC filter is about as good as you are going to get security-wise.
 
Originally Posted By: Cutehumor
Originally Posted By: Drew99GT
Try scanning with this:

http://www.kaspersky.com/virusscanner


I wasn't able to finish this. after 20 minutes, it only scanned 3% of my hard drive. My laptop has 80 gigs, but only have 10 gigs are full.


Then go to f-secure's online scanner. Afterall it will remove if it finds anything.
 
Originally Posted By: benjamming
Originally Posted By: Cutehumor
Originally Posted By: Drew99GT
Try scanning with this:

http://www.kaspersky.com/virusscanner


I wasn't able to finish this. after 20 minutes, it only scanned 3% of my hard drive. My laptop has 80 gigs, but only have 10 gigs are full.


Then go to f-secure's online scanner. Afterall it will remove if it finds anything.


I did F secure's online scanner. it found five tracking cookies labeled as "malware" it didn't find this pwcrack-aircrack, looks like mcafee deleted it after six attempts.
 
Originally Posted By: firemachine69
I have a decoy G wireless that's full-open... Which happens to throw any connection attempt into an infinite loop. My real network is standard WEP-key, but hidden, and MAC-controlled.


WEP has been cracked a lot time ago, now it is cracked in seconds. Use something with WPA instead.
 
Originally Posted By: OVERK1LL
Did you run the ESET online scanner?


no, ESET online scanner?
 
I'll have to try it when I get home. how many antivirus products are out there? lol
 
Sounds like you might be OK then.

Some of these things embed themselves in System Restore though, so might be an idea to turn it off, which deletes the restore points, then reboot, run a cleanup, then turn it back on if you like it on.
 
Status
Not open for further replies.
Back
Top Bottom