1. Check whether Windows Remote Desktop is enabled
Open Settings → System → Remote Desktop. If you never use Remote Desktop, it should normally be off. Microsoft notes that a PC accepting Remote Desktop connections needs a Pro edition of Windows; a Windows Home PC can still act as a client.
Do not switch it off during an authorized work or support session without checking first. The setting only covers Microsoft's Remote Desktop host. Other support tools use their own services and settings.
2. Review signed-in users and running processes
Press Ctrl + Shift + Esc to open Task Manager. Check the Users, Processes and Details views. Look for a user session you do not recognize or a remote-support application you did not install or authorize.
A strange name is not automatically malicious. Note its exact name, publisher, file path and process ID before taking action. Windows components often use names that are unfamiliar to non-technical users.
3. Match active connections to their processes
Open Command Prompt as an administrator and run netstat -ano. Microsoft documents that the -o option includes the PID for each active TCP connection. Match that PID to Task Manager's Details tab.
An ESTABLISHED connection is not proof of remote control: browsers, cloud storage, messaging apps and Windows services all connect to the internet. Investigate the owning process, its path and whether the destination makes sense for the application.
4. Review successful Windows logons
Open Event Viewer → Windows Logs → Security and filter for event ID 4624. Microsoft defines logon type 10 as RemoteInteractive, used for Terminal Services or Remote Desktop.
Compare the timestamp, account name, workstation and source network address with activity you expect. One type-10 event does not prove an attack; it may be your own authorized Remote Desktop session. Remote-support applications that do not use RDP may not create this logon type at all.
5. Check startup applications
Open Settings → Apps → Startup or Task Manager's Startup apps tab. Microsoft explains that Task Manager shows the registered startup applications and their startup impact.
Document unfamiliar entries before disabling them. Avoid broad registry edits or disabling Microsoft services simply because a name looks technical. If you identify a specific unwanted application, remove it through Settings and then scan the PC.
6. Run a full Microsoft Defender scan
Open Windows Security → Virus & threat protection → Scan options and start a full scan. Make sure security intelligence is current first.
If you remain concerned, choose Microsoft Defender Offline scan. Microsoft states that this restarts the PC and scans in the Windows Recovery Environment, making it harder for persistent malware to hide while Windows is running. Save your work before starting it.
7. Secure accounts from a trusted environment
If you saw active unauthorized control, use a different trusted device for urgent email, Microsoft-account and banking security. Review recent sign-ins, remove unknown recovery methods and enable a passkey or another strong verification method.
Microsoft's compromised-account guidance recommends clearing malware from the affected PC before changing the password on that PC. Do not reuse an old password and do not approve unexpected verification prompts.
8. Update, monitor and escalate when needed
Install current Windows and application updates. Free security updates for Windows 10 ended on 14 October 2025 unless the device is covered by an applicable extended-support option, so plan an upgrade to a supported Windows version.
Seek professional incident-response help if you handle sensitive business data, see unknown administrator accounts, find repeated unauthorized logons, suspect financial theft or cannot restore trust in the device. Preserve screenshots, timestamps and relevant logs.