nebulus200, I do have administrative shares and anonymous access restricted now. When things started getting strange I did that. Everyone here helped me out and suggested that be the first thing to do. I do not thing I have index service turned off.. What are the potential hazards in this? I do have all the latest service packs and patches installed. I use Windows Critical Notification as well. As for other things I have done to lock down, I have removed all sample files, and also unmapped extenstion from IIS that aren't being used such as htr, htw, etc.... No FTP services running have anonymous access enabled.

Tedob1, I guess that is what I am going to have to do. I will reformat and all that, but I want to get to the bottom of this while I can. Though I look at this as a real shitty thing to happen, I am also looking at it as a major learning experience to help prevent this from happening again. Also it gives me a view from the cracker's side by seeing what they have done.

khakisrule, thanks for the suggestions, but I want to use this box to host sites. I actually have a few on there now, that is why I am bugging out about this. I can't play around like that. If it was a personal comp, I would, but not a business comp. I do weekly backups, and everything is saved.

Now for more nitty gritty fun stuff. I just downloaded this really great tool called AATools. It tells me what processes are running on what ports. Currently I am running DNS, IIS, and PCAnywhere. Those are the only programs that should be using ports that are open to the internet.

Here is what is running on my system. Any ideas? Some ports seem pretty strange.

dns.exe is running on port 53 which is normal, however it is also running on: 1027, 1028, 102, I do not know if that is normal.
inetinfo.exe is running on port 25 and 80 which is normal, however it is also running on: 1031, 1033, 3456, I do not know if that is normal.
lsass.exe is running on 500. I do not know if this is normal
MsgSys.exe is running on 38037. I have no clue what this is. It is located in: C:\WINNT\System32\MsgSys.exe
MSTask.exe is running on 1026. This is the task scheduler, I don't know why it has an port open. It is located in: C:\WINNT\system32\MsgSys.exe
services.exe is running on 1030... I do not know if this is normal. It is located in: C:\WINNT\system32\services.exe
svchost.exe is running on 135
System is running on 445. It did not give me any application name.

Any ideas anyone? The inetinfo.exe running on 3456 seems really strange.