Tea,
In addition to the ewido report and hijackthis log (on the previous page) I have some more information. Apparently the virus downloader program is still active and is still downloading ww32.exe files onto the documents and settings folders of any user that logs on, however the file with the virus is inside something called dotrm.dll or something spelled like that.