Wilders Security Forums  

Go Back   Wilders Security Forums > Other Security Topics > malware problems & news
User Name
Password
Register FAQ Members List Calendar Search Today's Posts Mark Forums Read

 
 
Thread Tools Search this Thread
  #1  
Old February 9th, 2005, 08:50 AM
Scott Chicago Scott Chicago is offline
Infrequent Poster
 
Join Date: Feb 2005
Posts: 3
Default NetSpy - Barchart/CBOT ActiveX Controls

Hello,

On my system, when any of my spyware prevention programs are launched (SpyBot, Spyware Guard, MS Antispyware) something starts the msi installer and tries to connect to http://208.169.221.52/cabs/21/ to install what is says is Barchart/CBOT ActiveX Controls.

That website is actually the Chicago Board of Trade site but I have determined that this is trying to install a version of netspy.

I have looked through every running process and I can't find a single one that is anythign other than I would expect. How can I find out what is trying to launch this installer when I start up these programs?

Scott
  #2  
Old February 9th, 2005, 09:51 AM
Sweetie(*)(*)'s Avatar
Sweetie(*)(*) Sweetie(*)(*) is offline
Frequent Poster
 
Join Date: Aug 2004
Location: Venus
Posts: 419
Default Re: NetSpy - Barchart/CBOT ActiveX Controls

Hi, have a look at your start list, if theres anything suspicious research it on web.

Process gaurd from DimondCS may be a help Link

You could try running HJT, post log at fourm that accepts logs, Wilders no longer allows it.
__________________
"Well behaved women rarely make history"
Laurel Thatcher Ulrich
  #3  
Old February 9th, 2005, 10:00 AM
Scott Chicago Scott Chicago is offline
Infrequent Poster
 
Join Date: Feb 2005
Posts: 3
Default Re: NetSpy - Barchart/CBOT ActiveX Controls

Hi,

Thanks. I have already scoured the HJT logs and startup and I can't find anything out of place.

What I'm trying to learn is exactly how to identify a process that launches the msi installer. Something is monitoring the task list and fires when it is sees a monitored process (ApywareGuard etc) start.

It would be nice to know if there is a way to pinpoint that system call.

I'm afraid that this thing may have replaced a typically normal file with its own which makes identifying it by name go out the door. I have only found one other instance of this reported on the web and it was on this site in May of 2004. That thread ended with no resolution.

Anyway, if anyone can point me to some advanced windows analysis tools I would appreciate it.

--Scott
  #4  
Old February 9th, 2005, 02:10 PM
Scott Chicago Scott Chicago is offline
Infrequent Poster
 
Join Date: Feb 2005
Posts: 3
Default Re: NetSpy - Barchart/CBOT ActiveX Controls

Ok, I've made some progress.

I started in safe mode and everything worked fine. Good.
I then started back up as normal and started killing processes to try and see if I could find the one calling the installer. No dice.

I used the console tasklist /svc to expand the services being run by svchost.exe and started knowcking off the unrequired of those. again, no dice.

I pruned the task list and services down to what normally run in safe mode and this stupid thing would still try to install when I open spyware guard etc.

Next I dug through the registry and found a boatload of entries of Barchart, CBOT.ocx and CBOT.msi, many of which included the server information it was trying to connect to. So I nuked all of those.

Under Program files, I found a directory named "barchart" that contained some of the files used by this and I erased all of those.

Now, when I start Spyware Guard or MS Antispyware the installer stills tries to open and immediately closes since the files it is looking for have been deleted by your truly.

The only thing that is still really bugging the heck out of me is what in the world is calling the installer in the first place when I open Spyware Guard?

The files are gone, the reg entries are gone, but ther eis still something tying to do bad things. This is driving me crazy.

Even if you could just reccomend a procedure to isolate this call then that would be cool.

Any ideas?

--Scott
  #5  
Old February 18th, 2005, 05:38 PM
wjkomo
 
Posts: n/a
Default Re: NetSpy - Barchart/CBOT ActiveX Controls

Hi, I am having the same issues. Glad I found your post. I will attempt to make the same changes you did. I'm wondering if this spyware could have come from the CBOT site. Have you used charting at that site? I have.

Bill
  #6  
Old February 24th, 2005, 09:13 PM
wjkomo wjkomo is offline
Infrequent Poster
 
Join Date: Feb 2005
Posts: 1
Default Re: NetSpy - Barchart/CBOT ActiveX Controls

Okay here is the scoop. The CBOT activex control was needed at one time to view charts at the CBOT website. It is not needed any longer, as they now use java. The activex installation happens to use some file names that are the same names as some well known spyware. However, the CBOT claims that this is just a coincidence, and the software is harmless.

Since the activex is no longer needed, just go into Windows Control Panel, go to "Add or Remove Programs", and uninstall Barchart CBOT Activex controls (that is not the exact wording, but close). It will uninstall and the spyware scans will no longer have an issue.
 

Wilders Security Forums > Other Security Topics > malware problems & news « Previous Thread | Next Thread »

Thread Tools Search this Thread
Search this Thread:

Advanced Search

Posting Settings
You may not post new threads
You may not post replies
You may not post attachments
You may not edit your posts

vB code is On
Smilies are On
[IMG] code is On
HTML code is Off
Forum Jump


All times are GMT -4. The time now is 05:56 PM.


Powered by vBulletin® Copyright ©2000 - 2013, Jelsoft Enterprises Ltd.
Copyright ©2002 - 2013, Wilders Security Forums