turn off "remote assistance" & "remote desktop"
1)Check your "termsrv.dll" and make sure it's not modified.
2)"start->run->control userpasswords2" to check all users in your system. Delete all suspicious user accounts in your system.
3)Don't use administrator or accounts with equivalent rights to log in.