Well it ran this time but it does not appear that anything was found to stop or delete. I have included the results of the cleanupHD screen and another HJT log below.
Please stick with me I really don't want to start from ground zero with a new OS and installation.
Rick
+++++++++++++++++++++++++++++++++++++++++++
Microsoft Windows XP [Version 5.1.2600]
© Copyright 1985-2001 Microsoft Corp.
C:\Documents and Settings\Rick>cd\windows\system32
C:\WINDOWS\system32>cleanupHD.bat
C:\WINDOWS\system32>REM based on Hacker Defender Removal Script from Brian Black
C:\WINDOWS\system32>sc.exe stop Fax
[SC] OpenService FAILED 1060:
The specified service does not exist as an installed service.
C:\WINDOWS\system32>sc.exe stop HackerDefender100
[SC] OpenService FAILED 1060:
The specified service does not exist as an installed service.
C:\WINDOWS\system32>sc.exe stop rpcxshell
[SC] OpenService FAILED 1060:
The specified service does not exist as an installed service.
C:\WINDOWS\system32>sc.exe stop DNTUS26
[SC] OpenService FAILED 1060:
The specified service does not exist as an installed service.
C:\WINDOWS\system32>sc.exe stop rmtbackup
[SC] OpenService FAILED 1060:
The specified service does not exist as an installed service.
C:\WINDOWS\system32>sc.exe delete Fax
[SC] OpenService FAILED 1060:
The specified service does not exist as an installed service.
C:\WINDOWS\system32>sc.exe delete HackerDefender100
[SC] OpenService FAILED 1060:
The specified service does not exist as an installed service.
C:\WINDOWS\system32>sc.exe delete rpcxshell
[SC] OpenService FAILED 1060:
The specified service does not exist as an installed service.
C:\WINDOWS\system32>sc.exe delete rsaservice
[SC] OpenService FAILED 1060:
The specified service does not exist as an installed service.
C:\WINDOWS\system32>sc.exe delete DNTUS26
[SC] OpenService FAILED 1060:
The specified service does not exist as an installed service.
C:\WINDOWS\system32>sc.exe delete rmtbackup
[SC] OpenService FAILED 1060:
The specified service does not exist as an installed service.
C:\WINDOWS\system32>del /f /q C:\WINDOWS\FAXSV.EXE
Could Not Find C:\WINDOWS\FAXSV.EXE
C:\WINDOWS\system32>del /f /q C:\WINDOWS\HXDEF100.EXE
Could Not Find C:\WINDOWS\HXDEF100.EXE
C:\WINDOWS\system32>del /f /q C:\WINDOWS\HXDEF100.INI
Could Not Find C:\WINDOWS\HXDEF100.INI
C:\WINDOWS\system32>del /f /q C:\WINDOWS\HXDEFDRV.SYS
Could Not Find C:\WINDOWS\HXDEFDRV.SYS
C:\WINDOWS\system32>del /f /q C:\WINDOWS\vb6dll.ocx
Could Not Find C:\WINDOWS\vb6dll.ocx
C:\WINDOWS\system32>del /f /q C:\WINDOWS\rasmins.dll
Could Not Find C:\WINDOWS\rasmins.dll
C:\WINDOWS\system32>del /f /q C:\WINDOWS\dpvcs.dll
Could Not Find C:\WINDOWS\dpvcs.dll
C:\WINDOWS\system32>del /f /q C:\WINDOWS\syslog.exe
Could Not Find C:\WINDOWS\syslog.exe
C:\WINDOWS\system32>del /f /q C:\WINDOWS\msinldt.dll
Could Not Find C:\WINDOWS\msinldt.dll
C:\WINDOWS\system32>del /f /q C:\WINDOWS\DNTUS26.EXE
Could Not Find C:\WINDOWS\DNTUS26.EXE
C:\WINDOWS\system32>del /f /q C:\WINDOWS\kills.exe
Could Not Find C:\WINDOWS\kills.exe
C:\WINDOWS\system32>del /f /q C:\WINDOWS\port.exe
Could Not Find C:\WINDOWS\port.exe
C:\WINDOWS\system32>del /f /q C:\WINDOWS\rmtbckp.exe
Could Not Find C:\WINDOWS\rmtbckp.exe
C:\WINDOWS\system32>del /f /q C:\WINDOWS\System32\FAXSV.EXE
Could Not Find C:\WINDOWS\System32\FAXSV.EXE
C:\WINDOWS\system32>del /f /q C:\WINDOWS\System32\HXDEF100.EXE
Could Not Find C:\WINDOWS\System32\HXDEF100.EXE
C:\WINDOWS\system32>del /f /q C:\WINDOWS\System32\HXDEF100.INI
Could Not Find C:\WINDOWS\System32\HXDEF100.INI
C:\WINDOWS\system32>del /f /q C:\WINDOWS\System32\HXDEFDRV.SYS
Could Not Find C:\WINDOWS\System32\HXDEFDRV.SYS
C:\WINDOWS\system32>del /f /q C:\WINDOWS\System32\vb6dll.ocx
Could Not Find C:\WINDOWS\System32\vb6dll.ocx
C:\WINDOWS\system32>del /f /q C:\WINDOWS\System32\rasmins.dll
Could Not Find C:\WINDOWS\System32\rasmins.dll
C:\WINDOWS\system32>del /f /q C:\WINDOWS\System32\dpvcs.dll
Could Not Find C:\WINDOWS\System32\dpvcs.dll
C:\WINDOWS\system32>del /f /q C:\WINDOWS\System32\syslog.exe
Could Not Find C:\WINDOWS\System32\syslog.exe
C:\WINDOWS\system32>del /f /q C:\WINDOWS\System32\msinldt.dll
Could Not Find C:\WINDOWS\System32\msinldt.dll
C:\WINDOWS\system32>del /f /q C:\WINDOWS\System32\DNTUS26.EXE
Could Not Find C:\WINDOWS\System32\DNTUS26.EXE
C:\WINDOWS\system32>del /f /q C:\WINDOWS\System32\kills.exe
Could Not Find C:\WINDOWS\System32\kills.exe
C:\WINDOWS\system32>del /f /q C:\WINDOWS\System32\port.exe
Could Not Find C:\WINDOWS\System32\port.exe
C:\WINDOWS\system32>del /f /q C:\WINDOWS\System32\rmtbckp.exe
Could Not Find C:\WINDOWS\System32\rmtbckp.exe
C:\WINDOWS\system32>del /f /q C:\WINDOWS\System\FAXSV.EXE
Could Not Find C:\WINDOWS\System\FAXSV.EXE
C:\WINDOWS\system32>del /f /q C:\WINDOWS\System\HXDEF100.EXE
Could Not Find C:\WINDOWS\System\HXDEF100.EXE
C:\WINDOWS\system32>del /f /q C:\WINDOWS\System\HXDEF100.INI
Could Not Find C:\WINDOWS\System\HXDEF100.INI
C:\WINDOWS\system32>del /f /q C:\WINDOWS\System\HXDEFDRV.SYS
Could Not Find C:\WINDOWS\System\HXDEFDRV.SYS
C:\WINDOWS\system32>del /f /q C:\WINDOWS\System\vb6dll.ocx
Could Not Find C:\WINDOWS\System\vb6dll.ocx
C:\WINDOWS\system32>del /f /q C:\WINDOWS\System\rasmins.dll
Could Not Find C:\WINDOWS\System\rasmins.dll
C:\WINDOWS\system32>del /f /q C:\WINDOWS\System\dpvcs.dll
Could Not Find C:\WINDOWS\System\dpvcs.dll
C:\WINDOWS\system32>del /f /q C:\WINDOWS\System\syslog.exe
Could Not Find C:\WINDOWS\System\syslog.exe
C:\WINDOWS\system32>del /f /q C:\WINDOWS\System\msinldt.dll
Could Not Find C:\WINDOWS\System\msinldt.dll
C:\WINDOWS\system32>del /f /q C:\WINDOWS\System\DNTUS26.EXE
Could Not Find C:\WINDOWS\System\DNTUS26.EXE
C:\WINDOWS\system32>del /f /q C:\WINDOWS\System\kills.exe
Could Not Find C:\WINDOWS\System\kills.exe
C:\WINDOWS\system32>del /f /q C:\WINDOWS\System\port.exe
Could Not Find C:\WINDOWS\System\port.exe
C:\WINDOWS\system32>del /f /q C:\WINDOWS\System\rmtbckp.exe
Could Not Find C:\WINDOWS\System\rmtbckp.exe
C:\WINDOWS\system32>
+++++++++++++++++++++++++++++++++++++++++++++++++++
Logfile of HijackThis v1.99.1
Scan saved at 11:46:20 PM, on 7/13/2005
Platform: Windows XP SP2 (WinNT 5.01.2600)
MSIE: Internet Explorer v6.00 SP2 (6.00.2900.2180)
Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\Program Files\STOPzilla!\szntsvc.exe
C:\Program Files\Common Files\Symantec Shared\ccSetMgr.exe
C:\Program Files\Common Files\Symantec Shared\SNDSrvc.exe
C:\Program Files\Common Files\Symantec Shared\SPBBC\SPBBCSvc.exe
C:\Program Files\Common Files\Symantec Shared\ccEvtMgr.exe
C:\WINDOWS\system32\spoolsv.exe
C:\Program Files\APC\APC PowerChute Personal Edition\mainserv.exe
C:\WINDOWS\System32\drivers\CDAC11BA.EXE
C:\Program Files\Norton AntiVirus\navapsvc.exe
C:\Program Files\Norton AntiVirus\IWP\NPFMntor.exe
C:\Program Files\Common Files\Symantec Shared\CCPD-LC\symlcsvc.exe
C:\WINDOWS\System32\ups.exe
C:\WINDOWS\Explorer.EXE
C:\WINDOWS\system32\wuauclt.exe
C:\Fixing Files\HijackThis.exe
R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page =
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page =
R0 - HKLM\Software\Microsoft\Internet Explorer\Search,SearchAssistant =
R0 - HKLM\Software\Microsoft\Internet Explorer\Search,CustomizeSearch =
R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Local Page =
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Local Page =
O2 - BHO: AcroIEHlprObj Class - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Adobe\Acrobat 6.0\Acrobat\ActiveX\AcroIEHelper.dll
O2 - BHO: AcroIEToolbarHelper Class - {AE7CD045-E861-484f-8273-0445EE161910} - C:\Program Files\Adobe\Acrobat 6.0\Acrobat\AcroIEFavClient.dll
O2 - BHO: NAV Helper - {BDF3E430-B101-42AD-A544-FADC6B084872} - C:\Program Files\Norton AntiVirus\NavShExt.dll
O2 - BHO: STOPzilla Browser Helper Object - {E3215F20-3212-11D6-9F8B-00D0B743919D} - C:\WINDOWS\System32\StopzillaBHO.dll
O3 - Toolbar: Adobe PDF - {47833539-D0C5-4125-9FA8-0819E2EAAC93} - C:\Program Files\Adobe\Acrobat 6.0\Acrobat\AcroIEFavClient.dll
O3 - Toolbar: Norton AntiVirus - {42CDD1BF-3FFB-4238-8AD1-7859DF00B1D6} - C:\Program Files\Norton AntiVirus\NavShExt.dll
O4 - Global Startup: Acrobat Assistant.lnk = C:\Program Files\Adobe\Acrobat 6.0\Distillr\acrotray.exe
O4 - Global Startup: APC UPS Status.lnk = ?
O4 - Global Startup: Microsoft Office.lnk = C:\Program Files\Microsoft Office\Office\OSA9.EXE
O4 - Global Startup: WinZip Quick Pick.lnk = C:\Program Files\WinZip\WZQKPICK.EXE
O6 - HKCU\Software\Policies\Microsoft\Internet Explorer\Control Panel present
O9 - Extra button: SEARCH - {0B5F1910-F111-11d2-BB9E-00C04F7956B1} -
http://www001.upp.so.....49Z/find.html (file missing)
O9 - Extra button: ANTIVIRUS - {0B5F1910-F111-11d2-BB9E-00C04F7956B2} -
http://www001.upp.so.../antivirus.html (file missing)
O9 - Extra button: ENTERTAINMENT - {0B5F1910-F111-11d2-BB9E-00C04F7956B3} -
http://www001.upp.so...4...IZ/ggo.html (file missing)
O9 - Extra button: SECURITY - {0B5F1910-F111-11d2-BB9E-00C04F7956B4} -
http://www001.upp.so.....Z/warning.htm (file missing)
O9 - Extra button: SEARCH - {0B5F1910-F111-11d2-BB9E-00C04F7956B5} -
http://www001.upp.so.../topsearch.html (file missing)
O9 - Extra button: (no name) - {120E090D-9136-4b78-8258-F0B44B4BD2AC} - C:\WINDOWS\System32\ms.exe (file missing)
O9 - Extra 'Tools' menuitem: MaxSpeed - {120E090D-9136-4b78-8258-F0B44B4BD2AC} - C:\WINDOWS\System32\ms.exe (file missing)
O9 - Extra button: Microsoft® JavaScript® Console - {62C369E6-4AC1-4B37-B7C9-C6844F60704E} - C:\WINDOWS\system32\comdlg32.ocx
O9 - Extra 'Tools' menuitem: JavaScript Console - {62C369E6-4AC1-4B37-B7C9-C6844F60704E} - C:\WINDOWS\system32\comdlg32.ocx
O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O9 - Extra button: Microsoft® JavaScript® Console - {62C369E6-4AC1-4B37-B7C9-C6844F60704E} - C:\WINDOWS\system32\comdlg32.ocx (HKCU)
O9 - Extra 'Tools' menuitem: JavaScript Console - {62C369E6-4AC1-4B37-B7C9-C6844F60704E} - C:\WINDOWS\system32\comdlg32.ocx (HKCU)
O16 - DPF: {1E2941E3-8E63-11D4-9D5A-00902742D6E0} (iNotes Class) -
http://coles2.kennesaw.edu/iNotes.cabO16 - DPF: {2BC66F54-93A8-11D3-BEB6-00105AA9B6AE} (Symantec AntiVirus scanner) -
http://security.syma...bin/AvSniff.cabO16 - DPF: {644E432F-49D3-41A1-8DD5-E099162EEEC5} (Symantec RuFSI Utility Class) -
http://security.syma...n/bin/cabsa.cabO23 - Service: APC UPS Service - American Power Conversion Corporation - C:\Program Files\APC\APC PowerChute Personal Edition\mainserv.exe
O23 - Service: C-DillaCdaC11BA - Macrovision - C:\WINDOWS\System32\drivers\CDAC11BA.EXE
O23 - Service: Symantec Event Manager (ccEvtMgr) - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\ccEvtMgr.exe
O23 - Service: Symantec Password Validation (ccPwdSvc) - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\ccPwdSvc.exe
O23 - Service: Symantec Settings Manager (ccSetMgr) - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\ccSetMgr.exe
O23 - Service: Norton AntiVirus Auto-Protect Service (navapsvc) - Symantec Corporation - C:\Program Files\Norton AntiVirus\navapsvc.exe
O23 - Service: Norton AntiVirus Firewall Monitor Service (NPFMntor) - Symantec Corporation - C:\Program Files\Norton AntiVirus\IWP\NPFMntor.exe
O23 - Service: SAVScan - Symantec Corporation - C:\Program Files\Norton AntiVirus\SAVScan.exe
O23 - Service: ScriptBlocking Service (SBService) - Symantec Corporation - C:\PROGRA~1\COMMON~1\SYMANT~1\SCRIPT~1\SBServ.exe
O23 - Service: Symantec Network Drivers Service (SNDSrvc) - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\SNDSrvc.exe
O23 - Service: Symantec SPBBCSvc (SPBBCSvc) - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\SPBBC\SPBBCSvc.exe
O23 - Service: STOPzilla Local Service - International Software Systems Solutions - C:\Program Files\STOPzilla!\szntsvc.exe
O23 - Service: Symantec Core LC - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\CCPD-LC\symlcsvc.exe
O23 - Service: SymWMI Service (SymWSC) - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\Security Center\SymWSC.exe