You definitely have a coolwebsearch infection. Make sure you have the latest version of CWShredder (1.58 I believe) & make sure that ALL windows are closed (browser & folders) So>>>>update CWShredder from here & run it. Select the fix button & it will get rid of everything related to CoolWebSearch that is stored in it's database. Close ALL windows, including IE, before running CWShredder. Reboot.
To help prevent this from happening again, install the patches for the vulnerabilities that this hijacker exploits by going here for your critical updates.
Close all (browser) windows & rescan with hijackthis. When the scan is finished place a check in the box to the left of the following entries & click 'fix checked' :
O2 - BHO: (no name) - {000020DD-C72E-4113-AF77-DD56626C6C42} - (no file)
O2 - BHO: (no name) - {D848A3CA-0BFB-4DE0-BA9E-A57F0CCA1C13} - (no file)
O4 - HKLM\..\Run: [sSaU] C:\documents and settings\drinella\local settings\temp\sSaU.exe
O4 - HKLM\..\Run: [Dsi] C:\WINNT\system32\dp-him.exe
O4 - HKLM\..\Run: [emsw.exe] C:\WINNT\emsw.exe
O4 - HKLM\..\Run: [wnhbiizsfmyk] C:\WINNT\system32\huzwdux.exe
O4 - HKLM\..\Run: [scnmnm] C:\WINNT\system32\scnmnm.exe
O4 - Global Startup: winlogin.exe
O8 - Extra context menu item: Coupons - file://C:\Program Files\couponsandoffers\System\Temp\couponsandoffers_script0.htm
O16 - DPF: {56336BCB-3D8A-11D6-A00B-0050DA18DE71} (RdxIE Class) - http://207.188.7.150/317739fd64ec9b...ip/RdxIE601.cab
C:\Program Files\couponsandoffers< folder
C:\documents and settings\drinella\local settings\temp< folder contents
C:\WINNT\system32\dp-him.exe< file
C:\WINNT\emsw.exe< file
C:\WINNT\system32\huzwdux.exe< file
C:\WINNT\system32\scnmnm.exe< file
winlogin.exe< file from the startup folder
In order to view these files you may have to select 'show hidden files/folders.' Instructions on how to here.
Reboot normally after doing this & post another log please.