Avatar of Joseph Salazar
Joseph Salazar
Flag for United States of America asked on

How can I see if someone is logged into my computer

Have a client who was logged in remotely using Logmein

All of a sudden the mouse was moving and opening files

She does not know if her laptop is hacked or if someone could be in the office or hacked into her computer at the office

How can I see when a computer log that shows when someone logs in?

Either on the Server or Windows 7 Desktop

We have a server 2012 r2 and the Workstations are all Win7-Pro 64bit with all patches applied

We have a Sophos firewall and sophos Antivirus and Intercept X on all pc's

Windows 7SecurityWindows Server 2012

Avatar of undefined
Last Comment
Joseph Salazar

8/22/2022 - Mon
William Miller

Log in or sign up to see answer
Become an EE member today7-DAY FREE TRIAL
Members can start a 7-Day Free trial then enjoy unlimited access to the platform
Sign up - Free for 7 days
Learn why we charge membership fees
We get it - no one likes a content blocker. Take one extra minute and find out why we block content.
Not exactly the question you had in mind?
Sign up for an EE membership and get your own personalized solution. With an EE membership, you can ask unlimited troubleshooting, research, or opinion questions.
ask a question

How exactly is logmein configured? I'd recommend making sure that it's set so that the local keyboard and mouse are locked during remote sessions.


Also, the screen should be blanked during remote sessions: https://secure.logmein.com/welcome/webhelp/EN/Pro/LogMeIn/t_remotecontrol_blank.html

Those two steps would at least prevent someone in front of the computer from doing anything.

You could try to use login events from the domain controller, but that also assumes that your user is logging off the computer when they leave the office.

Check windows logs:

Press Windows button + R and type eventvwr.msc.
In event viewer, Expand Windows Logs, and select System.
In the middle you’ll see a list with Date and Time, Source, Event ID and Task Category.  The Task Category pretty much explains the event, Logon, Special Logon, Logoff and other details. Also you can audit the successful or failed logon and logoff attempts in the network using the audit policies: https://www.lepide.com/blog/audit-successful-logon-logoff-and-failed-logons-in-activedirectory/

The event Details will contain the UserSid of Account logging on, which you can match with a list obtained from Command Prompt using:

wmic useraccount 

Open in new window

How to Find Out if Someone's Secretly Been Using Your Computer

Hope this helps!
Joseph Salazar

Yep it is a Defective Mouse
I started with Experts Exchange in 2004 and it's been a mainstay of my professional computing life since. It helped me launch a career as a programmer / Oracle data analyst
William Peck