How one can tell if and when anyone has logged on to a Windows PC?
Posted on 2011-09-06
I have a user that swears that he turned off his Windows XP Professional PC over the weekend. And that this morning, it was logged on and a web page was minimized(that he never openned). Additionally, the windows screen was not locked. I walked the user through changing his password and we took a look at the event viewer logs together.
The user's PC is a Windows XP Professional SP3 OS installed. The PC is set to go to 'standy by' mode after 15 minutes of innactivity. I did not see anything in the 'System' logs to indicate that his PC was turned on over the weekend. It appears that it was never tunred off actually.
I say this becasue I only see a 'The Event log service was started.' entry in the system logs after he restarted the PC today(after he came in).
My questions are:
1. How can I verify when the last time the PC was turned off?
2. How can I verify when the PC was turned on last?
3. How can I verify if the PC was locked (becasue of stand by mode) and then un-locked?
a. Unlocked by entering a username and password?
4. When I initiated a shutdown and start up right in front of the user, I was able to see the new system logs indicating a new restart. 'The Event log service was started.'