Run Hijackthis and go to the process viewer by going to Config, Misc Tools, Process Viewer, to unload all instances of the following running processes;
desbyhdw.exe
Then go to C:\WINDOWS\system32 and delete the file manually.
Scan with hijackthis and tick the boxes next to all the following entries, then close all browser and explorer windows, and hit the "Fix checked" button.
R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Bar = http://websearch.drsnsrch.com/sidesearch.cgi?id=
R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Page = http://websearch.drsnsrch.com/sidesearch.cgi?id=
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Bar = http://websearch.drsnsrch.com/sidesearch.cgi?id=
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = http://websearch.drsnsrch.com/sidesearch.cgi?id=
R0 - HKLM\Software\Microsoft\Internet Explorer\Search,SearchAssistant = http://websearch.drsnsrch.com/sidesearch.cgi?id=
R0 - HKLM\Software\Microsoft\Internet Explorer\Search,CustomizeSearch = http://websearch.drsnsrch.com/sidesearch.cgi?id=
R1 - HKCU\Software\Microsoft\Internet Explorer\SearchURL,(Default) = websearch.drsnsrch.com/q.cgi?q=
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Local Page = C:\WINDOWS\SYSTEM\blank.htm
O2 - BHO: ZServObj Class - {00000000-C1EC-0345-6EC2-4D0300000000} - C:\WINDOWS\ZServ.dll
O2 - BHO: Band Class - {01F44A8A-8C97-4325-A378-76E68DC4AB2E} - (no file)
O3 - Toolbar: (no name) - {2CDE1A7D-A478-4291-BF31-E1B4C16F92EB} - (no file)
O4 - HKLM\..\Run: [bnfvyf] C:\WINDOWS\system32\desbyhdw.exe
O4 - HKLM\..\Run: [ynyihqod] C:\WINDOWS\system32\desbyhdw.exe
O4 - HKLM\..\Run: [WebSavingsfromEbates] wjview /cp:p "C:\Program Files\WebSavingsfromEbates\System\Code" Main lp: "C:\Program Files\WebSavingsfromEbates"
O4 - HKLM\..\Run: [ViewMgr] C:\Program Files\Viewpoint\Viewpoint Manager\ViewMgr.exe
O4 - HKLM\..\Run: [SENTRY] C:\WINDOWS\SENTRY.exe
O4 - HKLM\..\Run: [bwsaxrvsxrjwm] C:\WINDOWS\System32\desbyhdw.exe
O4 - HKLM\..\Run: [alchem] C:\WINDOWS\alchem.exe
O8 - Extra context menu item: Web Savings - file://C:\Program Files\WebSavingsfromEbates\System\Temp\ebateswebsavings_script0.htmOnline\ControlPad\Misc\a_menu.exe (file missing)
O9 - Extra button: (no name) - {CD67F990-D8E9-11d2-98FE-00C0F0318AFE} - (no file)
O9 - Extra button: ComcastHSI - {11DDA08A-57DB-4B9D-A1EB-5AC71A1E8F21} - http://www.comcast.net (file missing) (HKCU)
O9 - Extra button: Help - {3E542AC5-6E28-4C7A-BC37-89F67D903403} - http://www.comcast.net/memberservices/ (file missing) (HKCU)
O9 - Extra button: Support - {97904587-20B6-4A5D-83F2-DD13A3973372} - http://www.comcastsupport.com (file missing) (HKCU)
O17 - HKLM\System\CS1\Services\Tcpip\Parameters: SearchList = naptg.com
O17 - HKLM\System\CS2\Services\Tcpip\Parameters: SearchList = naptg.com
O17 - HKLM\System\CCS\Services\Tcpip\Parameters: SearchList = naptg.com
Reboot into safe mode following the instructions here and navigate to and delete the following if found:
C:\Program Files\WebSavingsfromEbates<----folder
C:\Program Files\Viewpoint\Viewpoint Manager<----folder
C:\WINDOWS\SENTRY.exe<----file
C:\WINDOWS\alchem.exe<----file
Reboot normally after doing the above, rescan with hijackthis, then post that log here please.