Wilders Security Forums  

Go Back   Wilders Security Forums > Archived Forums > Closed Sub-Forums > Archived ESET Support Forums > NOD32 version 2 Forum
User Name
Password
Register FAQ Members List Calendar Search Today's Posts Mark Forums Read

 
 
Thread Tools Search this Thread
  #1  
Old June 12th, 2006, 01:29 AM
verktyg verktyg is offline
Infrequent Poster
 
Join Date: Dec 2004
Posts: 17
Default Infected file in NOD32 Cache

KAV32DOS reports that the file FND0.NFI in my NOD32 Cache is
"Infected by virus:not-a-virus:AdWare.Win32.WinAd.bg".

Nothing shows in the NOD32 Control Console Quarantine Window.

Running Win98SE. NOD32, F-Prot DOS, AdAware, SpyBot, a-squared and others find nothing.

Is it safe to delete this file?

Chas.
  #2  
Old June 12th, 2006, 02:16 AM
Marcos Marcos is offline
Eset Moderator
 
Join Date: Nov 2002
Posts: 14,185
Default Re: Infected file in NOD32 Cache

It's definitely a false positive from KAV, nqi files only contain information about files stored in NOD32's quarantine.
  #3  
Old June 12th, 2006, 02:25 AM
verktyg verktyg is offline
Infrequent Poster
 
Join Date: Dec 2004
Posts: 17
Default Re: Infected file in NOD32 Cache

Thanks,

That's what I suspected. Is it safe to delete the file or is it part of NOD32's detection process?

Chas.
  #4  
Old June 12th, 2006, 03:07 AM
Brian N's Avatar
Brian N Brian N is offline
Very Frequent Poster
 
Join Date: Jul 2005
Location: Denmark
Posts: 2,150
Default Re: Infected file in NOD32 Cache

Why do you wanna delete the file when it's an F/P as stated above?
__________________
AntiVir PremiumFD-ISR ProFirefox 3Jetico 2 Firewall
ASAP Member
  #5  
Old June 12th, 2006, 03:11 AM
pykko's Avatar
pykko pykko is offline
Very Frequent Poster
 
Join Date: Apr 2005
Location: Romania...and walking to heaven
Posts: 2,228
Default Re: Infected file in NOD32 Cache

verktyg, you should let the file there.
It's inoffensive and it's used by NOD32 to stoer informations about quarantined itmes as Marcos stated.
__________________

---------------------------------------------------
My security apps: Avira AntiVir Premium * Comodo Firewall PRO * Malwarebytes Anti-Malware * Firefox with Adblock and NoScript
  #6  
Old June 12th, 2006, 04:12 AM
Marcos Marcos is offline
Eset Moderator
 
Join Date: Nov 2002
Posts: 14,185
Default Re: Infected file in NOD32 Cache

It can actually be deleted, especially if there ain't a file with the same name and the nqf extension.
  #7  
Old June 13th, 2006, 01:14 AM
verktyg verktyg is offline
Infrequent Poster
 
Join Date: Dec 2004
Posts: 17
Default Re: Infected file in NOD32 Cache

Thanks for the feedback. I do a lot of technical searches and at least 1 or 2 times a month a bad link takes me to a malware site. NOD32 has been very good at notifying me when some kind of threat tries to attack my system. Most of the time I get a warning screen with options.

On occasion, NOD32 has quarantined the malware before I could respond. I delete the quarantined files when this happens.

Since this file serves no purpose I'll delete it.

Chas.
  #8  
Old March 27th, 2007, 09:06 PM
Zookeeper Zookeeper is offline
Infrequent Poster
 
Join Date: Mar 2007
Posts: 11
Default Re: Infected file in NOD32 Cache

Both the Kapersky & F-Secure online scanners reported that the file FND0.NFI is infected with Backdoor.Win32.Agobot.gen & should be deleted. I've already deleted all the things that NOD32 put into quarantine. Is it safe to delete this file?
  #9  
Old March 27th, 2007, 09:32 PM
The Hammer's Avatar
The Hammer The Hammer is offline
Massive Poster
 
Join Date: May 2005
Location: Toronto Canada
Posts: 5,089
Default Re: Infected file in NOD32 Cache

Quote:
Originally Posted by Zookeeper
Both the Kapersky & F-Secure online scanners reported that the file FND0.NFI is infected with Backdoor.Win32.Agobot.gen & should be deleted. I've already deleted all the things that NOD32 put into quarantine. Is it safe to delete this file?
Try an online scanner that is not associated with the Kaspersky engine such as Bitdefender perhaps.
  #10  
Old March 27th, 2007, 10:37 PM
Lollan's Avatar
Lollan Lollan is offline
Frequent Poster
 
Join Date: Feb 2006
Posts: 288
Default Re: Infected file in NOD32 Cache

Quote:
Originally Posted by The Hammer
Try an online scanner that is not associated with the Kaspersky engine such as Bitdefender perhaps.

Bitdefender runs the Kaspersky engine
  #11  
Old March 28th, 2007, 09:08 AM
Zookeeper Zookeeper is offline
Infrequent Poster
 
Join Date: Mar 2007
Posts: 11
Default Re: Infected file in NOD32 Cache

Basically, what I'm trying to find out is if FND0.NFI is an infected file or not. Has anyone else tried to use one of the online scanners? Has FND0.NFI popped up as being infected? Is this a false positive, or is NOD32 not capable of determining whether FND0.NFI is infected or not? Can I delete FND0.NFI?

As I'm typing this, I'm having Mcafee scan my computer.
  #12  
Old March 28th, 2007, 09:36 AM
danieleb danieleb is offline
Regular Poster
 
Join Date: Dec 2006
Posts: 111
Default Re: Infected file in NOD32 Cache

Quote:
Originally Posted by Lollan
Bitdefender runs the Kaspersky engine
No, I don't think it does.
  #13  
Old March 28th, 2007, 11:43 AM
Zookeeper Zookeeper is offline
Infrequent Poster
 
Join Date: Mar 2007
Posts: 11
Default Re: Infected file in NOD32 Cache

Can I delete FND0.NFI?


Help me Please
  #14  
Old March 28th, 2007, 12:43 PM
BFG BFG is offline
Frequent Poster
 
Join Date: Oct 2004
Location: San Diego
Posts: 482
Default Re: Infected file in NOD32 Cache

Hello,

You initially referred to it as a .nfi file. Is that the extension or is it .nqi?

BFG
  #15  
Old March 28th, 2007, 01:37 PM
Marcos Marcos is offline
Eset Moderator
 
Join Date: Nov 2002
Posts: 14,185
Default Re: Infected file in NOD32 Cache

It's nfi, nqi files only contain information about a particular quarantined file.
  #16  
Old March 28th, 2007, 02:26 PM
DVD+R's Avatar
DVD+R DVD+R is offline
Very Frequent Poster
 
Join Date: Aug 2006
Location: The Antipodes
Posts: 1,724
Default Re: Infected file in NOD32 Cache

Heres your answer And yes please delete it:

C:\Program Files\ESET\cache\FND0.NFI</location> <risk>High</risk> <description>Backdoor.Agent.AIR is a malicious application that runs in the background and allows remote access to your system ...
__________________
'What is understood, doesn't need to be Discussed'


OS: Windows 8 Pro x64 based Systems.
Security: Avira AntiVir Premium/ Outpost Firewall Pro/ Acronis® True Image™ .
  #17  
Old March 28th, 2007, 02:38 PM
Marcos Marcos is offline
Eset Moderator
 
Join Date: Nov 2002
Posts: 14,185
Default Re: Infected file in NOD32 Cache

It's a file detected by NOD32, stored in a safe, encrypted form and pending for submission for analysis. You can delete it anyway.
  #18  
Old March 28th, 2007, 06:02 PM
Zookeeper Zookeeper is offline
Infrequent Poster
 
Join Date: Mar 2007
Posts: 11
Default Re: Infected file in NOD32 Cache

Quote:
Originally Posted by DVD+R
Heres your answer And yes please delete it:

C:\Program Files\ESET\cache\FND0.NFI</location> <risk>High</risk> <description>Backdoor.Agent.AIR is a malicious application that runs in the background and allows remote access to your system ...


Quote:
Originally Posted by Marcos
It's a file detected by NOD32, stored in a safe, encrypted form and pending for submission for analysis. You can delete it anyway.

Thanks for a clear answer. I still don't understand why this file was never picked up by NOD32. Shouldn't I have been given a warning?

Once again, thanks to all of you who have responded to my request for help
  #19  
Old March 28th, 2007, 07:52 PM
Marcos Marcos is offline
Eset Moderator
 
Join Date: Nov 2002
Posts: 14,185
Default Re: Infected file in NOD32 Cache

If it actually wasn't picked up by NOD32 then NOD32 would not have encrypted it and stored it as an nfi file in its cache NOD32 will never detect its encrypted cached and quarantine files.
 

Wilders Security Forums > Archived Forums > Closed Sub-Forums > Archived ESET Support Forums > NOD32 version 2 Forum « Previous Thread | Next Thread »

Thread Tools Search this Thread
Search this Thread:

Advanced Search

Posting Settings
You may not post new threads
You may not post replies
You may not post attachments
You may not edit your posts

vB code is On
Smilies are On
[IMG] code is On
HTML code is Off
Forum Jump


All times are GMT -4. The time now is 06:47 PM.


Powered by vBulletin® Copyright ©2000 - 2013, Jelsoft Enterprises Ltd.
Copyright ©2002 - 2013, Wilders Security Forums