Hacker Newsnew | past | comments | ask | show | jobs | submitlogin

Have you looked into Windows logs?


I saw these entries in Event Viewer -> TerminalServices-LocalSessionManager.

I tried to turn it on around 8:50 pm. Here, "SURFACE\name" is my MS account.

> 4/9/2018 8:49:40 PM Remote Desktop Services: Session logoff succeeded: User: SURFACE\name Session ID: 3

> 4/9/2018 8:49:40 PM Session 3 has been disconnected by session 3

> 4/9/2018 8:49:40 PM %s from %S( #0x%x/0x%x )

> 4/9/2018 8:49:40 PM Session 3 has been disconnected, reason code 11

> 4/9/2018 8:49:41 PM Session 4 has been disconnected, reason code 11

> 4/9/2018 8:49:41 PM Remote Desktop Services: Session has been disconnected: User: SURFACE\name Session ID: 3 Source Network Address: LOCAL

> 4/9/2018 8:51:00 PM Begin session arbitration: User: SURFACE\name Session ID: 4

> 4/9/2018 8:51:00 PM End session arbitration: User: SURFACE\name Session ID: 4

>4/9/2018 8:51:00 PM Remote Desktop Services: Session logon succeeded: User: SURFACE\name Session ID: 4 Source Network Address: LOCAL

>4/9/2018 8:51:00 PM Remote Desktop Services: Shell start notification received: User: SURFACE\name Session ID: 4 Source Network Address: LOCAL

I am not sure if the entries at 8:49 pm is what I saw as the "remote session active". Also, I am not sure if this LocalSessionManager is the right place to look.


Your post prompted me to check my own Even Viewer. After some frenzied searching for the meaning of "Remote Desktop Services" entries in my own logs I figured that alarm seems to stem only from unfortunate naming of events that LocalSessionManager drops. As this document describes[0] and after confirming with another account the events are generated when one account wishes to run a processes under another account ("Run as administrator/different user" functionality). It might be that Windows Update triggered this on your computer, consider also that Windows Update sometimes updates third party drivers and one wouldn't expect they follow all best practices.

[0] https://docs.microsoft.com/en-us/windows-hardware/customize/...


There should be another TerminalServices-something or RemoteDesktop-something log which logs connection attempts in more detail.




Guidelines | FAQ | Lists | API | Security | Legal | Apply to YC | Contact

Search: