Please just copy & paste your logs into this thread. Do the following.
Check ADD/REMOVE Programs and uninstall the following if present.
Mywebsearch
PartyPoker
PartyGaming
Then go to C/Program Files and delete the above folders if still present.
Download Ewido(AVG Antispyware)
http://www.ewido.net/en/download/ then set it up this way
http://rstones12.geekstogo.com/ewidosetup.htm You will need this later in safe mode
Make sure to update this program.
Download ATF-Cleaner to your desktop from this link
http://www.atribune.org/content/view/19/2/ You will need it later in safe mode.
Reboot your computer in Safe Mode by doing the following.
After hearing your computer beep once during startup, but before the Windows icon appears, tap the F8 key continually;
Instead of Windows loading as normal, a menu with options should appear;
Select the first option, to run Windows in Safe Mode, then press "Enter".
Choose your usual account.
Disable your security programs like AVG, Ewido, Spybot, etc, until needed as they may interfere with the cleaning process.
From safemode, run HijackThis and put a check by the following entries if still present, close all open windows and browsers except HijackThis and click 'Fix Checked'
R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = about:blank
R1 - HKCU\Software\Microsoft\Internet Explorer\SearchURL,(Default) =
http://g.msn.com/0SEENUS/SAOS01?FORM=TOOLBR
R3 - Default URLSearchHook is missing
O2 - BHO: (no name) - {24C57E81-D656-CDF8-4D12-C94757EDFCFF} - C:\WINDOWS\system32\mskwgtaw.dll (file missing)
O2 - BHO: (no name) - {9E85E2F9-5E3E-53B1-68EA-57800B3C52C5} - C:\WINDOWS\system32\dsarcvwo.dll
O2 - BHO: (no name) - {AFA8D28C-730F-66F7-45DD-65AD390F7FF7} - C:\WINDOWS\system32\dsarcvwo.dll
O3 - Toolbar: (no name) - {BA52B914-B692-46c4-B683-905236F6F655} - (no file)
O3 - Toolbar: (no name) - {BDAD1DAD-C946-4A17-ADC1-64B5B4FF55D0} - (no file)
O4 - Global Startup: Exif Launcher.lnk = ?
O8 - Extra context menu item: &Search -
http://edits.mywebsearch.com/toolbaredits/menusearch.jhtml?p=ZN
O9 - Extra button: PartyPoker.com - {B7FE5D70-9AA2-40F1-9C6B-12A255F085E1} - C:\Program Files\PartyGaming\PartyPoker\RunApp.exe (file missing)
O9 - Extra 'Tools' menuitem: PartyPoker.com - {B7FE5D70-9AA2-40F1-9C6B-12A255F085E1} - C:\Program Files\PartyGaming\PartyPoker\RunApp.exe (file missing)
O9 - Extra button: (no name) - {CD67F990-D8E9-11d2-98FE-00C0F0318AFE} - (no file)
O20 - Winlogon Notify: Controls Folder - C:\WINDOWS\system32\srncui.dll (file missing)
O20 - Winlogon Notify: Telephony - C:\WINDOWS\system32\p44u0eh9eh4.dll (file missing)
Exit Hijack This but remain in safe mode.
Run Ewido - make sure of the following settings.
Select the "Scanner" icon at the top of the screen, then select the "Settings" tab.
Once in the Settings screen click on "Recommended actions" and then select "Quarantine".
Under "Reports"
Select "Automatically generate report after every scan"
Un-Select "Only if threats were found"
Save this scan log.
Run ATF-Cleaner from safe mode.Double-click ATF-Cleaner.exe to run the program.
Under Main choose: Select All
Click the Empty Selected button.
If you use firefox also, select at top of ATF cleaner-tick Select all and run again.
Reboot into normal windows, run ATF cleaner again and post a fresh 'HJT' log along with the safemode scan log from Ewido.