Welcome, Guest. Please login or register.
January 03, 2010, 07:16:12 AM

Login with username, password and session length

347037 Posts
38367 Topics
87210 Members

Latest Member: jolei

Search:     Advanced search | Tag Cloud
+  Welcome to the Comodo Forum
|-+  Desktop Security Products
| |-+  Comodo Instant Malware Analysis Online - CIMA
| | |-+  CIMA - am I downloading it correctly
« previous next »
Pages: [1] Go Down Print
Author Topic: CIMA - am I downloading it correctly  (Read 3323 times)
overfifty
Comodo Loves me
****
Offline Offline

Posts: 146


« on: February 02, 2009, 06:54:46 AM »

My NOD 32 antivirus has said that I am possibly having a threat. It states it is possibly a varient to win 32/adware. agent and each time the size is exactly the same with the same varient.

I am going into the NOD32 log file and copying the said possible threat which starts  [ C:\ and ends in....ocx ]  and then pasting this onto the CIMA line  - one of the lines says process - failed - but the assesment is that it is not a threat. Am I doing it correctly .
Logged
Toxteth O'Grady
Comodo's Hero
*****
Offline Offline

Posts: 538


« Reply #1 on: February 03, 2009, 06:26:00 AM »

I don't think CIMA is capable of analysing .ocx files.

You could upload the file to one of these sites and see what they report:
http://www.virustotal.com/
http://www.virscan.net/
http://scanner.novirusthanks.org/index.php
« Last Edit: February 03, 2009, 06:29:12 AM by Toxteth O'Grady » Logged
overfifty
Comodo Loves me
****
Offline Offline

Posts: 146


« Reply #2 on: February 03, 2009, 12:36:55 PM »

thanks toxteth,

I tried the middle one , but it says that "0 bytes sent , possibly firewall or malware stopping it being sent". I tried virustotal and it seemed forever to down load the file , so what I have done is send my suspect ones via their e-mail address.

What are .ocx files anyway ?
Logged
Toxteth O'Grady
Comodo's Hero
*****
Offline Offline

Posts: 538


« Reply #3 on: February 03, 2009, 01:29:50 PM »

I'm sorry to hear things didn't work as expected, but hopefully you'll get a reply to your e-mail.

Alternatively, you could upload the file to Avira\Antivir. They will send you a confirmation immediately after receiving the file and you'll get a final report, after the file was analysed.

These guys are very fast. Usually the final report (which clearly indicates whether the file is infected or not) is send within 1 or 2 days. If you want 100% certainty, this is the way to go (because the file is actually analysed, not just checked by scanners).

http://analysis.avira.com/samples/index.php



What are .ocx files, you ask? I can't help you there.
This should explain it, although I still don't understand.   Cheesy
http://www.webopedia.com/TERM/O/OCX.html
Logged
overfifty
Comodo Loves me
****
Offline Offline

Posts: 146


« Reply #4 on: February 04, 2009, 02:59:13 PM »

You didnt understand!!!!  - I stood no chance, I read it 3 times and even took a copy to my local takeaway in case they understood the language but they couldnt help either - bring back old fashioned "plain English"

I thought about it and I believe the fault probably lies with me . I thought I was downloading it correctly by copying the offending line on the log report and then pasting it onto the scan sites. so I think I am just pasting a line of text? To be honest  I am not sure what I actually have to send off, whether it is the whole of the log file report or if I was right by just sending the one line ?

But as always  - thanks for the help thus far..
Logged
ilpin55
Newbie
*
Offline Offline

Posts: 1


« Reply #5 on: February 04, 2009, 03:59:37 PM »

How do you scan and download comodo firewall?
Logged
Toxteth O'Grady
Comodo's Hero
*****
Offline Offline

Posts: 538


« Reply #6 on: February 04, 2009, 04:18:12 PM »

I thought about it and I believe the fault probably lies with me . I thought I was downloading it correctly by copying the offending line on the log report and then pasting it onto the scan sites. so I think I am just pasting a line of text? To be honest  I am not sure what I actually have to send off, whether it is the whole of the log file report or if I was right by just sending the one line ?

But as always  - thanks for the help thus far..


If you managed to paste the one line you mentioned before, C:.....ocx, and clicked send, you did everything right. Although I don't know how you did it. I can't paste anything on the websites from my earlier post.   Huh   Cheesy

Perhaps something went wrong using copy\paste. Try using the browse button on, for example, VirusTotal and select the file that way. That should work.
Logged
overfifty
Comodo Loves me
****
Offline Offline

Posts: 146


« Reply #7 on: February 05, 2009, 07:53:47 AM »

Toxteth,
I went into my 'scanner report' in NOD32  and highlighted the line which said it was possibly a threat, right clicked and copied it. I then pasted it onto the line of the visus scan deleting all the other words such as ' possibly a varient of adware agent , item cleansed ... blah.... blah ..etc so that I just left the C:\ ........... .ocx

ilpinn 55,
I assume you posted this in the wrong place ?
Logged
pranaygtr
Comodo Loves me
****
Offline Offline

Posts: 114



WWW
« Reply #8 on: August 23, 2009, 03:21:36 PM »

Eset has removed the file from that location and placed it in Quarantine or deleted it.
That's why you get "0 bytes" and/or "another program may be using it".

Basically, that file don't exist in that location no more.
Logged

panic
Global Moderator
Comodo's Hero
*****
Offline Offline

Posts: 7697


... and I say to myself, "What a wonderful world"


« Reply #9 on: August 23, 2009, 05:59:29 PM »


What are .ocx files, you ask? I can't help you there.
This should explain it, although I still don't understand.   Cheesy
http://www.webopedia.com/TERM/O/OCX.html


OCX files, in plain English, as small programs generally designed to perform one or two specific functions. They may have been installed as part of application X, but the OCX parts of application X can be called and used by other applications.

It's a way of sharing functionality between applications. This sharing can be for good or not-so-good purposes.

Hope this helps,
Ewen :-)
Logged

As your mums would say, "If you can't play nice with all the other kiddies, go home".
All users are asked to please read and abide by the  Comodo Forum Policy.
If you don't like it, don't use the forum.
Tags:
Pages: [1] Go Up Print 
« previous next »
Jump to:  

SSL Certificate Free Virus Removal Firewall
Page created in -0 seconds with 18 queries.
Powered by SMF 1.1.11 | SMF © 2006, Simple Machines LLC
Seo4Smf v0.2 © Webmaster's Talks
Design by 7dana.com