Here is the situation, I have had 2 clients with this same issue and I am unable to resolve. I know our precinct has ran into this issue too. The computer when you open up IE will start popups, after further investigation there are multiple issues, first the hosts file is changing somehow.... I have tried changing it to what I wanted and making it read only, only to find out it changed back entries include this
O1 - Hosts: 69.20.16.183 auto.search.msn.com
O1 - Hosts: 69.20.16.183 search.netscape.com
O1 - Hosts: 69.20.16.183 ieautosearch

What I have done.....
Ran (in safe mode) Hijack this, spybot, spyware blaster, adaware (with vx2 tool) hosts reader, spysweeper, about buster, CWShredder, lsp fix, winsock fix, restored all defaults in IE, cleared all temp including prefetch and offline content, ran ccleaner, NONE of this fixed the issue.

Hijack this comes up with these entries
O1 - Hosts: 69.20.16.183 auto.search.msn.com
O1 - Hosts: 69.20.16.183 search.netscape.com
O1 - Hosts: 69.20.16.183 ieautosearch

If I remove them then restart hijack this they are there again, even after a reboot. ccleaner is removing lists of things everytime I run it.

Does anyone have any idea why these hosts files are changing back Now I got the host files fixed and the other files out of hijack this (might be cause I am behind a proxy now) But I cant get those other 2 files to disappear and its causing other popups to happen

*****************
Using Sysinternals Process explorer in SAFE MODE this is what I am getting

just noticed on this one computer there are 2 things that keep coming up hkitut.exe (cant find anything about this) I deleted it from everywhere I could find including registry.
and another called narrator

some other file comes and goes as it pleases wcvrir.exe <--- This is a pain it wont go away

in safe mode only processes running are
ctfmon.exe
explorer.exe
lsass.exe
prcview
rundll32 c:\windows\system32\rundll32.exe (I deleted this but it came back)
smss
svchost
svchost
winlogon