Here is the new HJT log followed by the other logs you requested.
Logfile of HijackThis v1.99.1
Scan saved at 9:46:33 PM, on 7/12/2005
Platform: Windows 2000 SP4 (WinNT 5.00.2195)
MSIE: Internet Explorer v6.00 SP1 (6.00.2800.1106)
Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\system32\spoolsv.exe
C:\PROGRA~1\Grisoft\AVGFRE~1\avgamsvr.exe
C:\PROGRA~1\Grisoft\AVGFRE~1\avgupsvc.exe
C:\WINDOWS\System32\svchost.exe
C:\Program Files\ewido\security suite\ewidoctrl.exe
C:\Program Files\ewido\security suite\ewidoguard.exe
C:\WINDOWS\system32\hidserv.exe
C:\WINDOWS\system32\regsvc.exe
C:\WINDOWS\system32\MSTask.exe
C:\WINDOWS\SYSTEM32\ZoneLabs\vsmon.exe
C:\WINDOWS\System32\WBEM\WinMgmt.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\Explorer.EXE
C:\WINDOWS\system32\spool\drivers\w32x86\3\hpztsb04.exe
C:\PROGRA~1\Grisoft\AVGFRE~1\avgcc.exe
C:\PROGRA~1\Grisoft\AVGFRE~1\avgemc.exe
C:\Program Files\Zone Labs\ZoneAlarm\zlclient.exe
C:\Program Files\Internet Explorer\iexplore.exe
C:\My Documents\Administrative\hijackthis\HijackThis.exe
R1 - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings,ProxyOverride = localhost
O2 - BHO: EarthLink ScamBlocker V2 - {15F4D456-5BAA-4076-8486-EECB38CD3E57} - C:\Program Files\EarthLink\Toolbar\EScamBlk.dll
O2 - BHO: EarthLink PopUp Blocker V2 - {512ACF1B-64D9-4928-B382-A80556F28DB4} - C:\Program Files\EarthLink\Toolbar\ElnkPuB.dll
O2 - BHO: (no name) - {53707962-6F74-2D53-2644-206D7942484F} - C:\Program Files\Spybot - Search & Destroy\SDHelper.dll
O2 - BHO: Earthlink Protection BHO - {9579D574-D4D8-4335-9560-FE8641A013BD} - C:\Program Files\EarthLink\Toolbar\ProtctIE.dll
O2 - BHO: Google Toolbar Helper - {AA58ED58-01DD-4d91-8333-CF10577473F7} - c:\program files\google\googletoolbar1.dll
O2 - BHO: Uninstall Legacy Earthlink Toolbar - {E713904C-DF05-4C79-BBAD-02DB923253BE} - C:\Program Files\EarthLink\Toolbar\uninsttb.dll
O3 - Toolbar: EarthLink Toolbar - {C7768536-96F8-4001-B1A2-90EE21279187} - C:\Program Files\EarthLink\Toolbar\Toolbar.dll
O4 - HKLM\..\Run: [SystemTray] SysTray.Exe
O4 - HKLM\..\Run: [Synchronization Manager] mobsync.exe /logon
O4 - HKLM\..\Run: [HPDJ Taskbar Utility] C:\WINDOWS\system32\spool\drivers\w32x86\3\hpztsb04.exe
O4 - HKLM\..\Run: [AVG7_CC] C:\PROGRA~1\Grisoft\AVGFRE~1\avgcc.exe /STARTUP
O4 - HKLM\..\Run: [AVG7_EMC] C:\PROGRA~1\Grisoft\AVGFRE~1\avgemc.exe
O4 - HKLM\..\Run: [Zone Labs Client] C:\Program Files\Zone Labs\ZoneAlarm\zlclient.exe
O8 - Extra context menu item: &Google Search - res://c:\program files\google\GoogleToolbar1.dll/cmsearch.html
O8 - Extra context menu item: Backward Links - res://c:\program files\google\GoogleToolbar1.dll/cmbacklinks.html
O8 - Extra context menu item: Cached Snapshot of Page - res://c:\program files\google\GoogleToolbar1.dll/cmcache.html
O8 - Extra context menu item: Send Image to Photo Library - file://C:\Documents and Settings\Gary Hawk\Application Data\ROXIO\PhotoSuite4\Temp\ROXIO00000.html
O8 - Extra context menu item: Similar Pages - res://c:\program files\google\GoogleToolbar1.dll/cmsimilar.html
O8 - Extra context menu item: Translate into English - res://c:\program files\google\GoogleToolbar1.dll/cmtrans.html
O16 - DPF: {6414512B-B978-451D-A0D8-FCFDF33E833C} (WUWebControl Class) -
http://update.micros...b?1120711276620O16 - DPF: {6E32070A-766D-4EE6-879C-DC1FA91D2FC3} (MUWebControl Class) -
http://update.micros...b?1120711246687O16 - DPF: {9A9307A0-7DA4-4DAF-B042-5009F29E09E1} (ActiveScan Installer Class) -
http://www.pandasoft.../as5/asinst.cabO16 - DPF: {AB86CE53-AC9F-449F-9399-D8ABCA09EC09} (Get_ActiveX Control) -
https://h17000.www1....loadManager.ocxO16 - DPF: {C40F8F85-3FC3-4C0C-AD91-6A204FAAD59F} (UCInstall Class) -
http://ultimateclean...tall/UCInst.cabO16 - DPF: {EB387D2F-E27B-4D36-979E-847D1036C65D} (QDiagHUpdateObj Class) -
http://h30043.www3.h.../qdiagh.cab?326O23 - Service: AVG7 Alert Manager Server (Avg7Alrt) - GRISOFT, s.r.o. - C:\PROGRA~1\Grisoft\AVGFRE~1\avgamsvr.exe
O23 - Service: AVG7 Update Service (Avg7UpdSvc) - GRISOFT, s.r.o. - C:\PROGRA~1\Grisoft\AVGFRE~1\avgupsvc.exe
O23 - Service: AVG6 Service (AvgServ) - Unknown owner - C:\PROGRA~1\Grisoft\AVG6\avgserv.exe (file missing)
O23 - Service: Logical Disk Manager Administrative Service (dmadmin) - VERITAS Software Corp. - C:\WINDOWS\System32\dmadmin.exe
O23 - Service: ewido security suite control - ewido networks - C:\Program Files\ewido\security suite\ewidoctrl.exe
O23 - Service: ewido security suite guard - ewido networks - C:\Program Files\ewido\security suite\ewidoguard.exe
O23 - Service: TrueVector Internet Monitor (vsmon) - Zone Labs, LLC - C:\WINDOWS\SYSTEM32\ZoneLabs\vsmon.exe
About:Buster log:AboutBuster 5.0 reference file 30
Scan started on [7/12/2005] at [1:24:33 PM]
------------------------------------------------
No Ads Found!
------------------------------------------------
No Files Found!
------------------------------------------------
Scan was COMPLETED SUCCESSFULLY at 1:26:11 PM
SpSeHjfix log:(7/12/05 1:28:15 PM) SPSeHjFix started v1.1.2
(7/12/05 1:28:15 PM) OS: Win2000 Service Pack 4 (5.0.2195)
(7/12/05 1:28:15 PM) Language: english
(7/12/05 1:28:15 PM) Win-Path: C:\WINDOWS
(7/12/05 1:28:15 PM) System-Path: C:\WINDOWS\system32
(7/12/05 1:28:15 PM) Temp-Path: C:\DOCUME~1\GARYHA~1\LOCALS~1\Temp\
(7/12/05 1:28:18 PM) Disinfection started
(7/12/05 1:28:18 PM) Bad-Dll(IEP): (not found)
(7/12/05 1:28:18 PM) Bad-Dll(IEP) in BHO: (not found)
(7/12/05 1:28:18 PM) UBF: 4 - UBB: 6 - UBR: 9
(7/12/05 1:28:18 PM) UBF: 4 - UBB: 6 - UBR: 9
(7/12/05 1:28:18 PM) Bad IE-pages: (none)
(7/12/05 1:28:18 PM) Stealth-String not found
(7/12/05 1:28:18 PM) Not infected->END
Ewido log:---------------------------------------------------------
ewido security suite - Scan report
---------------------------------------------------------
+ Created on: 4:16:25 PM, 7/12/2005
+ Report-Checksum: F5E3E313
+ Scan result:
HKLM\SOFTWARE\180solutions -> Spyware.180Solutions : Cleaned with backup
HKLM\SOFTWARE\Classes\AppID\AtlBrowser.EXE -> Spyware.eZula : Cleaned with backup
HKLM\SOFTWARE\Classes\AppID\{0818D423-6247-11D1-ABEE-00D049C10000} -> Spyware.eZula : Cleaned with backup
HKLM\SOFTWARE\Classes\CLSID\{469C7080-8EC8-43A6-AD97-45848113743C} -> Dialer.Generic : Cleaned with backup
HKLM\SOFTWARE\Classes\Interface\{12E919BC-C70F-432B-B831-1180DE734505} -> Dialer.Generic : Cleaned with backup
HKLM\SOFTWARE\Classes\Interface\{370F6327-41C4-4FA6-A2DF-1BA57EE0FBB9} -> Spyware.eZula : Cleaned with backup
HKLM\SOFTWARE\Classes\Interface\{53B95210-7D77-11D2-9F81-00104B107C96} -> Spyware.CoolWebSearch : Cleaned with backup
HKLM\SOFTWARE\Classes\Interface\{66BD1BD0-3655-42E4-8CE9-16D3613B0B25} -> Dialer.Generic : Cleaned with backup
HKLM\SOFTWARE\Classes\Interface\{9388907F-82F5-434D-A941-BB802C6DD7C1} -> Spyware.ISTBar : Cleaned with backup
HKLM\SOFTWARE\Classes\Interface\{EFA52460-8822-4191-BA38-FACDD2007910} -> Spyware.eZula : Cleaned with backup
HKLM\SOFTWARE\Classes\TypeLib\{53B95204-7D77-11D2-9F81-00104B107C96} -> Spyware.CoolWebSearch : Cleaned with backup
HKLM\SOFTWARE\Classes\TypeLib\{795EB484-BD6D-4125-93DB-D6FF015325E9} -> Dialer.Generic : Cleaned with backup
HKLM\SOFTWARE\Microsoft\Code Store Database\Distribution Units\{469C7080-8EC8-43A6-AD97-45848113743C} -> Dialer.Generic : Cleaned with backup
HKLM\SOFTWARE\Microsoft\Code Store Database\Distribution Units\{9E98E84C-79E1-49C3-82EB-798FCD552EFB} -> Dialer.Generic : Cleaned with backup
HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\App Management\ARPCache\Bargain Buddy -> Spyware.BargainBuddy : Cleaned with backup
HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\App Management\ARPCache\ISTbarISTbar -> Spyware.HotBar : Cleaned with backup
HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\Web Offer -> Spyware.eZula : Cleaned with backup
HKU\.DEFAULT\Software\Hiwire -> Spyware.HiWire : Cleaned with backup
HKU\.DEFAULT\Software\Hiwire\MusicMatch -> Spyware.HiWire : Cleaned with backup
HKU\.DEFAULT\Software\Hiwire\MusicMatch\Browser -> Spyware.HiWire : Cleaned with backup
HKU\.DEFAULT\Software\Hiwire\MusicMatch\Faceplate -> Spyware.HiWire : Cleaned with backup
HKU\.DEFAULT\Software\Hiwire\MusicMatch\History -> Spyware.HiWire : Cleaned with backup
HKU\.DEFAULT\Software\Hiwire\MusicMatch\Resources -> Spyware.HiWire : Cleaned with backup
HKU\.DEFAULT\Software\Hiwire\MusicMatch\Stations -> Spyware.HiWire : Cleaned with backup
HKU\.DEFAULT\Software\Hiwire\MusicMatch\WebUpdate -> Spyware.HiWire : Cleaned with backup
C:\Documents and Settings\Gary Hawk\Application Data\teht.exe -> Spyware.PurityScan : Cleaned with backup
C:\Documents and Settings\Gary Hawk\Cookies\gary
[email protected][2].txt -> Spyware.Cookie.Wegcash : Cleaned with backup
C:\Documents and Settings\Gary Hawk\Cookies\gary
[email protected][2].txt -> Spyware.Cookie.Offshoreclicks : Cleaned with backup
C:\Documents and Settings\Gary Hawk\Cookies\gary
[email protected][1].txt -> Spyware.Cookie.Porntrack : Cleaned with backup
C:\Documents and Settings\Gary Hawk\Cookies\gary
[email protected][2].txt -> Spyware.Cookie.Porntrack : Cleaned with backup
C:\Documents and Settings\Gary Hawk\Cookies\gary
[email protected][1].txt -> Spyware.Cookie.Porntrack : Cleaned with backup
C:\Documents and Settings\Gary Hawk\Cookies\gary
[email protected][2].txt -> Spyware.Cookie.Porntrack : Cleaned with backup
C:\Documents and Settings\Gary Hawk\Cookies\gary
[email protected][3].txt -> Spyware.Cookie.Porntrack : Cleaned with backup
C:\Documents and Settings\Gary Hawk\Cookies\hp authorized
[email protected][2].txt -> Spyware.Cookie.Link4ads : Cleaned with backup
C:\Documents and Settings\Gary Hawk\Cookies\hp authorized
[email protected][3].txt -> Spyware.Cookie.Link4ads : Cleaned with backup
C:\Documents and Settings\Gary Hawk\Cookies\hp authorized
[email protected][4].txt -> Spyware.Cookie.Link4ads : Cleaned with backup
C:\Documents and Settings\Gary Hawk\Cookies\hp authorized
[email protected][1].txt -> Spyware.Cookie.Porntrack : Cleaned with backup
C:\Documents and Settings\Gary Hawk\Cookies\hp authorized
[email protected][2].txt -> Spyware.Cookie.Porntrack : Cleaned with backup
C:\Documents and Settings\Gary Hawk\Cookies\hp authorized customer@oxcash[1].txt -> Spyware.Cookie.Oxcash : Cleaned with backup
C:\Documents and Settings\Gary Hawk\Cookies\hp authorized customer@preferences[1].txt -> Spyware.Cookie.Preferences : Cleaned with backup
C:\Documents and Settings\Gary Hawk\Cookies\hp authorized
[email protected][1].txt -> Spyware.Cookie.Porntrack : Cleaned with backup
C:\Documents and Settings\Gary Hawk\Cookies\hp authorized
[email protected][1].txt -> Spyware.Cookie.Porntrack : Cleaned with backup
C:\Documents and Settings\Gary Hawk\Cookies\hp authorized
[email protected][2].txt -> Spyware.Cookie.Porntrack : Cleaned with backup
C:\Documents and Settings\Gary Hawk\Cookies\hp authorized
[email protected][3].txt -> Spyware.Cookie.Porntrack : Cleaned with backup
C:\Documents and Settings\Gary Hawk\Local Settings\Temp\q381275.exe -> TrojanSpy.Small.r : Cleaned with backup
C:\Documents and Settings\Gary Hawk\Local Settings\Temp\sp.html -> Spyware.Hijacker.Generic : Cleaned with backup
C:\Program Files\Screensavers.com\Installer\bin\ScreensaversInst.dll -> Spyware.Comet : Cleaned with backup
C:\WINDOWS\Downloaded Program Files\CONFLICT.1\HDPlugin1101.dll -> Adware.Gator : Cleaned with backup
C:\WINDOWS\Downloaded Program Files\CONFLICT.2\HDPlugin1101.dll -> Adware.Gator : Cleaned with backup
C:\WINDOWS\Downloaded Program Files\CONFLICT.3\HDPlugin1101.dll -> Adware.Gator : Cleaned with backup
C:\WINDOWS\Downloaded Program Files\HDPlugin1101.dll -> Adware.Gator : Cleaned with backup
C:\WINDOWS\Downloaded Program Files\MediaTicketsInstaller.ocx -> Spyware.MediaTickets : Cleaned with backup
C:\WINDOWS\Downloaded Program Files\UCInst.dll -> Spyware.UCInst : Cleaned with backup
C:\WINDOWS\tmpcpyis.bat -> Backdoor.AcidShiver : Cleaned with backup
::Report End