Help - Search - Members - Calendar
Full Version: netshield.exe scan on jotti
Gladiator Security Forum > Malware Help Forum > HELP! Think you are Infected?
Drac0
hi, i wanted to add a reply to this thread http://gladiator-antivirus.com/forum/index...mp;#entry178639 but was pointed to another page which tells me only admin can add reply to a thread and hence i have to start a new topic.

i have had the same problem for months but since i noticed that by killing netshield.exe (fortunately i had additionally installed process explorer), i am able to get back my task manager and the system behaves normally, i was too lazy to get it fixed especially after some online scans didnt trigger anything.

bobbi flekman wanted more info on netshield.exe, so here goes.

Service
---------
Service load: approx 100%
File: netshield.exe
Status: INFECTED/MALWARE (Note: this file has been scanned before. Therefore, this file's scan results will not be stored in the database)
MD5: b7b0a8baf1cd634c3f373aabd387a36c
Packers detected: -
Bit9 reports: No threat detected (more info)

Scanner results
------------------
Scan taken on 03 Aug 2007 04:20:17 (GMT)
A-Squared: Found nothing
AntiVir: Found BDS/Agent.aqb.18
ArcaVir: Found Trojan.Agent.Aqb
Avast: Found nothing
AVG Antivirus: Found BackDoor.Agent.IAW
BitDefender: Found Backdoor.Agent.AQB
ClamAV: Found nothing
CPsecure: Found nothing
Dr.Web: Found BackDoor.Fonly
F-Prot Antivirus: Found W32/Backdoor.BFTB
F-Secure Anti-Virus: Found Backdoor.Win32.Agent.aqb
Fortinet: Found nothing
Kaspersky Anti-Virus: Found Backdoor.Win32.Agent.aqb
NOD32: Found probably a variant of Win32/Agent (probable variant)
Norman Virus Control: Found nothing
Panda Antivirus: Found W32/Sdbot.KQE.worm
Rising Antivirus: Found nothing
Sophos Antivirus: Found Mal/Dropper-G
VirusBuster: Found nothing
VBA32: Found Trojan.Win32.PSW.XShadow.C
Bobbi Flekman
Hi Drac0,

Thanks for the check at Jotti's. Do you still have the infection? If you do, you'd better add a log from HijackThis so e can check you out.

Good luck.
Drac0
Hi Bobbi,

I did run HiJackThis and Combofix (posted in an earlier thread) and cleaned up my mess. It was really easy to get rid of this one and I wonder why I hadn't bothered to do this earlier :)

I removed some entries with HiJackThis and ran Combofix and (didn't delete but) renamed and moved the netshield.exe to another location just in case you guys need it.

After that was done, it's business as usual for my pc which otherwise had icons hidden or removed on the taskbar apart from other minor quirks.

Thanks.
This is a "lo-fi" version of our main content. To view the full version with more information, formatting and images, please click here.
Invision Power Board © 2001-2009 Invision Power Services, Inc.