For the record, I've used Bitdefender's rescue disk. It found about 2000 infections and deleted them, but the problem still persists.
Here's the log from HijackThis:
Logfile of Trend Micro HijackThis v2.0.2
Scan saved at 10:24:53 AM, on 1/26/2009
Platform: Windows 2003 SP2 (WinNT 5.02.3790)
MSIE: Internet Explorer v7.00 (7.00.6000.16762)
Boot mode: Normal
Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\csrss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\system32\spoolsv.exe
C:\WINDOWS\system32\msdtc.exe
C:\Program Files\Symantec\pcAnywhere\awhost32.exe
C:\WINDOWS\system32\Dfssvc.exe
C:\WINDOWS\System32\dns.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\system32\inetsrv\inetinfo.exe
C:\Program Files\Microsoft ISA Server\isastg.exe
C:\WINDOWS\System32\ismserv.exe
C:\Program Files\Microsoft SQL Server\MSSQL$MSFW\Binn\sqlservr.exe
C:\Program Files\Microsoft SQL Server\MSSQL.1\MSSQL\Binn\sqlservr.exe
D:\Program Files\Microsoft SQL Server\MSSQL\Binn\sqlservr.exe
C:\WINDOWS\system32\ntfrs.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\system32\locator.exe
D:\Program Files\Avira\AntiVir Exchange\Engine\savapi2s.exe
D:\Program Files\Symantec\SMSMSE\6.0\Server\SMSUtilityService.exe
D:\Program Files\Symantec\SMSMSE\6.0\Server\SAVFMSESrv.exe
D:\Program Files\Symantec\SMSMSE\6.0\Server\ConsoleAppMgr.exe
D:\Program Files\Symantec\CMaF\2.0\bin\CmafReportSrv.exe
C:\Program Files\Microsoft SQL Server\90\Shared\sqlbrowser.exe
C:\Program Files\Microsoft SQL Server\90\Shared\sqlwriter.exe
C:\WINDOWS\System32\svchost.exe
d:\Program Files\ThreatFire\TFService.exe
C:\WINDOWS\system32\dllhost.exe
C:\WINDOWS\system32\tcpsvcs.exe
D:\Program Files\Exchsrvr\bin\exmgmt.exe
D:\Program Files\Symantec\SMSMSE\6.0\Server\SAVFMSECtrl.EXE
D:\Program Files\Symantec\SMSMSE\6.0\Server\SAVFMSEUI.EXE
D:\Program Files\Symantec\SMSMSE\6.0\Server\SAVFMSESp.exe
D:\Program Files\Symantec\SMSMSE\6.0\Server\SAVFMSESp.exe
D:\Program Files\Symantec\SMSMSE\6.0\Server\SAVFMSESp.exe
D:\Program Files\Symantec\SMSMSE\6.0\Server\SAVFMSESp.exe
D:\Program Files\Symantec\SMSMSE\6.0\Server\SAVFMSESp.exe
C:\WINDOWS\system32\wbem\wmiprvse.exe
D:\Program Files\Symantec\SMSMSE\6.0\Server\SAVFMSELog.EXE
D:\Program Files\Symantec\SMSMSE\6.0\Server\SAVFMSESJM.EXE
D:\Program Files\Symantec\SMSMSE\6.0\Server\SAVFMSETask.exe
D:\Program Files\Exchsrvr\bin\mad.exe
C:\WINDOWS\system32\wbem\wmiprvse.exe
C:\Program Files\Common Files\System\MSSearch\Bin\mssearch.exe
C:\WINDOWS\System32\svchost.exe
C:\Program Files\Microsoft ISA Server\mspadmin.exe
D:\Program Files\Exchsrvr\bin\store.exe
D:\Program Files\Exchsrvr\bin\emsmta.exe
C:\WINDOWS\system32\dllhost.exe
C:\Program Files\Microsoft ISA Server\wspsrv.exe
C:\Program Files\Microsoft ISA Server\W3Prefch.exe
C:\Program Files\SPAMfighter\bin\SPAMfighter.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\System32\dmadmin.exe
c:\windows\system32\inetsrv\w3wp.exe
C:\WINDOWS\system32\csrss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\Explorer.EXE
c:\windows\system32\inetsrv\w3wp.exe
C:\WINDOWS\system32\drwtsn32.exe
C:\WINDOWS\Explorer.EXE
C:\PROGRA~1\SRNMIC~2\SOLOSENT.EXE
C:\PROGRA~1\SRNMIC~2\SOLOCFG.EXE
C:\WINDOWS\system32\NOTEPAD.EXE
C:\Program Files\Trend Micro\HijackThis\HijackThis.exe
R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = res://shdoclc.dll/hardAdmin.htm
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL =
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL =
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page =
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page =
R1 - HKCU\Software\Microsoft\Internet Connection Wizard,ShellNext =
R1 - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings,ProxyServer = server:8080
O2 - BHO: bho2gr Class - {31FF080D-12A3-439A-A2EF-4BA95A3148E8} - D:\Downloads\GetRight\xx2gr.dll
O4 - HKLM\..\Run: [SoloSentry] C:\PROGRA~1\SRNMIC~2\SOLOSENT.EXE
O4 - HKLM\..\Run: [SoloSchedule] C:\PROGRA~1\SRNMIC~2\SOLOCFG.EXE
O4 - HKLM\..\Run: [SoloSysCheck] C:\PROGRA~1\SRNMIC~2\SYSCHECK.COM
O4 - HKLM\..\Run: [ThreatFire] d:\Program Files\ThreatFire\TFTray.exe
O4 - HKLM\..\Run: [UserFaultCheck] %systemroot%\system32\dumprep 0 -u
O4 - HKCU\..\Run: [ctfmon.exe] C:\WINDOWS\system32\ctfmon.exe
O4 - HKUS\S-1-5-19\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\CTFMON.EXE (User 'LOCAL SERVICE')
O4 - HKUS\S-1-5-19\..\RunOnce: [tscuninstall] %systemroot%\system32\tscupgrd.exe (User 'LOCAL SERVICE')
O4 - HKUS\S-1-5-20\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\CTFMON.EXE (User 'NETWORK SERVICE')
O4 - HKUS\S-1-5-20\..\RunOnce: [tscuninstall] %systemroot%\system32\tscupgrd.exe (User 'NETWORK SERVICE')
O4 - HKUS\S-1-5-18\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\CTFMON.EXE (User 'SYSTEM')
O4 - HKUS\S-1-5-18\..\RunOnce: [tscuninstall] %systemroot%\system32\tscupgrd.exe (User 'SYSTEM')
O4 - HKUS\.DEFAULT\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\CTFMON.EXE (User 'Default user')
O4 - HKUS\.DEFAULT\..\RunOnce: [tscuninstall] %systemroot%\system32\tscupgrd.exe (User 'Default user')
O4 - Global Startup: Service Manager.lnk = C:\Program Files\Microsoft SQL Server\80\Tools\Binn\sqlmangr.exe
O6 - HKCU\Software\Policies\Microsoft\Internet Explorer\Control Panel present
O6 - HKLM\Software\Policies\Microsoft\Internet Explorer\Control Panel present
O8 - Extra context menu item: Download with GetRight - D:\Downloads\GetRight\GRdownload.htm
O8 - Extra context menu item: Open with GetRight Browser - D:\Downloads\GetRight\GRbrowse.htm
O15 - ESC Trusted Zone:
O15 - ESC Trusted Zone:
O15 - ESC Trusted Zone:
O15 - ESC Trusted Zone:
O15 - ESC Trusted Zone:
O15 - ESC Trusted Zone:
O15 - ESC Trusted Zone:
O15 - ESC Trusted Zone:
O15 - ESC Trusted Zone:
O15 - ESC Trusted Zone:
O15 - ESC Trusted Zone:
O15 - ESC Trusted Zone:
O15 - ESC Trusted Zone:
O15 - ESC Trusted Zone:
O15 - ESC Trusted Zone:
O15 - ESC Trusted Zone:
O15 - ESC Trusted Zone:
O15 - ESC Trusted Zone:
O15 - ESC Trusted Zone:
O15 - ESC Trusted Zone:
O15 - ESC Trusted Zone:
O15 - ESC Trusted Zone:
O15 - ESC Trusted Zone:
O15 - ESC Trusted Zone:
O15 - ESC Trusted Zone:
O15 - ESC Trusted Zone:
O15 - ESC Trusted Zone: *.hotmail.com
O15 - ESC Trusted Zone:
O15 - ESC Trusted Zone:
O15 - ESC Trusted Zone:
O15 - ESC Trusted Zone:
O15 - ESC Trusted Zone:
O15 - ESC Trusted Zone:
O15 - ESC Trusted Zone:
O15 - ESC Trusted Zone:
O15 - ESC Trusted Zone:
O15 - ESC Trusted Zone:
O15 - ESC Trusted Zone:
O15 - ESC Trusted Zone:
O15 - ESC Trusted Zone:
O15 - ESC Trusted Zone:
O15 - ESC Trusted Zone:
O15 - ESC Trusted Zone:
O15 - ESC Trusted Zone:
O15 - ESC Trusted Zone:
O15 - ESC Trusted Zone:
O15 - ESC Trusted Zone:
O15 - ESC Trusted Zone:
O15 - ESC Trusted Zone:
O15 - ESC Trusted Zone:
O15 - ESC Trusted Zone:
O15 - ESC Trusted Zone:
O15 - ESC Trusted Zone:
O15 - ESC Trusted Zone:
O15 - ESC Trusted Zone:
O15 - ESC Trusted Zone:
O15 - ESC Trusted Zone:
O15 - ESC Trusted Zone:
O15 - ESC Trusted Zone:
O15 - ESC Trusted Zone:
O15 - ESC Trusted Zone:
O15 - ESC Trusted Zone:
O15 - ESC Trusted Zone:
O15 - ESC Trusted Zone:
O15 - ESC Trusted Zone:
O15 - ESC Trusted Zone:
O15 - ESC Trusted Zone:
O15 - ESC Trusted Zone:
O15 - ESC Trusted Zone:
O15 - ESC Trusted Zone:
(HKLM)
O15 - ESC Trusted IP range:
O15 - ESC Trusted IP range:
O15 - ESC Trusted IP range:
O16 - DPF: {475DF11A-2BC2-41A9-8A97-E989E023E517} (SetupComponent Class) -
O16 - DPF: {6414512B-B978-451D-A0D8-FCFDF33E833C} (WUWebControl Class) -
O16 - DPF: {6E32070A-766D-4EE6-879C-DC1FA91D2FC3} (MUWebControl Class) -
O17 - HKLM\System\CCS\Services\Tcpip\Parameters: Domain = MILMAR.COM.EG
O17 - HKLM\Software\..\Telephony: DomainName = MILMAR.COM.EG
O17 - HKLM\System\CCS\Services\Tcpip\..\{A710B035-825F-4331-A98C-CFB66F6D9AF6}: NameServer = 213.131.66.246,213.131.66.138,10.70.49.1
O17 - HKLM\System\CCS\Services\Tcpip\..\{D8BF6E49-066B-4DF7-924D-CD25C488D446}: NameServer = 10.70.49.1
O17 - HKLM\System\CS1\Services\Tcpip\Parameters: Domain = MILMAR.COM.EG
O17 - HKLM\System\CS2\Services\Tcpip\Parameters: Domain = MILMAR.COM.EG
O23 - Service: pcAnywhere Host Service (awhost32) - Symantec Corporation - C:\Program Files\Symantec\pcAnywhere\awhost32.exe
O23 - Service: Intel File Transfer - Intel® Corporation - C:\WINDOWS\system32\cba\xfr.exe
O23 - Service: Microsoft Exchange Event (MSExchangeES) - Unknown owner - D:\Program Files\Exchsrvr\bin\events.exe (file missing)
O23 - Service: Savapi-Service - Avira GmbH - D:\Program Files\Avira\AntiVir Exchange\Engine\savapi2s.exe
O23 - Service: Savapi-Update-Service - Unknown owner - D:\Program Files\Avira\AntiVir Exchange\Engine\DwldSvc.exe (file missing)
O23 - Service: Symantec Mail Security Utility Service (SAVFMSESpamStatsManager) - Unknown owner - D:\Program Files\Symantec\SMSMSE\6.0\Server\SMSUtilityService.exe
O23 - Service: Symantec Mail Security for Microsoft Exchange (SMSMSE) - Symantec Corporation - D:\Program Files\Symantec\SMSMSE\6.0\Server\SAVFMSESrv.exe
O23 - Service: SPAMfighter - SPAMfighter ApS - C:\Program Files\SPAMfighter\bin\SPAMfighter.exe
O23 - Service: SQLSERVERAGENT - Unknown owner - D:\Program Files\Microsoft SQL Server\MSSQL\Binn\sqlagent.EXE (file missing)
O23 - Service: ThreatFire - PC Tools - d:\Program Files\ThreatFire\TFService.exe
--
End of file - 11951 bytes