this was the file MCShield detected and removed
https://www.virustotal.com/en/file/223cf2fada3c74d9291d6e6d65061ddd6b1a8d28952e9d328f176aebb92d1c1c/analysis/

Worm:Win32/Dorkbot.I
http://www.microsoft.com/security/portal/threat/encyclopedia/entry.aspx?Name=Worm%3AWin32%2FDorkbot.I

Worm:Win32/Dorkbot.I is a member of the [b]Win32/Dorkbot family; a family of IRC-based worms that spreads via removable drives,[/b] instant messaging programs, and social networks. Win32/Dorkbot.I may capture user names and passwords by monitoring network communication, and may block websites that are related to security updates. It may also launch a limited denial of service (DoS) attack.