Network admin has noticed that a system is constantly trying to connect to a domain with the following IP: 216.133.246.134. We have blocked all outbound traffic to this 'ad' site. Upon further investigation of the PC, I have found that there is an unknown, rogue process running with a corresponding .exe located in the C:\windows\temp folder. This executable and process name changes upon every reboot. We have tried various spyware programs and registry cleaning programs to no avail. I do have a HijackThis log file available and will post this when asked.

Any help will be greatly appreciated.