Reboot into safe mode following the instructions here & Unzip HJT into it's own permanent folder before doing anything in order for it to create backups. (Not a temporary folder or directly on the desktop & not directly on your hard drive). Close all (browser) windows & rescan with hijackthis. When the scan is finished place a check in the box to the left of the following entries & click 'fix checked' :
R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://mysearchnow.com/passthrough/...unonce.msn.com/
R1 - HKCU\Software\Microsoft\Internet Explorer\Search,SearchAssistant = http://mysearchnow.com/searchbar.html
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Bar = http://mysearchnow.com/searchbar.html
F0 - system.ini: Shell=C:\Aston\aston.exe ,svchost.exe
O1 - Hosts: 69.1.67.70 btuga.com www.btuga.com
O2 - BHO: (no name) - {E06DE18D-7530-977B-A974-82B8E32C6724} - C:\PROGRA~1\gridheck\HTM PURE.dll
O3 - Toolbar: mags manager - {ECFF9B8F-84C7-09D2-F1C2-1F4DE7DD2099} - C:\PROGRA~1\gridheck\HTM PURE.dll
O4 - HKLM\..\Run: [book proc] C:\PROGRA~1\ADMINV~1\TypeWinDent.exe
O4 - HKLM\..\Run: [AutoUpdater] "C:\Program Files\AutoUpdate\AutoUpdate.exe"
O4 - HKLM\..\Run: [Windows SA] C:\Program Files\WindowsSA\omniscient.exe
Delete the following manually:
C:\PROGRA~1\gridheck< folder
C:\PROGRA~1\ADMINV~1< folder
C:\Program Files\AutoUpdate< folder
C:\Program Files\WindowsSA< folder
Reboot normally after doing the above then post a fresh log plz.