Below if the HJT log. Any help would be appreciated.
Logfile of HijackThis v1.99.1
Scan saved at 2:07:21 PM, on 12/19/2006
Platform: Windows 2000 SP4 (WinNT 5.00.2195)
MSIE: Internet Explorer v6.00 SP1 (6.00.2800.1106)
Running processes:
C:\WINNT\System32\smss.exe
C:\WINNT\system32\winlogon.exe
C:\WINNT\system32\services.exe
C:\WINNT\system32\lsass.exe
C:\PROGRA~1\CISCOS~1\VPNCLI~1\cvpnd.exe
C:\WINNT\system32\svchost.exe
C:\MAINT\sid\DISTH\DISTH.EXE
C:\WINNT\system32\spoolsv.exe
C:\Program Files\Network Associates\VirusScan\Avsynmgr.exe
C:\WINNT\System32\svchost.exe
C:\WINNT\system32\dllcache\dllhost.exe
C:\WINNT\system32\cache\dllhost.exe
C:\WINNT\system32\dllcache\dllhost.exe
c:\winnt\system32\cache\spoolsvr.exe
c:\winnt\system32\dllcache\svhost.exe
C:\Tivoli\lcf\bin\w32-ix86\mrt\lcfd.exe
C:\WINNT\system\microsft.exe
C:\WINNT\system32\dllcache\lsass.exe
c:\winnt\system32\dllcache\svchost.exe
C:\WINNT\system32\nvsvc32.exe
C:\Program Files\PIPC\BIN\pilogsrv.exe
C:\Program Files\PIPC\BIN\pinetmgr.exe
C:\Program Files\Network Associates\VirusScan\VsStat.exe
C:\WINNT\system32\MSTask.exe
C:\Program Files\Network Associates\VirusScan\Vshwin32.exe
C:\WINNT\system32\FLRSERV.EXE
C:\WINNT\system32\stisvc.exe
C:\WINNT\System32\WBEM\WinMgmt.exe
C:\WINNT\system32\svchost.exe
C:\Program Files\PIPC\BIN\pimsgss.exe
C:\Program Files\Network Associates\VirusScan\Avconsol.exe
C:\Program Files\Common Files\Network Associates\McShield\Mcshield.exe
C:\WINNT\MS\SMS\clicomp\apa\Bin\smsapm32.exe
C:\WINNT\Explorer.EXE
C:\WINNT\MS\SMS\CORE\BIN\LAUNCH32.EXE
C:\WINNT\system32\dla\tfswctrl.exe
C:\Tivoli\lcf\bin\w32-ix86\mrt\lcfep.exe
C:\WINNT\regsrvr32.exe
C:\WINNT\system32\winsock32.exe
C:\Program Files\Adobe\Acrobat 5.0\Distillr\AcroTray.exe
C:\WINNT\MS\SMS\CLICOMP\SWDist32\bin\smsmon32.exe
C:\Program Files\Hewlett-Packard\Digital Imaging\bin\hpotdd01.exe
C:\Lotus\smartctr\SMARTCTR.EXE
C:\Program Files\PrecisionTime\PrecisionTime.exe
C:\PROGRA~1\WinZip\winzip32.exe
C:\unzipped\hijackthis\HijackThis.exe
R1 - HKCU\Software\Microsoft\Internet Explorer,SearchURL = http://www.the818search-co.com/sp2.php
R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Bar = http://www.the818search-co.com/sp2.php
R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Page = http://www.the818search-co.com/sp2.php
R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://iptexmill.ipaper.com/
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://inside.abb.com
R1 - HKCU\Software\Microsoft\Internet Explorer\Search,SearchAssistant = http://www.the818search-co.com/sp2.php
R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Window Title = Microsoft Internet Explorer provided by ABB
R1 - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings,ProxyServer = uswndproxy.us.abb.com:80
R1 - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings,ProxyOverride = 127.0.0.1;*.abb.com
O1 - Hosts: 172.18.77.11 TEXPM1SADBSVR
O1 - Hosts: 172.18.77.17 TEXPM1SACAM01
O1 - Hosts: 172.18.77.18 TEXPM1SACAM02
O1 - Hosts: 172.18.77.19 TEXPM1SACAM03
O1 - Hosts: 172.18.77.20 TEXPM1SACAM04
O1 - Hosts: 172.18.77.21 TEXPM1SACAM05
O1 - Hosts: 172.18.77.25 TEXPM1SACAM06
O1 - Hosts: 172.18.77.26 TEXPM1SACAM07
O1 - Hosts: 172.18.77.27 TEXPM1SACAM08
O1 - Hosts: 172.18.77.28 TEXPM1SACAM09
O1 - Hosts: 172.18.77.29 TEXPM1SACAM10
O1 - Hosts: 172.18.77.31 TEXPM1SACAM11
O1 - Hosts: 172.18.77.109 TEXPM1SACAM12
O1 - Hosts: 172.18.77.55 TEXPM1SACAM13
O1 - Hosts: 172.18.77.57 TEXPM1SACAM14
O1 - Hosts: 172.18.77.110 TEXPM1SACAM15
O1 - Hosts: 172.18.77.61 TEXPM1SACAM16
O1 - Hosts: 172.18.77.65 TEXPM1SACAM17
O1 - Hosts: 172.18.77.113 TEXPM1SACAM18
O1 - Hosts: 172.18.77.68 TEXPM1SACAM19
O1 - Hosts: 172.18.77.69 TEXPM1SACAM20
O1 - Hosts: 172.18.77.73 TEXPM1SACAM21
O1 - Hosts: 172.18.77.108 TEXPM1SACAM22
O1 - Hosts: 172.18.76.176 SACAMERA113
O1 - Hosts: 172.18.76.107 SACAMERA101
O4 - HKLM\..\Run: [Synchronization Manager] mobsync.exe /logon
O4 - HKLM\..\Run: [Tweak UI] RUNDLL32.EXE TWEAKUI.CPL,TweakMeUp
O4 - HKLM\..\Run: [StoreCleanup] RunDLL32 c:\PROGRA~1\NETMAN~1\common\nmconfig.dll,StoreCleanup
O4 - HKLM\..\Run: [NetManage LaunchNow Init] RunDLL32 c:\PROGRA~1\NETMAN~1\common\nmgoinn.dll,VerifyStartMenu
O4 - HKLM\..\Run: [NvCplDaemon] RUNDLL32.EXE NvQTwk,NvCplDaemon initialize
O4 - HKLM\..\Run: [SMS Application Launcher] C:\WINNT\MS\SMS\CORE\BIN\LAUNCH32.EXE
O4 - HKLM\..\Run: [dla] C:\WINNT\system32\dla\tfswctrl.exe
O4 - HKLM\..\Run: [UpdateManager] "C:\Program Files\Common Files\Sonic\Update Manager\sgtray.exe" /r
O4 - HKLM\..\Run: [lcfep] C:\Tivoli\lcf\bin\w32-ix86\mrt\lcfep.exe -x
O4 - HKLM\..\Run: [Windows Firewall] C:\WINNT\regsrvr32.exe
O4 - HKLM\..\Run: [Configuration Loader] winsock32.exe
O4 - HKLM\..\Run: [MagnifyingGlass] C:\Program Files\ABB\Smart Advisor\Client\Bin\Magnifying Glass.exe /autorun
O4 - HKLM\..\Run: [SwdisUsrPCN.USABBCLEW01854] "C:\Tivoli\lcf\dat\1\cache\lib\w32-ix86\wdusrpcn.exe" "C:\Tivoli\swdis\1\wdusrpcn.envUSABBCLEW01854"
O4 - HKLM\..\RunServices: [Windows Firewall] C:\WINNT\regsrvr32.exe
O4 - HKLM\..\RunServices: [Configuration Loader] winsock32.exe
O4 - HKCU\..\Run: [Windows Firewall] C:\WINNT\regsrvr32.exe
O4 - HKCU\..\RunOnce: [FlashPlayerUpdate] C:\WINNT\system32\Macromed\Flash\GetFlash.exe
O4 - Global Startup: Acrobat Assistant.lnk = C:\Program Files\Adobe\Acrobat 5.0\Distillr\AcroTray.exe
O4 - Global Startup: Date Manager.lnk = C:\Program Files\Date Manager\DateManager.exe
O4 - Global Startup: hpoddt01.exe.lnk = C:\Program Files\Hewlett-Packard\Digital Imaging\bin\hpotdd01.exe
O4 - Global Startup: Lotus Organizer EasyClip.lnk = C:\Lotus\organize\easyclip.exe
O4 - Global Startup: Lotus SmartCenter.lnk = C:\Lotus\smartctr\SMARTCTR.EXE
O4 - Global Startup: Lotus SuiteStart.lnk = C:\Lotus\smartctr\SUITEST.EXE
O4 - Global Startup: Microsoft Office.lnk = C:\Program Files\Microsoft Office\Office\OSA9.EXE
O4 - Global Startup: officejet 6100.lnk = C:\Program Files\Hewlett-Packard\Digital Imaging\bin\hposol08.exe
O4 - Global Startup: PrecisionTime.lnk = C:\Program Files\PrecisionTime\PrecisionTime.exe
O4 - Global Startup: Push Client.LNK = C:\Interwise\Student\pull.exe
O6 - HKCU\Software\Policies\Microsoft\Internet Explorer\Restrictions present
O6 - HKCU\Software\Policies\Microsoft\Internet Explorer\Control Panel present
O9 - Extra button: Related - {c95fe080-8f5d-11d2-a20b-00aa003c157a} - C:\WINNT\web\related.htm
O9 - Extra 'Tools' menuitem: Show &Related Links - {c95fe080-8f5d-11d2-a20b-00aa003c157a} - C:\WINNT\web\related.htm
O12 - Plugin for .spop: C:\Program Files\Internet Explorer\Plugins\NPDocBox.dll
O14 - IERESET.INF: START_PAGE_URL=http://inside.abb.com
O16 - DPF: {6414512B-B978-451D-A0D8-FCFDF33E833C} (WUWebControl Class) - http://update.micros...b?1128098615625
O16 - DPF: {6E32070A-766D-4EE6-879C-DC1FA91D2FC3} (MUWebControl Class) - http://update.micros...b?1128098648796
O17 - HKLM\System\CS1\Services\Tcpip\Parameters: SearchList = cmh.us.abb.com,ipaper.com
O17 - HKLM\System\CS2\Services\Tcpip\Parameters: SearchList = cmh.us.abb.com,ipaper.com
O17 - HKLM\System\CCS\Services\Tcpip\Parameters: SearchList = cmh.us.abb.com,ipaper.com
O20 - Winlogon Notify: PCANotify - C:\WINNT\SYSTEM32\PCANotify.dll
O23 - Service: AVSync Manager (AvSynMgr) - Unknown owner - C:\Program Files\Network Associates\VirusScan\Avsynmgr.exe
O23 - Service: pcAnywhere Host Service (awhost32) - Symantec Corporation - C:\Program Files\Symantec\pcAnywhere\awhost32.exe
O23 - Service: BBDistHandler - Unknown owner - %SystemDrive%\MAINT\sid\DISTH\DISTH.EXE (file missing)
O23 - Service: Cisco Systems, Inc. VPN Service (CVPND) - Cisco Systems, Inc. - C:\PROGRA~1\CISCOS~1\VPNCLI~1\cvpnd.exe
O23 - Service: Logical Disk Manager Administrative Service (dmadmin) - VERITAS Software Corp. - C:\WINNT\System32\dmadmin.exe
O23 - Service: Help and Support (helpsvc) - Unknown owner - C:\WINNT\system32\dllcache\dllhost.exe
O23 - Service: Help and Support Center (helpsvcc) - Unknown owner - C:\WINNT\system32\cache\dllhost.exe
O23 - Service: Internet Application Migration (IAM) (iamsvc) - Unknown owner - C:\WINNT\system32\dllcache\dllhost.exe
O23 - Service: Tivoli Endpoint (lcfd) - Unknown owner - C:\Tivoli\lcf\bin\w32-ix86\mrt\lcfd.exe
O23 - Service: McShield - Unknown owner - C:\Program Files\Common Files\Network Associates\McShield\Mcshield.exe
O23 - Service: microsft.exe - Unknown owner - C:\WINNT\system\microsft.exe
O23 - Service: Microsoft Updater (msupdt) - Cat Soft - C:\WINNT\system32\dllcache\lsass.exe
O23 - Service: NVIDIA Driver Helper Service (NVSvc) - NVIDIA Corporation - C:\WINNT\system32\nvsvc32.exe
O23 - Service: PIPC Log Server (pilogsrv) - OSI Software - C:\Program Files\PIPC\BIN\pilogsrv.exe
O23 - Service: PI Message Subsystem (pimsgss) - OSI Software, Inc. - C:\Program Files\PIPC\BIN\pimsgss.exe
O23 - Service: PI Network Manager (pinetmgr) - OSI Software, Inc. - C:\Program Files\PIPC\BIN\pinetmgr.exe
O23 - Service: Pml Driver HPZ12 - HP - C:\WINNT\system32\HPZipm12.exe
O23 - Service: Shared Folders Server (SFOLDER) - NetManage. - C:\WINNT\system32\FLRSERV.EXE