OK, I will ask you to give us some other logs at the end also.
Please print out the instructions here (or save it in Notepad) so that you can follow along more easily.
This hijack may take a couple of tries to remove it. If you have any questions during this process, please ask us (just don't restart or shutdown - unless the instructions say so).
1. Run CleanUp! program and click on CleanUp button. Say NO when it asks you to reboot/logoff. Check your Downloaded Program Files folder for any program that you do not recognize and remove anything in question.
2. Go to Start->Run and type in regedit and hit OK. Go to File->Export and save the registry somewhere as a backup. While in the Registry Editor, navigate to:
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Winlogon\Notify\ and delete
IntlRun
If any of the above registry keys are giving you problems deleting, right click on them and click on Permissions. Then click on the Advanced button. Make sure the first box (Inherit from parent...) is checked. Click OK and OK. Then try deleting the entry again. Once you're done, close the Registry Editor.
3. Run KillBox now.
a) Click on the 'Delete on Reboot' button.
b) Check 'End Explorer Shell While Killing File'.
c) Check 'Unregister .dll Before Deleting' for each file (if it's available).
Copy and paste each of the following (one by one) into KillBox and hit the X button for each one (when it asks you if you want to reboot, choose NO for all of them):
c:\recycler\desktop.ini
C:\WINDOWS\system32\guard.tmp
C:\WINDOWS\system32\lt2027fmg.dll
4. Restart and hit the F8 key (repeatedly until a menu shows up) to enter Safe Mode.
5. Run HijackThis and do a scan. Check and fix the following:
O1 - Hosts: 69.20.16.183 auto.search.msn.com
O1 - Hosts: 69.20.16.183 search.netscape.com
O1 - Hosts: 69.20.16.183 ieautosearch
O20 - Winlogon Notify: IntlRun - C:\WINDOWS\system32\lt2027fmg.dll (file missing)
Close HijackThis and run Hoster. Click 'Restore Original Hosts' and click OK.
Run CleanUp! program again and clean everything. Say Yes when it asks you to reboot/logoff.
6. Reboot into Normal Mode and run HijackThis. Do a scan and give us a new log.
Go to c:\windows\system32\drivers\etc and open up the hosts file (no extensions) up in Notepad. There should be a bunch of lines with a # in front of them followed by a single line like:
127.0.0.1 localhost
If you have anything after that, please post them here.
Download
DllCompare and run it. Click on the
Locate.com button. Wait a few seconds and then click on the
Compare button. Let it run, then click on
Make a log of what was found. Post that log here. Note: If you are having problems using DllCompare (16 bit error), copy autoexec.nt from the C:\WINDOWS\repair folder to C:\WINDOWS\system32 folder. Now run DllCompare.
Download
Find It and unzip it. Open up the folder and double click on the
find.bat file. Let it run for a while. After it's finished, open up file. Copy and paste the contents to the forums.