You don’t need to be a security expert to check five things on your PC this weekend. No downloads, no jargon you won’t understand by the end of the sentence, nothing you can’t undo if you get it wrong. Just five places in Windows worth actually looking at, most of which you’ve probably never opened.
Grab a coffee, sit down at your PC, and work through these in order. Ten to fifteen minutes, tops.
1. Check If Remote Desktop Is Quietly Turned On
Remote Desktop lets someone connect to your PC over the internet and use it as if they were sitting in front of it. Plenty of people have it enabled and don’t know it — sometimes turned on by an old troubleshooting session, sometimes by a “helpful” family member, sometimes by default depending on how the machine was set up.
Open Settings, go to System, then click Remote Desktop. If the toggle is on and you don’t actively use this feature — say, to connect to your work PC from home — turn it off. If you do use it, at least check who’s listed under “Select users that can remotely access this PC” and make sure it’s only people you recognize.
This is the check most likely to produce a genuine surprise. If you find it on and you never turned it on, that’s worth sitting with for a second.
2. See Who’s Actually Logged Into This Machine
Windows keeps a detailed record of every login and every failed login attempt. It’s just buried somewhere you’ve probably never gone looking.
Search for Event Viewer in the Start menu and open it. On the left, expand Windows Logs, then click Security. You’ll see a long list of entries — most of it is routine background noise, but you’re looking for two specific event IDs: 4624, which means a successful login, and 4625, which means a failed one.
You can filter for these directly: click “Filter Current Log” on the right-hand panel and type 4625 into the Event ID field to isolate just the failures. One or two failed logins scattered across weeks is completely normal — everyone fat-fingers a password now and then. What’s worth noticing is a cluster of failures in a short window, especially at an hour nobody in your house or office would be at the keyboard.
This is also, honestly, the most tedious check on this list. Worth remembering that for later.
3. Check Who Has Admin Rights on This PC
Every account on your PC is either a Standard user or an Administrator. Administrator accounts can install software, change security settings, and access anything on the machine. It’s worth knowing exactly who has that level of access, because it’s surprisingly common to find an account you’d completely forgotten about.
Go to Settings, then Accounts, then Other users (on some versions of Windows this section is still labeled “Family & other users”). Look through the list. An old contractor’s account that was never removed. A “test” profile from years ago. A family member’s login on a shared machine that somehow ended up with admin rights it never needed.
If you find something you don’t recognize or no longer need, remove it. If you find an account that has admin rights but doesn’t need them, click on it, select “Change account type,” and switch it to Standard User.
4. Look for Anything Scheduled to Run That You Didn’t Schedule
This one sounds more technical than it is. Search for Task Scheduler and open it. Click on Task Scheduler Library on the left to see everything set up to run automatically on your PC — some of it from Windows itself, some from apps you’ve installed, and occasionally, something that shouldn’t be there at all.
You’re not trying to become an expert in reading this list. You’re just scanning for anything with an unfamiliar name, especially anything that runs at odd hours or references a program you don’t recognize. Malware and browser hijackers commonly use scheduled tasks to relaunch themselves even after you think you’ve removed them, so this is a genuinely useful thing to glance at periodically, not just once.
5. Check When This PC Last Restarted Unexpectedly
Head back into Event Viewer, but this time click on Windows Logs, then System. You’re looking for Event ID 41, which Windows logs specifically when the system starts back up after a shutdown that wasn’t clean — a crash, a power loss, or a forced restart that didn’t go through the normal process.
An occasional one of these is nothing to worry about. Everyone’s had a machine crash or a power cut. But a pattern of them, especially on a PC you don’t remember touching at the time, is one of the quieter early signs that something is running on your machine that you didn’t put there.
So, How Did It Go?
If you made it through all five, you now know more about your own PC than most people ever bother to find out. Good. Bookmark this page and run through it again in a few months — it’s the kind of thing that’s easy to do once and then never think about again, which somewhat defeats the purpose.
But here’s the honest part: security isn’t really a once-a-weekend chore. It’s an ongoing state. The next failed login attempt, the next unexpected reboot, the next unfamiliar RDP connection — none of them are going to wait politely for your next Saturday afternoon with Event Viewer open.
That’s really the whole idea behind Login AlertX. Instead of manually digging through logs every so often, it watches for the same kinds of events you just checked by hand — logins, failed attempts, remote connections, unexpected reboots, and nineteen others — and sends you an alert the moment one happens. Email, WhatsApp, Slack, Teams, whatever you actually look at.
You just did the manual version. This is what it looks like when something else does it for you, continuously, without you having to remember to check.
Login AlertX is free to download for Windows 7 through 11, with no login events monitored requiring you to open Event Viewer again. See how it works.
