How to know if Someone Access your Computer without your Permission

How to find if someone logged into your computer without permission

Do you want to know who access your computer in your absence ?  this is important because you want to know if something has been done to your computer when you were not around , hackers could have install something in your pc that will give a remote access to your PC and that will be very bad .

To make this possible we are going to use an inbuilt windows feature called Windows Event Viewer. The Event Viewer post a notification in an Event Log when ever a user start a program on a PC , it also record every security changes all the system access  and all driver issues

This gives you a very powerful control over your PC .

How to start Event Viewer in Windows PC?

To start Event Viewer in your Windows 7 and 8.1, you need to click the Start Button and open the Control Panel. Now find the System and Maintenace option and click on it. There, you’ll find Administrative Tool which will contain Event Viewer.

You access the Event Viewer on your windows 7,8,8.1 PC by

  1. Open the control panel
  2. Click on the System and Maintenance option
  3. Choose the Administrative Tool and the choose Event Viewer
  4. Or simply open Run dialog by pressing Windows+R key and type in the Run dialog eventvwr

You open the Event Viewer in windows 10 by simply pressing Windows + X and then choose Event Views in the menu. Or you can also perform the fourth step.

Now, after opening Event Viewer in your Windows PC,  it time to find out if indeed some one used your PC and you do that by locating Windows Logs > System. In the middle pane, this will open a list of the events that took place when Windows system was running. The events might take a couple of moments to populate.Here, click on any row in the middle pane to open a new pop-up with the information about that particular event.

Now, to find out if someone logged into your PC, you need to sort this data.

To do this, click on the Filter Current Log button in the right pane. Firstly, make sure that Event logs field shows System. Secondly, make sure that User field shows <All Users>.As shown in the screenshot, enter event IDs 6005 and 6006 in the empty field. This will filter the System events.

You can see the start-up and shut down time in the Date and Time column. Here, Event ID 6005 means “The event log service was started” (i.e. start-up time) and 6006 means “The event log service was stopped

Categories: 

Share This Story

Subscribe to RUUT.ug

Keep Up with Technology! Our news to your Email

About Author

A Technology enthusiast, developer and content maker that wants to keep you in the loop of that i keep an eye on. Let's Tech