Examples of output of script:

contents of file "c:\McAfee.lst"

code:

[KLMVD1_NT]
spldxxxxx NL_NT=00148_000527_02:57:07 4.0.4079 4.0.70 4.0.3a 001011101 NL1 (NT - vs 1.00 L NL1 \\SPLNxxxxx) 171.171.171.171 00A024A835EF mca SPLDxxxxx ('MCA'+'USER001')

Information is also to eventlog for Windows NT environments. So you can see how long it needs to run and you can see the completion message.
Messages are:

code:

Kixtart VIC 3.62 start
Kixtart VIC 3.62c completion

contents of file "c:\McAfee_dump.txt". this file can be created by changing "$debug_mode" to "yes"

code:

Kixtar 3.62 - NT debug mode (vs 1.00) 02:57:08 (on-line)

file c:\McAfee.lst
section 00148
key 00148_000527_02:57:07 NL1
user MCA ('MCA'+'USER001')

workstation SPLDxxxxx (c:\winnt\system32) C=132096 KBytes
domain NL1
ldomain NL1
-> = NL1
NL1 (L)
ip_adress 171.171.171.171 00A024A835EF

debug_mode yes
offline_mode no


Inventory McAfee version

HKEY_LOCAL_MACHINE\Software\McAfee\VirusScan
AlertConfigEXE=C:\PROGRA~1\NETWOR~1\VIRUSS~1\AMGRCNFG.EXE
szVSTempDir=C:\PROGRA~1\NETWOR~1\VIRUSS~1\temp
bNotifyOneMonth=1
bCommEnableDiscovery=0
dwDefaultServerPlatform=1
szCommAddrCache=C:\PROGRA~1\NETWOR~1\VIRUSS~1\NETADDR.CAC
dwCommTimeOut=300
dwRefreshTime=3
Product=VirusScan
szInstallDir=C:\PROGRA~1\NETWOR~1\VIRUSS~1
* szProductVer=4.0.3a
* szSerialNum=E000-AIU3-DUYD
szUpdateEXE=C:\PROGRA~1\NETWOR~1\VIRUSS~1\MCUPDATE.EXE
ConsoleEXE=C:\PROGRA~1\NETWOR~1\VIRUSS~1\MCCONSOL.EXE
szUpdateMsgFile=
szVirusInfoURLValue=http://www.nai.com/vinfo
ScnStatEXE=C:\PROGRA~1\NETWOR~1\VIRUSS~1\SCNSTAT.EXE
ViewLogEXE=Notepad.EXE
WizardEXE=C:\PROGRA~1\NETWOR~1\VIRUSS~1\SCNCFG32.EXE
ScnCfg32EXE=C:\PROGRA~1\NETWOR~1\VIRUSS~1\SCNCFG32.EXE
ShCfg32EXE=C:\PROGRA~1\NETWOR~1\VIRUSS~1\SHCFG32.EXE
ShStatEXE=C:\PROGRA~1\NETWOR~1\VIRUSS~1\SHSTAT.EXE
dwConsoleRefreshRate=0
* szVirDefVer=4.0.4079
* szVirDefDate=10-May-2000
* szEngineVer=4.0.70
bDenyFloppyMountIfInfected=0
bNetshieldEnabled=1
bEnableDriverLog=0
bTaskManagerRunning=2
Scan32EXE=C:\PROGRA~1\NETWOR~1\VIRUSS~1\SCAN32.EXE
TaskMgrEXE=C:\PROGRA~1\NETWOR~1\VIRUSS~1\VsTskMgr.EXE
DAT=C:\PROGRA~1\NETWOR~1\VIRUSS~1\
NotifiedTime=cf070100804301000f0039003a001e00
bLoadAtStartup=1
HKEY_LOCAL_MACHINE\Software\McAfee\VirusScan\McShield
* dwFilesScanned=700
dwLastModified=267870
szLastScanned=Y:\virus.479\check.exe
bNewStatValues=0
* dwFilesCleaned=0
dwFileCacheHits=0
dwFilesInfected=0
* dwFilesDeleted=0
* dwFilesMoved=0
szLastInfected=
szLastVirusName=
HKEY_LOCAL_MACHINE\Software\McAfee\VirusScan\McShield\CurrentVersion
* bVScan=1
wTaskType=2
* bDisableScanning=0
* bScanFloppyOnShutdown=1
bApplyNow=0
* bCanBeDisabled=0
bFileCacheEnabled=1
bNetworkScanEnabled=0
Exclude0=HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\MSExchangeIS\ParametersSystem\DB Log Path
bLimitSize=0
* bLoadAtStartup=1
bLogClean=1
bLogDateTime=1
bLogDelete=0
bLogDetection=1
bLogMove=0
bLogSettings=0
bLogSummary=0
bLogUserName=1
bLogToFile=1
bReloadDATs=0
* bScanAllFiles=0
* bScanCompressed=1
* bScanIncoming=1
* bScanOutgoing=0
dwExitStatus=0
dwLastModified=888
ExcludedItem_0=|pagefile.sys|49|0
NumExcludeItems=2
ExcludedItem_1=C:\Program Files\Network Associates\VirusScan NT| |49|1
szDefProgExts=EXE COM DOC DOT XL? MD? VXD 386 SYS BIN RTF OBD DLL SCR OBT PP? POT SHS MPP MPT OLE XTP XLB CMD OVL DEV VB? JS HTA HTM BAT INI WSH
szLogFileName=C:\Program Files\Network Associates\VirusScan NT\VirusScan Activity Log.txt
szMoveToFolder=C:\Program Files\Network Associates\VirusScan NT\INFECTED
* szProgExts=EXE COM DOC DOT XL? MD? VXD 386 SYS BIN RTF OBD DLL SCR OBT PP? POT SHS MPP MPT OLE XTP XLB CMD OVL DEV VB? JS HTA HTM BAT INI WSH
szRedirectorDeviceNames=LanmanRedirector NwRdr NetWareRedirector
* szTaskName=VirusScan On-Access Monitor
uAction=2
uCloseDelta=500
uKilobytes=100
wDate=0
wTime=0
wFlags=4096
UnloadDriver=0
ExcludedItem_2=|pagefile.sys|49|0
ExcludedItem_3=C:\PROGRA~1\NETWOR~1\VIRUSS~1| |49|1
bDisconnectUser=0
bSendDisconnectMessage=0
szDisconnectMessage=
HKEY_LOCAL_MACHINE\Software\McAfee\VirusScan\Tasks\Upgrade
dwExitStatus=0
wFlags=0
dwLastModified=4
* szTaskName=Automatic Product Upgrade
wTaskType=6
dwInternetAccessType=3
bLogToFile=0
szUpgradeCmd=setup -s
wTime=0
wDate=0
wTaskAttrib=0
wLastExec=0
* bSchedEnabled=0
bApplyNow=1
bAnonymousLogin=0
bDoUpdate=0
bProxy=0
bRetrieveOnly=0
dwProxyPort=80
szFTPPassword=
szFTPUserName=
* szUpdateFTPLocation=
szUpdateStoreFolder=
szUpdateUNCLocation=
uUpdateFrom=1
bUpdateStoreAfter=0
szProxy=
szUpdateShellScript=
HKEY_LOCAL_MACHINE\Software\McAfee\VirusScan\Tasks\Update
wflags=798
dwExitStatus=0
dwLastModified=14
* szLastUpdateFile=dat-4079.zip
* szTaskName=Automatic DAT Update
wTaskType=5
dwInternetAccessType=3
bProxy=0
bAnonymousLogin=0
dwProxyPort=80
szProxy=
* szUpdateFtpLocation=ftp.nai.com/pub/antivirus/datfiles/4.x
szFtpUserName=
szFtpPassword=
szUpdateStoreFolder=
szUpdateUncLocation=\\spln54662\apps\virus\update
szUpdateShellScript=
bRenameExisting=0
bUpdateStoreAfter=0
bDoUpdate=1
bRetrieveOnly=0
bExecAfterUpdate=0
uUpdateFrom=1
wTime=4623
wDate=0
wTaskAttrib=0
bApplyNow=1
wLastExec=0
* bSchedEnabled=0
bLogToFile=0
szUpdateDefaultFtpLocation=ftp.nai.com/pub/antivirus/datfiles/4.x

file_x = c:\Mcafee.lst
section_x = NL1_NT
key_x = spldxxxxx NL1_NT
xxx = 00148_000527_02:57:07 4.0.4079 4.0.70 4.0.3a 001011101 NL1 (NT - vs 1.00 L NL1 \\SPLN59906) 171.171.171.171 00A024A835EF MCA SPLDxxxxx ('MCA'+'USER001')


contents of a file running at our site.

code:

[SPLNX000_NT]
spldxxxxx NL_NT=00119_000428_14:21:51 4.0.4077 4.0.50 4.0.3a 001011101 NL (NT - vs 3.61 L NL \\server2) 171.171.171.171 00A024A835EF ...
server1 NL_NT=00133_000512_16:52:33 4.0.4074 4.0.50 4.0.3a 101011110 NL (NT - vs 3.69 L NL \\server1) 171.171.171.064 0000832DD1E6 ...
server2 NL_NT=00133_000512_16:52:08 4.0.4074 4.0.50 4.0.3a 101011110 NL (NT - vs 3.69 L NL \\server2) 171.171.171.062 4000D710E062 ...
[NL_95]
wd11111 NL_95=00147_000526_07:53:19 4073 4.0.70 4.0.2 1x1001110 NL (95 - vs 3.75 L NL \\server2) 171.171.171.052 4000D700E552 ...
wd22222 NL_95=00146_000525_09:35:12 4067 4.0.50 4.0.3 xxxxxxxxx NL (95 - vs 3.75 L NL \\server1) 171.171.171.057 4000D700E557 ...
wd33333 NL_95=00147_000526_10:40:15 4.0.4061 4.0.50 4.0.3 xxxxxxxxx NL (95 - vs 3.75 L NL \\server2) 171.171.171.050 4000D700E550 ...
wd44444 NL_95=00146_000525_18:13:51 4.0.4073 4.0.70 4.0.3 xxxxxxxxx NL (95 - vs 3.75 L NL \\server2) 171.171.171.044 4000D700E544 ...
[NL_NT_error]
spldyyyyy NL_NT_error=00144_000523_00:23:27 NL (NT - vs 3.74 L NL \\server2) 171.171.171.245 00104BB919A2 ...
wd55555 NL_NT_error=00147_000526_09:38:01 NL (NT - vs 3.75 L NL \\server2) 171.171.171.016 0000832717B4 ...
wd66666 NL_NT_error=00138_000517_15:04:11 NL (NT - vs 3.70 L NL \\server2) 171.171.171.044 4000D700E544 ...

Another interest topic about virus is:

http://kixtart.to/script/board/ubbhtml/Forum2/HTML/000473.html

Greetings.
Any reaction is welcome.

_________________________
email scripting@wanadoo.nl homepage scripting@wanadoo.nl | Links | Summary of Site Site KiXforms FAQ kixtart.org library collection mirror MCA | FAQ & UDF help file UDF kixtart.org library collection mirror MCA | mirror USA | mirror europe UDF scriptlogic library collection UDFs | mirror MCA