Lt_Bromhead said:
Okay - so it seems I might have found something of an...untrustworthy nature...on my system.
Google searched all the processess and found this little chap lurking at the bottom:
"winlogon.exe"
Now it sounds like a winlogon executeable is normally a reliable fellow to have running, as it's your user authenticator within Windows. This is only if it's running from the System32 folder, however, and when I tried to check the properties of this file nothing happened. I tried to open the file's location, and to get it's properties, and nothing happened.
I took a gamble and tried to end the process, but I just got the message "This operation could not be completed. Access is denied". Now I'm using an administrator account, so I should have full access throughout the computer. I know that even vital windows processes let you end them, despite the possible effect on the system.
A bit worried here.
Any advice on what to do, chaps? :/
Download a Linux ISO (Ubuntu 11.04 for the easy way), then hit PenDriveLinux.com for YUMI ? Multiboot USB Creator (Windows) [http://www.pendrivelinux.com/yumi-multiboot-usb-creator/], download and run YUMI to 'burn' the Linux ISO to a USB thumb drive (anything that's 1GB or bigger will work, 4GB is best).
Having your new USB Linux Live Drive (akin to a Live Disk but on a thumb drive instead), reboot the system and hit whichever button the boot sequance tells you to get into a Boot Selection Menu (from which one can boot from optical disc, USB drive, or an internal drive), once there select the USB Drive option and let Linux load up from the USB drive.
Now you are within Linux, and the fake winlogin.exe will no longer work, so you can go through and clear it out (if you have found where it is hiding. if not sure, open firefox and google for it againt, as you've done before here).
Once you've cleared it out (where the virus is hiding will tend to depend if you're running XP or vista/7) you can reboot the system and take the thumb drive out so Windows will boot up once again without the fake winlogin.exe running (as it doesn't exist anymore).
~~~~
I know this might seem a complex procedure, but by swapping to Linux (as a temporary OS on a live drive at least) one prevents any malicious program written for Windows from running so you can clear it out.
I myself have had a problem like this (not full-out banning, but enough that I changed the password to my B.Net/WoW account, changed the email address it was on, changed the password of the original email address, and made sure I'm the only one accessing that address), but it was somewhat easy to get control back and undo any damage done by those who hijacked my account (not to mention killed off the character they created that caused the issue in the first place).