CMC Sentinel Deutsch Windows guide

WINDOWS REMOTE-ACCESS CHECKLIST

Is someone remotely accessing my Windows PC?

A moving cursor, an unfamiliar process or a network connection can be unsettling. None of those signals proves an intrusion on its own. These eight checks help you separate normal Windows activity from evidence that deserves action.

8 practical checksWindows 11 and supported Windows 10 environmentsOfficial Microsoft referencesUpdated 28 September 2026

If someone appears to be controlling the PC right now

If the cursor moves, windows open or text appears without your input and you did not authorize remote support, disconnect that PC from Wi-Fi or unplug Ethernet to interrupt the connection. Note the time and what you saw. Use a separate trusted device for urgent account recovery. Do not start deleting random files or disabling Windows services: that can remove evidence and damage the system without removing the cause.

1. Check whether Windows Remote Desktop is enabled

Open Settings → System → Remote Desktop. If you never use Remote Desktop, it should normally be off. Microsoft notes that a PC accepting Remote Desktop connections needs a Pro edition of Windows; a Windows Home PC can still act as a client.

Do not switch it off during an authorized work or support session without checking first. The setting only covers Microsoft's Remote Desktop host. Other support tools use their own services and settings.

2. Review signed-in users and running processes

Press Ctrl + Shift + Esc to open Task Manager. Check the Users, Processes and Details views. Look for a user session you do not recognize or a remote-support application you did not install or authorize.

A strange name is not automatically malicious. Note its exact name, publisher, file path and process ID before taking action. Windows components often use names that are unfamiliar to non-technical users.

3. Match active connections to their processes

Open Command Prompt as an administrator and run netstat -ano. Microsoft documents that the -o option includes the PID for each active TCP connection. Match that PID to Task Manager's Details tab.

An ESTABLISHED connection is not proof of remote control: browsers, cloud storage, messaging apps and Windows services all connect to the internet. Investigate the owning process, its path and whether the destination makes sense for the application.

4. Review successful Windows logons

Open Event Viewer → Windows Logs → Security and filter for event ID 4624. Microsoft defines logon type 10 as RemoteInteractive, used for Terminal Services or Remote Desktop.

Compare the timestamp, account name, workstation and source network address with activity you expect. One type-10 event does not prove an attack; it may be your own authorized Remote Desktop session. Remote-support applications that do not use RDP may not create this logon type at all.

5. Check startup applications

Open Settings → Apps → Startup or Task Manager's Startup apps tab. Microsoft explains that Task Manager shows the registered startup applications and their startup impact.

Document unfamiliar entries before disabling them. Avoid broad registry edits or disabling Microsoft services simply because a name looks technical. If you identify a specific unwanted application, remove it through Settings and then scan the PC.

6. Run a full Microsoft Defender scan

Open Windows Security → Virus & threat protection → Scan options and start a full scan. Make sure security intelligence is current first.

If you remain concerned, choose Microsoft Defender Offline scan. Microsoft states that this restarts the PC and scans in the Windows Recovery Environment, making it harder for persistent malware to hide while Windows is running. Save your work before starting it.

7. Secure accounts from a trusted environment

If you saw active unauthorized control, use a different trusted device for urgent email, Microsoft-account and banking security. Review recent sign-ins, remove unknown recovery methods and enable a passkey or another strong verification method.

Microsoft's compromised-account guidance recommends clearing malware from the affected PC before changing the password on that PC. Do not reuse an old password and do not approve unexpected verification prompts.

8. Update, monitor and escalate when needed

Install current Windows and application updates. Free security updates for Windows 10 ended on 14 October 2025 unless the device is covered by an applicable extended-support option, so plan an upgrade to a supported Windows version.

Seek professional incident-response help if you handle sensitive business data, see unknown administrator accounts, find repeated unauthorized logons, suspect financial theft or cannot restore trust in the device. Preserve screenshots, timestamps and relevant logs.

Official Microsoft references