Remote Desktop Shell Start- Local

Anonymous
2024-10-25T18:13:24+00:00

Why do I have an EVENT indicating Remote Desktop Shell was started on the LOCAL network address?

I am using Windows11 Home

I have uninstalled:

Remote Desktop and Quick Assist

I do EVERYTHING possible to ensure I do not have any remote activity on my computer.

This is NOT the only concern regarding Remote Activity on/ in my computer

Microsoft-Windows-TerminalServices-LocalSessionManager/Operational

TerminalServices-LocalSessionManager

Event ID: 22

Remote Desktop Services: Shell start notification received:

User: OCT***********\DFly

Session ID: 2

Source Network Address: LOCAL

*** Moved from Windows / Windows 11 / Security and privacy ***

Windows for business | Windows Client for IT Pros | User experience | Remote desktop services and terminal services

Locked Question. This question was migrated from the Microsoft Support Community. You can vote on whether it's helpful, but you can't add comments or replies or follow the question. To protect privacy, user profiles for migrated questions are anonymized.

0 comments No comments
{count} votes

3 answers

Sort by: Most helpful
  1. Anonymous
    2024-10-28T02:14:32+00:00

    Hello,

    Can you recognize the user account: OCT*********\DFly . If this is a legitimate user account on your computer, it could mean that the user (or a process running under that user's context) started a Remote Desktop session.

    By default, Windows 11 Home does not support incoming Remote Desktop connections. However, the event you are seeing (Event ID 22) with Source Network Address: LOCAL suggests that a Remote Desktop session was started locally on the machine itself, rather than from an external source.

    I hope this information helps.

    Best regards,

    Karlie Weng

    0 comments No comments
  2. Anonymous
    2024-11-06T22:35:35+00:00

    VERY HELPFUL!!

    THANK YOU!!!!!

    The User Account is mine

    Nothing should be creating a Remote Desktop Connection

    Where do I go from here??!!!

    0 comments No comments
  3. Anonymous
    2024-11-24T23:57:34+00:00

    Hi,

    When you monitor the timing of these remote connection events, have you noticed any patterns? Could it be that some software is triggering this activity? Have you conducted a full virus scan? Additionally, you might want to consider disabling the Remote Desktop connection on port 3389 through the firewall to prevent any incoming network traffic

    0 comments No comments