Should remote desktop services be running every day in Windows 8?

The logs of Terminal Services show Remote Desktop Services logging in and running every day on a new pc with Windows 8, although I never use remote access.  Is this normal, or not; and how can I stop it please?

Thanks, Robin.

 

Question Info


Last updated February 17, 2020 Views 1,597 Applies to:

 

Hi robin,

 

Thank you for choosing Windows 8 and giving us this opportunity to assist you.

 

I see that the Remote Desktop Service is logging in and running everyday and you want to know how to stop it.

 

Let us work together to resolve this issue.

 

However, we need more information on this issue. Please answer the following question.

 

1.     What do you exactly mean by “logs of Terminal Services”?

 

Here’s what you can try:

 

Follow the steps below to change the Startup Type of the Remote Desktop Service.

 

a.     On the desktop, press Windows key + R to open the Run Dialog.

b.     Type services.msc and press Enter.

c.      In the Services window, check the Status and Startup Type of Remote Desktop Services. Ideally, they should be ‘Started’ and ‘Manual’.

d.     If not, right-click on it and select Properties.

e.     Click on Start and change the Startup Type to Manual.

f.       Press Apply and OK.

 

It is advisable to not stop the service completely. If you wish to take remote access later, you will not be able to do so. Even if the service is started, it will not run till it is manually accessed.

 

Hope this is helpful.

 

If you have any further questions about Windows operating systems, write to us, anytime.

Did this solve your problem?

Sorry this didn't help.

Great! Thanks for marking this as the answer.

How satisfied are you with this reply?

Thanks for your feedback, it helps us improve the site.

How satisfied are you with this response?

Thanks for your feedback.

Hello Manasa,

It makes no difference what the Remote Desktop Service is set to: even when Disabled it still shows logons and logoffs, which coincide with my logons and logoffs on my pc.

This is shown in the Event Viewer under Applications and Services/Microsoft/Windows/Terminal Services/Local Session Manager/Operational.    Over 430 such events are shown since last August, four months before I bought the pc, an HP Pavilion P6-2310ea, and the earlier events are shown under HP's administration when they installed Windows 8, etc. 

I have even disabled the Plugin RDSAppX, but the logons and logoffs still occur.  Could this be a remote wireless connection inside the pc sending out information?  This security risk is what bothers me greatly.

No malware has been discovered by Comodo CIS, Malwarebytes, or Norton.

 

Any information would be appreciated, thank you, Robin.

 

Did this solve your problem?

Sorry this didn't help.

Great! Thanks for marking this as the answer.

How satisfied are you with this reply?

Thanks for your feedback, it helps us improve the site.

How satisfied are you with this response?

Thanks for your feedback.

Hi Robin,

 

Thanks for the update.

 

Please post your question in Microsoft TechNet Forums.

 

Refer to the following link:

 http://social.technet.microsoft.com/Forums/en-US/category/w8itpro

 

Please get back to us if you have any queries about Windows Operating Systems.

Did this solve your problem?

Sorry this didn't help.

Great! Thanks for marking this as the answer.

How satisfied are you with this reply?

Thanks for your feedback, it helps us improve the site.

How satisfied are you with this response?

Thanks for your feedback.

PC world assures me that Remote Desktop Services DOES run continually in all new pcs; and it certainly does in the replacement I have obtained, which is running Windows 8.  This is an unnecessary security risk, and which can lead to hackers obtaining control of pcs.  My new one also had the remote access box ticked; if I did not spot this, hackers could access my pc.  I am sure this is how unsuspecting people are having their bank accounts emptied.  All remote access should be DISABLED BY DEFAULT!  Microsoft makes it far too easy for hackers, with numerous unnecessary remote access vulnerabilities.  Why are they on continually?  I want them off, having been remotely hacked once.

Did this solve your problem?

Sorry this didn't help.

Great! Thanks for marking this as the answer.

How satisfied are you with this reply?

Thanks for your feedback, it helps us improve the site.

How satisfied are you with this response?

Thanks for your feedback.

Some functions are being called by the operating ststem from the remote desktop service, but as you noted from the log file it was for a local session. In a previous installation of My Windows 8 operating system I deleted the service and not only did I get errors in the same log in the event viewer, but my charms bar had trouble, and there were other issues as well. In Windows XP I do remember that even though I had disabled all remote desktop functions at least one remote desktop module file was loaded anyways, as part of the operating system's normal operation that didn't, to the best of my knowledge, cause any security risks. However, Windows XP didn't have a Terminal Services/Local Session Manager/Operational log to let everybody know! Sorry to hear you were hacked/ cracked.

Did this solve your problem?

Sorry this didn't help.

Great! Thanks for marking this as the answer.

How satisfied are you with this reply?

Thanks for your feedback, it helps us improve the site.

How satisfied are you with this response?

Thanks for your feedback.

Nobody said OP was hacked/ cracked did they?

I too want RD disabled, permanently.

Why does it need to run?

Remote Desktop Services: Session logoff succeeded:

User: MYCOMPTER\Me
Session ID: 1

Remote Desktop Services: Session logon succeeded:

User: MYCOMPTER\Me
Session ID: 1
Source Network Address: LOCAL

Remote Desktop Services: Shell start notification received:

User: MYCOMPTER\Me
Session ID: 1
Source Network Address: LOCAL

Did this solve your problem?

Sorry this didn't help.

Great! Thanks for marking this as the answer.

How satisfied are you with this reply?

Thanks for your feedback, it helps us improve the site.

How satisfied are you with this response?

Thanks for your feedback.

Cartel thankyou for your reply, robinbanks claimed to have been remotely hacked once in last reply dated Febuary 6, 2013. Newer versions of Windows have Terminal Services logs that show the previously unseen use of Remote Desktop functions, even if you have disabled Remote Desktop Services on your machine. This is due to the fact that in newer versions of Windows you are logged on as a Terminal User to help isolate your operating system from attack.

Did this solve your problem?

Sorry this didn't help.

Great! Thanks for marking this as the answer.

How satisfied are you with this reply?

Thanks for your feedback, it helps us improve the site.

How satisfied are you with this response?

Thanks for your feedback.

Hm.. my logs show repeated logins after I start the pc Sessions 1, 2 and 3. Shows numerous log ins and logout for different sessions? Plus entries that simply say $%s from $%S what does this mean since nothing shows up for it when I google this? This event id 59 which also nothing shows up for?

All scans come up clean and no information on these - doesn't feel quite right.

Did this solve your problem?

Sorry this didn't help.

Great! Thanks for marking this as the answer.

How satisfied are you with this reply?

Thanks for your feedback, it helps us improve the site.

How satisfied are you with this response?

Thanks for your feedback.