Share via

How to know if there is a remote desktop connection hack?

Anonymous
2025-02-25T06:17:46+00:00

Hello, I recently learned about the netstat /nbf command while watching youtube, I went to use it out of curiosity and found a bunch of connections that are labelled as remotedesktopcompanion.exe and some of them are listed as established. I am not even really sure what to look for its just very concerning as I have ran multiple virus scans with nothing coming up. Some have a :443 number at the end of ip, the video said to do a find "3389", "5500" and "5900" cmd and it would it would show anything that comes up, yet nothing came up and yet there is still those multiple listed remotedesktopcompanion.exe. I am really worried and any help is appreciated thank you. I am not really sure what info I need to share so please let me know.

Windows for home | Windows 11 | Security and privacy

Locked Question. This question was migrated from the Microsoft Support Community. You can vote on whether it's helpful, but you can't add comments or replies or follow the question.

0 comments No comments

Answer accepted by question author

Francisco Montilla 30,635 Reputation points Independent Advisor
2025-02-25T07:07:04+00:00

HI Reilly,

Best you can do right now is to check your Windows Security Event Logs for any Remote Desktop logon activity you don’t recognize. Remotedesktopcompanion.exe is a legitimate system process usually located in C:\Windows\System32, so its appearance in netstat isn’t uncommon.

To be sure nothing’s amiss, open Event Viewer (press Windows key + R, type eventvwr, and hit Enter), then navigate to Windows Logs → Security. Look for Remote Desktop logon events and check details such as the source IP, the time, and whether the logons match your typical usage.

If nothing looks unusual, then the established connections you’re seeing are most likely normal background activity.

Was this answer helpful?

4 people found this answer helpful.
0 comments No comments

Answer accepted by question author

Francisco Montilla 30,635 Reputation points Independent Advisor
2025-02-26T04:36:27+00:00

Hi Reilly,

Grad to hear that! Yes, I just found too that it's related to Oculus, but maybe there was no need to delete, it's probably just a telemetry tool or a feature.

Anyway I'm happy to see you have your issue solved. Feel free to reach out to the Community again if you ever have a new question or issue. Your feedback is really appreciated. :)

Was this answer helpful?

2 people found this answer helpful.
0 comments No comments

Answer accepted by question author

Francisco Montilla 30,635 Reputation points Independent Advisor
2025-02-25T23:31:43+00:00

Hi Reilly,

I'm sorry for the late reply, I'm in a different timezone but I'm back now.

I think you could try to install the Sysinternals Suite from Microsoft Store. This suite provides a program with GUI called "TcpView". This will show you all the current IPv4/6 and TCP/UDP connections established or listening in real time.

This way, you can share a screenshot and I can verify for you if there's any remote connection, and also verifying if the IP address belongs to Microsoft.

Let me know how it goes!

Was this answer helpful?

1 person found this answer helpful.
0 comments No comments

5 additional answers

Sort by: Most helpful
  1. Anonymous
    2025-02-25T22:51:16+00:00

    Hi Francisco,

    I used the the method and all I found was like over 100 from the source microsoft windows security auditing going back till feb 14 this year. A few sources are listed as eventlog. The task category varies from logon, special logon, process creation, secruity group mangement, user account mangement. There are some others about policy and audit changes too.

    Edited: I found, the filter and selected the remote access options nothing shows up fromm all time out of 15k events. I still dont understand why its showing in the cmd prompt. When I searched remote, the remoteapp and desktop connections one shows its no longer installed and the control panel option also shows no connections available.

    I found an option to turn off allowing remote assistance to pc the only thing I can think of is its beacuse its a prebuilt pc.

    Was this answer helpful?

    0 comments No comments
  2. Anonymous
    2025-02-25T18:26:11+00:00

    Hi Francisco,

    Thank you for the response, my only concern is that its a windows 11 not supporting remote desktop, I have not ever used it as far as I remember. The only thing is that it is a pre builf pc would that possibly answer it?

    I haven't noticed anything amiss or stolen accounts which puzzles me. Ill look with your example when am home. Should I look at doing a fresh install just to be safe?

    Thank you,

    Reilly

    Was this answer helpful?

    0 comments No comments