Contacts

Disable all remote access connects. RemoteApp disabled is disabled. Data security First of all: how to delete remote access to the computer

From time to time, users who are trying to install terminal services or connecting a remote desktop In Windows 7, Windows Vista, Windows Server 2008 (R2), Windows Server 2003, Windows Server 2000, Windows Home Server or other RDP servers, an error message may appear. "The terminal server exceeded the maximum allowable number of connections".

An error occurs because there is a previous session or an existing RDP connection with a server or host that have not been disabled or discontinued. In order for the case to not even worse, if only the terminal server on the network was completely related to remote clients, and no additional slots were connected, the administrator can disable the remote server using the Terminal Services Manager to kill any RDP connection.

Instead of restarting or rebooting a host or server that the user wants to apply to the remote desktop in the remote control, here are alternative methods for bypassing a remote disconnection or termination Terminal Services. or remote desktop sessions and connections.

Method 1.

  1. Terminal Services Manager or Remote Desktop Services Manager can be used to disconnect and reset any Terminal Services or DESKTOP Remote Connection. Depending on the operating system, there are various ways to start and launch the Terminal Services Manager.

Windows XP and Windows Server 2003:

Press Start - Perform and enter % Systemroot% \\ System32 \\ tsadmin.exe

Windows Vista and Windows Server 2008:

Press Start and enter the type tsadmin.msc. In the Start Search box.

Windows 7 and Windows Server 2008 R2 or higher:

Press Start and enter the type REMOTE DESKTOP SERVICES MANAGER In the Start Search box.

Tip: On the client operating system or workstation, remote Server Admin Tools (RSAT) must be installed for a definition manager.

  1. After starting the Remote Desktop Services Manager or the Terminal Services Manager, right-click on the "Remote Desktop Services Manager" or "All of the Server List" and select Connect to computer .
  2. Then enter the name or IP address of the remote desktop service server you want to control.

Log in to the remote server, if required.

  1. The server checks will be listed on the left pane. Select the desired server that does not respond to a remote desktop session.
  2. On the right pane, go to the panel Session.
  3. Right-click on the session you want to disable and select Disable .

Method 2

  1. Run the window Command line.
  2. Complete authentication on a remote computer using the following command:

\\ C $

Replace server name or computer IP address with actual NetBIOS name or remote host IP address. For example, Net Use / User: Administrator \\\\ 188.8.8.8 \\ C $.

Enter password.

  1. Completing any existing remote desktop connection or terminal service connections using the following command:

rESET SESSION. / Server:

Replace server name or computer IP address with actual NetBIOS name or remote host IP address. For , enter the number gradually starting from 1, 2, 3 ... until the message appears " I I did not find the ID session "which were not returned as an error when executing the team. For example, "Reset session 1 / server: 188.8.8.8".

Tip: Notification will not be displayed when the session is successfully completed.

Method 3.

  1. Run the window Command lineAnd go through the remote host authentication using the following command:

net Use / User: Administrator \\\\ \\ C $

Replace the server name or IP address of the computer with the actual NetBIOS name or the IP address of the remote host. For example, Net Use / User: Administrator \\\\ 188.8.8.8 \\ C $.

Enter password.

In addition, from Windows Explorer, a network disk card for sharing folders on the target server, and log in according to the system.

  1. In the command prompt, enter the following command:

qWINSTA / SERVER:

Where the server name or IP address is the actual computer name or the IP address of the remote host. For example, Qwinsta /server:18.8.8.8.

  1. A list of active connections to the remote desktop or terminal service sessions will be displayed. Determine the "dependent" links and its ID.
  2. To reset and disconnect connections to a remote desktop or sessions, run the following command:

rwinsta. / Server:

Replace With the session identifier that is identified with the "qwinsta" command, and the server name or IP address on the actual name of the computer or the IP address of the remote host. For example, Rwinsta 1 /server:188.8.8.8.

Note: QWINSTA is a query of the window and Rwinsta station resets the Window stations.

After the Remote Desktop or Terminal Services Connects the session and disconnect, the slot will be released and the remote user can remotely log in again.

Quite unpleasant when someone gets unauthorized access to your computer. If you think the computer is hacked, disconnect it from the Internet. Then find the vulnerabilities that the cracker used to penetrate the system, and eliminate them. After that, take measures to avoid similar invasions in the future.

Steps

Part 1

Blocking unauthorized access

    Keep in mind that the computer can automatically turn on to install updates. Most of the latest versions of operating systems are updated automatically; As a rule, it happens at night when no one uses the computer. If the computer has turned on without your knowledge (that is, when you do not use it), most likely, it came out of sleep mode to install updates.

    • The attacker can get remote access to the computer, but it is unlikely. But you can take some measures to prevent the intrusion attempt.
  1. Look for obvious signs of remote access. If the cursor moves, the programs start and the files are deleted without your participation, someone got access to the computer. In this case, turn off the computer and disconnect the Ethernet cable.

    • If you find unfamiliar programs or the speed of connecting to the Internet fell, this does not mean that the computer is hacked.
    • Many programs that are updated automatically, in the update process, open pop-ups.
  2. Disconnect your computer from the Internet. Do it if you think that the computer is hacked. Disconnect the computer not only from the Internet, but also from the local network to prevent unauthorized access to other computers.

    • Turn off the wireless router and disconnect an Ethernet cable from the computer.
  3. Run the task manager or system monitoring. Using these utilities, you can define active processes.

    • In Windows, press Ctrl + ⇧ SHIFT + ESC.
    • In Mac OS, open the "Applications" folders - "Utilities" and click "System Monitoring".
  4. In the list of running programs, find programs for remote access. Also on this list, look for any unfamiliar or suspicious programs. The following programs are popular programs for remote access, which are installed without the user's knowledge.

    • VNC, REALVNC, TIGHTVNC, ULTRAVNC, LOGMEIN, GOTOMYPC, AND TEAMVIEWER
    • We also look for unfamiliar or suspicious programs. If you do not know the purpose of this or that active process, find information about it on the Internet.
  5. Pay attention to the abnormally high processor load. It is displayed in the Task Manager or in the system monitoring. The high loading of the processor is a normal phenomenon and does not testify to hacking a computer, but if it is observed when no one uses the computer, most likely many processes work in the background, which is very suspicious. Keep in mind that the high workload of the processor takes place during the background update system or download large files (which you forgot).

    Scan the system with an antivirus program. Be sure to install the antivirus or do not turn off the Windows Defender. Open the antivirus program and run the operating system scanning. For a complete scan will leave for about an hour.

    • If there is no antivirus on the computer, download it on another computer and copy to your computer using a USB drive. Install the antivirus and scan the system.
  6. Remove the files found by antivirus. If the antivirus detected malicious programs, delete them or send them to Quarantine (it depends on the antivirus); In this case, the programs found will no longer harm the computer.

    Download and install Malwarebytes Anti-Malware. This is a program that detects and neutralizes malicious programs that are not found by antivirus. Malwarebytes Anti-Malware can be downloaded for free download on MalwareBytes.org.

    • Since the computer is disabled from the Internet, download Malwarebytes anti-malware on another computer and copy to your computer using a USB drive.
  7. Schedule the Anti-Malware system. At full scan will go about 30 minutes. Perhaps Anti-Malware will detect a cracker program that controls the computer.

    Detected malicious programs Send to Quarantine. In this case, the programs found will no longer harm the computer.

    Download and run MalwareBytes Anti-Rootkit Beta. This program can be downloaded for free on MalwareBytes.org/antirotkit/. Anti-RootKit Beta detects and removes rootkits, which are malicious programs that allow an attacker to gain themselves in the system and hide the traces of penetration. At full scanning system will leave for a while.

    Post for the behavior of the computer after removing malicious programs. Even if the Antivirus and / or Anti-Malware program found and removed the malware, follow the behavior of the computer to determine the presence of hidden malware.

    Change all passwords. If the computer is hacked, most likely, the attacker received your passwords using a keylogger. In this case, change passwords to various accounts. Do not use the same password to multiple accounts.

    Exit all accounts. Make it after changing passwords. Exit accounts on all devices you use these accounts. In this case, the cracker will not be able to use old passwords.

  8. Reinstall the operating system if you cannot block unauthorized access to the computer. This is the only reliable way to prevent the invasion and get rid of all malicious files. Before reinstalling the system, create a backup copy of important data, since in the process of reinstalling the system all information will be removed.

    • By creating a backup copy of the data, scan each file, because there is a risk that old files will result in infection of the reheattered system.
    • Read for more information on how to reinstall Windows or Mac OS.

    Part 2

    Prevent unauthorized access
    1. Configure the automatic update of the antivirus program. Modern antivirus detects malicious programs before they fall onto the computer. Windows is preceded by a Windows Defender, which is a good antivirus working and updated in the background. You can also download an excellent and free antivirus, such as BitDefender, Avast! or AVG. Remember that only one antivirus program can be installed on the computer.

      • Read for more information on how to enable Windows Defender.
      • Read

In Windows 7 and previous versions of the operating system there is a built-in program "Remote Assistant". It allows you to manage the user's computer who needs help from another computer using a local network or connection via the Internet.

Assistant Activation and Deactivation

The wizard can manage the computer to be fixed, right from his computer. When connecting via the "Remote Assistant", an image from a computer of another user appears on the wizard screen, and all the actions made by the wizard are transmitted to the computer of this user and change its parameters.

There are three ways to ensure a secure connection:

  • for computers connected by the local network, you can transfer the invitation file that the user needs a help in need and transfers to the wizard;
  • the same security file can be sent by email if the connection will be made via the Internet;
  • if the IPv6 protocol is configured, you can use a direct connection through the Easy Connect button.

When connecting, first turns on the mode that allows the wizard to observe the actions performed on another user's computer, but it cannot affect what is happening. To go to control, you will need additional resolution.

To start using "Remote Assistant", you must perform the following steps:

Also in Windows 7 is the ability to enable a voice connection that allows you to communicate the wizard and the user during a session without third-party programs.

Video: Setting a remote assistant

Computer connection

After the computer has been configured, perform the following actions on it:

  1. Run the "Remote Assistant" from the "Maintenance" folder in the Start menu.
    Open the "remote assistant" through the "Start" menu
  2. Specify that this computer needs help.
    Select the mode "Invite someone you trust to assist"
  3. Select one of the ways to invite the wizard. For example, through the file.
    Choose how to invite masters
  4. Save the file provided.
    Save the file to the folder from which it will take it most convenient.
  5. Send the resulting file by any convenient way to the computer to the master, and a clock with a password will appear on the configurable computer, which will be needed to be connected.
    It will be best to write a password for connecting
  6. Now go to the Master's Computer. You must already have an invitation file, open it.
    Open the invitation on the Master's computer
  7. Enter the password received earlier on the user's computer.
    We enter the wizard on the computer previously received password
  8. Return to the user's computer again and confirm that you allow the Master Connection.
    I confirm by pressing the "Yes" button that the connection must be installed
  9. The connection is established, but the master can only observe. To start running a user's computer, it must click on the "Take Management" button.
    Click on the button "Take control" to start running a computer of another user
  10. After that, the user must confirm once again that he trusts the master.
    We specify that the wizard can manage the computer
  11. Cut the connection using the "Stop remote control" button on one of the computers. To set a voice connection, click on the "Conversation" button.
    Use the "Stop remote control" button to stop the session

Video: Connect to a remote desktop Windows

Install connection without invitation

There are cases when sending a request from a computer computer to a computer is inconvenient or impossible. Therefore, there is a method that changes the parameters so that the request will be able to send the master itself, that is, it will not be needed for this invitation file.

Mandatory condition for such a connection - the wizard must be authorized in the account with the name and password, the same with the account in which the user who is authorized to be assisted. The master account must be in the Administrators group, and the user account is to the group of remote assistants, which is created by the system automatically after entering the help offer mode.

  1. On the Master's computer, run the command line with administrator rights. To do this, go to the Start menu and locate the command line through the search.
    Open the command line on behalf of the administrator from the Start menu
  2. Use the MMC command in it to open the console.
    We prescribe in the MMC command prompt, press ENTER
  3. Expand the File menu, select "Add or Remove Equip" item. In the unfolded window, click on the Add button and add the Group Policy object editor. Save all the changed settings and return to the console.
    Add a group policy editor to the control console can be using the "Add" button
  4. Open the local computer policy, and in it "System Configuration" - "Administrative Templates" - "System" - "Remote Assistants". In the final folder, expand the "Request Aid Request" file.
    Open the "Request Aid Request" file
  5. Activate the function, noting "Enable" in the window that opens.
    Turn on the "Request Aid Request" function, noting "Enable"
  6. Return to the folder and open the "Offer Remote Help" feature. Also activate it, and specify the parameters that the helpers can manage this computer. Click on the "Show" button.
    Turn on the "Offer Help" function and indicate that assistants can manage this computer.
  7. Push the name and password to the wizard account. Save all changes made.
    Specify the wizard that will have access to the user's computer
  8. Go to the Master's computer and start the connection mode in it using the C: \\ Windows \\ System32 \\ MSRA.EXE / OFFERRA command, made on behalf of the administrator.
    We execute the C: \\ Windows \\ System32 \\ MSRA.EXE / OFFERRA command
  9. Enter the IP of the computer to which you want to connect. It can either be found on the Internet by typing the corresponding request, or through the "Start" - "Control Panel" - "Network and Internet" - "Network Management Center" - "View network status and tasks" - under the inscription "Network with Access Type: Internet »Click the link with the connection type -" Details "- in the" IPv4 address "line and will be the desired IP.
    Indicate IP to which you need to connect
  10. All subsequent actions coincide with those described above with normal connection: the user must issue a permission to the connection, and then - to control. The communication break is carried out by the standard method, through the "Stop remote control" button.
    We start working with "remote assistant"

Video: "Remote Assistant" without an invitation outside the domain on Windows 7

Connection without permissions

Sometimes the Master must be connected to the user's computer during its absence. But by default, to start watching another computer and start controlling them, you need a user permission. You can bypass these security steps by changing the assistant code:

Ready, now the wizard can connect to the user without confirmation from the user. Files that changed above will eventually look like this:

  • fUNCTION LOADVARIABLES ()
    {
    ;
    try.
    {
    if (parant.gisura)
    {
    idnormal.classname \u003d "SYS-FONT-BODY SYS-COLOR-BODY DISPLAYNONE";
    idunsolicited.classname \u003d "SYS-FONT-BODY SYS-COLOR-BODY DISPLAY";
    if (Parent.ghelperName)
    {
    idunsolichelper.innertext \u003d parent.ghelpername;
    idunsolichelper1.innertext \u003d parent.ghelpername;
    }
    }
    eLSE.
    {
    if (Parent.ghelperName)
    {
    idhelpername.innertext \u003d parent.ghelpername;
    }
    }
    }
    catch (Error)
    {
    parent.fatalerror (parent.l_rcctl_text, error);
    }
    btnaccept.disabled \u003d false;
    btndecline.disabled \u003d false;
    btndecline.focus ();
    Doaccept ();
    ;
    }
    fUNCTION DOACCEPT ()
  • fUNCTION INITITEMSG ()
    {
    var vargs \u003d window.dialogarguments;
    try.
    {
    idexpert1.innertext \u003d vargs;
    idexpert2.innertext \u003d vargs;
    idexpert3.innertext \u003d vargs;
    }
    catch (Error)
    {
    idbody.style.visibility \u003d "Hidden";
    alert (L_ERRACESSDENIED_TEXT);
    return;
    }
    onClickHandler (0);
    return;
    }
    function OnClickHandler (ID)

What if the assistant does not work

There are instructions for problems with connecting or connected.

Check access

If the assistant is not found in the system or inactive, then this means that it can be blocked. To ensure this, follow these steps:


Configure firewall

In Windows 7, the built-in firewall is configured automatically, but still problems may arise due to it. To avoid, it is worth, first, turn off third-party antiviruses, secondly, perform the following steps:

  1. You must turn off the Firewall (or allow DCOM access to exceptions) on the computer.
  2. In XP SP2 systems, it is necessary to change security settings (this can be done using group policy). At the Computer Configuration / Windows Settings / Security Settings / Local Policies / Security Options / SETTINS / Security Options / Loca
    • for DCOM: Machine Access Restrictions in Security Descriptor Definition Language (SDDL) Syntax issues Anonymous Logon and Everyone Groups Allow Local and Allow Remote Access;
    • for DCOM: Machine Launch Restrictions in SDDL Syntax Issue the Administrators group of Allow Local Launch, Allow Remote Launch, Allow Local Activation, Allow Remote Activation, and the Everyone - Allow Local Launch, ALLOW Local Activation group.

You can control a computer of another user from your computer by performing a connection through a built-in remote assistant. For standard connection, the invitation file and the Agreement on the user in need of help will be required. But these prohibitions can be bypassed by changing the assistant code and group policy parameters.

Hey! We continue to disassemble the Windows 10 operating system! Today you will learn how to configure remote access on Windows 10 Computer. You can enable or disable remote control of the computer. You can limit the time of using a remote assistant. To configure remote access, at the bottom of the screen on the left, open the "Start" menu. In the window that opens, in the list of all applications, at the bottom of the list, open the Oboy Windows tab. In the list that opens, click on the Control Panel tab.

Next, you will open the "System Properties" window. Here you can enable or disable the connection of a remote assistant to your computer. Click on the button - additionally to view additional parameters.

Allow or disable remote control by your computer.

You can set a deadline for which the invitation may remain open.

You can set the creation of invitations only for computers with Windows Vista or newer.

After changing the parameters, click on the OK button.

How to run a remote assistant instruction Read here !!!

Have questions? Write a comment! Good luck!

Configuring Windows 10 Remote Access Updated: February 11, 2017 by author: Ilya Zhuravlev

info-effect.ru.

How to get remote access to the desktop in Windows 10 through the Appendix "Fast Help"

Microsoft improves Windows 10 operating system, not only eliminating various problems, but also adding new features. With the "anniversary" (Anniversary) update of the operating system (version above 1607), a new application was added - "Fast Help". It allows you to easily and quickly provide a remote access to your computer if it also uses Windows 10 required version.

Why do I need a utility "Fast Help" on Windows 10

The "Fast Help" program is a built-in analogue of many other applications that offer approximately similar functionality, namely, providing Internet access to a computer for another user. The most famous program with similar functions is TeamViewer. However, it is not pre-installed in the operating system, and it is required to configure it, whereas for the work of "quick care" is a fairly simple connection to the Internet.

Utility "Fast Help" can be useful to the user of the computer:

  • When contacting the support service of the operating system. Microsoft employees, if the user is poorly focused on Windows 10, will be able to remotely connect to its computer and make the necessary actions to eliminate errors, diagnostics or PC settings;
  • To transfer to another user management computer. For example, if an employee stayed at home, but it requires working materials, another person can enable its computer and activate the remote access mode through the Fast Help application, which allows not only to view the files, but also transmit them to both sides.

You can come up with dozens of situations when you need to receive remote access to the computer, and the "Fast Help" application allows you to do a few clicks.

How to get remote access to a computer through "Fast Help"

Since this utility is built into the Windows 10 operating system, you will not need to download anything to start working with it. It's just enough to run it by pressing "Starting" - "Standard" - "Windows" - "Fast Help" or starting to enter "Quick Assist" in the search for a nonlineated version of the system).

When the program is running, you will need to do the following:


How to use the "Fast Help" program in Windows 10

When a remote user will allow access to its computer, another user will open the "work area". In the middle of the window "Fast Help" utility will be shown the image that is now displayed on a remote computer. From above, a number of instruments and service information will appear, among which:


In addition to the designated and obvious features, it is also worth noting the possibility of transferring files. The user who received remote access can copy the file on its computer, then switch to the remote PC screen and insert the previously copied file to the required directory.

It is important to note that at any time a user who provides remote access to its computer can close the "Fast Help" application to disable the broadcast.

OKEYGEEK.RU.

Function Fast Help for Remote Access to Computer in Windows 10

Windows 10 allows you to remotely manage other computers with the very version of the operating system. This feature is built into the system and it is easier to use it than in previous versions of Windows. Without the need to install additional programs, we can manage a stranger computer or ask someone to remotely restore us the operating system via the Internet.

Built-in remote control feature in Windows 10

Remote control by other computers is useful in many situations. For example, if you have problems with the operating system and you cannot solve them yourself, you can contact a friend or friend, which is also not necessary to come to your home. It is enough to open it remote access to your desktop so that it can connect and manage them via the Internet.

Usually for such purposes use the TeamViewer program, which allows you to control the remote PC. But users who are installed Windows 10 with an update Anniversary Update, get remote access will be much easier and without installing additional programs. The remote desktop function is built into the OS, and it is much easier to use it in Windows 10 than once in the form of the so-called "fast help".

Setting up remote access in Windows 10

But before you start paying attention to the following. This feature requires both users to update Anniversary Update.

Connection in Windows 10 runs a little different than in the case of TeamViewer type programs. The TeamViewer applies the principle according to which the user, which provides access to its computer, must be registered and obtaining an identifier and password to it. Then he sends the received data to a friend who wants to provide remote access.

In Windows 10, everything is on the turn - a user who wants to connect to a remote computer performs the first step by registering as a person providing assistance. Gets such a way a unique 6-digit code that is valid for 10 minutes. Then the one who needs remote support introduces the code in itself, thereby initiating the connection between the two computers. Let's consider the connection process step by step.

Step 1 - User actions that wants to manage a remote computer

The user who needs access to the remote PC must go to the Start menu - standard and select the "Fast Help" option. After enabling this feature, you need to select the "Assist" option and log in to the Microsoft account. After login, the 6-digit code will appear.

The code is valid for 10 minutes and performs the role of the user ID needed to connect to another computer. The code needs to be sent to the one who wants to provide remote access to its device.

Step 2 - User Actions, which provides access to your PC

The user who wants to provide access to its computer needs to be obtained and copying the 6-digit code. Then go to the Start menu - Standard and select the "Fast Help" option. After enabling this option, you need to select "Get Help".

A window will be highlighted where you need to enter the user ID to whom we want to provide remote access. After entering the 6-digit code, the connection process will begin. When a message appears about whether we want to allow other users to connect to your computer, select "Allow".

Providing assistance in Windows 10

If there are no 10 minutes and the code is still relevant, the connection between computers will be installed and the user from the first step will see the person's desktop from the second step on its screen. Now you can control the mouse and keyboard and perform any operations on the remote PC.

As noted above, this feature is intended mainly to obtain / providing quick care. If your friend has problems, for example, with viruses, the work of Windows or it does not work something, instead of explaining it in Skype or another messenger, it is worth just asking him to provide remote access and perform the appropriate actions for it.

The easiest way to connect to a remote computer

If you or your familiar other version of Windows or have problems installing an Anniversary Update update, you will have to consider other connection options.

There are many applications and programs for managing a remote desktop. Some require accurate settings and are not very clear for novice users. Nevertheless, there is one program that is very simple and amazingly effective.

It will be about AnyDesk, which is very popular and highlights the environment of such programs. First of all, it is very easy to use, and the connection between computers is reminded by calling the interlocutor on Skype. The program does not require any settings (just type the unique user number, which you want to connect to the computer). In addition, the program is portable, which means that it can be launched on any PC without installation, for example, from a flash drive.

After starting AnyDesk, the main window will open, divided into two parts - one concerns your computer, the second serves to intercept control over another PC.

In the section "This Workstation" is your address AnyDesk. It allows other users to connect to your computer. That is, that someone can get remote access to your PC, pass this address to him. This address may also be required if you need to connect to your home computer, for example, from work.

The "Other Workplace" section is designed to establish a connection with a remote PC. To set the connection, you can simply enter the address (identifier) \u200b\u200bof the remote computer and click on the "Connect" button. A window with information will appear on a remote PC that someone tries to establish a connection with it. The user must enable the connection by pressing the "Accept" button.

A remote desktop will appear in the AnyDesk window. Now you can run programs on it, view files and perform any operations.

Connect to a home computer

To remote access to your home PC, you need to enable the function of uncontrolled access. This feature allows you to make a connection without confirming the receiving party.

On the home computer, go to the program settings, and then on the Safety tab. In the "Access During No" section, mark the "Allow uncontrollable access" item and enter the Reliable Password field.

Now, when you try to connect with a home PC desktop from your workplace, a request to enter a password will appear on the screen. After entering it, you will receive full access over your home PC.

Instcomputer.ru.

How to enable remote access to administrative balls in Windows 10

Faced that it is not possible to remotely connect to default administrative balls (which with a dollar) on a computer with Windows 10 under the user belonging to the group of local administrators. Moreover, under the integrated local administrator account (it is disabled by default), such access works.

A little more about what the problem looks like. I am trying with a remote computer to contact the built-in administrative resources of the Windows 10 computer, consisting in the working group (with a firewall disconnected) in this way:

  • \\\\ win10_pc \\ c $
  • \\\\ win10_pc \\ d $
  • \\\\ win10_pc \\ ipc $
  • \\\\ win10_pc \\ admin $

In the authorization window, I enter the account name and password consisting in the Windows 10 local administrators group, to which Access IS Denied) appears. At the same time, access to shared network directories and printers on Windows 10 is working normally. Access under the built-in Administrator account to administrative resources also works. If this computer is included in the Active Directory domain, then under domain accounts with administrator rights access to admin balls is also not blocked.

The case in another aspect of the security policy that appears in the UAC is the so-called Remote UAC (monitoring accounts for remote connections), which filters the tokens of access to local entries and Microsoft accounts, blocking remote administrative access to such accounts. When accessing a domain account, such a restriction is not imposed.

Disable Remote UAC by creating in the system registry LocalaccountTokenFilterpolicy parameter

Council. This operation slightly reduces the system security level.

After download, try remotely open the C $ Administrative Catalog directory on Windows 10 Computer. Log in to a record included in the Local Administrators group. A conductor window must open with the contents of the C: \\ disk.

So, we figured out using the LocalacCountTokenFilterPolicy parameter to allow remote access to hidden admin resources for all local Windows computer administrators. This instruction also applies to Windows 8.x, 7 and Vista.

winitPro.ru.

How to configure a remote desktop Windows 10

Not every user knows how to connect a remote desktop correctly and start working with it. Configuring such a useful tool significantly facilitates work at a computer. There is a possibility not to be at the place of placement of the machine, but to manage all important functions at a distance. This is especially true in large organizations and complex home network structures.

Therefore, consider the question more carefully in the article below. Of course, you can use special programs that implement a remote desktop, but still you need to know about standard tools 10. After all, the additional software is an excess load on the resources of the axis, and the use of native utilities is already optimized. Setting up the desktop does not differ in great complexity and is very similar to the desktop organization in Windows 8. This is natural, because the 10 generation draws a lot of positive moments from previous versions.

Preparation

To implement this functionality, it is important to pre-prepare. It is important to configure computers for successful interaction. Connection within the desktop is carried out via the RDP protocol through one local network. At home is a single router for all devices. It is also possible to implement a single table through the global network. For direct connection you only need to find out the address of the computer (its IP). It is known that in conditions of the house, such an address is constantly amended, so it's worth it for a start to force to be static:

  • Go to the control panel.
  • Open the Network Management Center and Common Access Center.
  • Right-click on the LAN connection and select information in the menu context.
  • Here we view the data on the IP address.
  • We leave the window and open properties.

Look more: setting up in Windows 10 tiles

  • A list of components will appear on which the selected connection works. Select the Internet protocol version 4.
  • Click on the properties button.
  • Click OK, then again OK.

All, the static address is assigned to the computer. If this is not done, then every time you reset the IP will break.

You can try to do it through the router. Almost all models allow you to fix the equipment specific address. Naturally, this topic is only for those persons who are able to cope with similar equipment. You can search articles in a global network that will answer the question of how IP fixation is implemented in a specific router.

Resolution

By itself, the remote desktop on the Windows 10 operating system does not start, it still needs to be allowed to connect via RDP protocol:

  • We go to the control panel and click on the system.
  • On the left there will be a list in which you want to select a remote access setting.

The options window will open, in which you should click on Allow remote connections to this computer and allow you to connect a remote assistant to this computer. It is better to specifically prescribe those users who will connect to the machine. It is also possible to specifically create a user for which the desktop setup will be relevant.

Connection

Now you do not need to install additional software to use a remote desktop. It is enough to go to the search for Windows 10 or any other operating system to find the control - remote desktop. After that, the connection utility is launched.

tips → Protect and Computer Optimization → Disable potentially dangerous Windows services

Disable potentially dangerous Windows services

One more step towards ensuring the security of your computer is to disable potentially dangerous Windows services. In addition, disconnecting some system services that run by default, but at the same time often unused at home, will speed up the operation of your computer.

Find these services as follows:

  • StartPerform → Write the following on the command line: services.msc. → Press OK. or
  • Control PanelToggle to classicAdministrationServices.

Disable services (of course, not all, but only unused) in the window that appears Services (Local) Just: Click on the desired service, the offer will appear on the right. stop or restart service. Read the proposed information and click "Disable".

I remind once again: Disable these services should be necessary if they do not need. That is, if you are the owner of a home computer, not connected by a local network with other computers, which is in most cases.

What Windows services should be disabled?

Here windows List (Services)considered potentially dangerous, that is, making your computer vulnerable to external invasions:

  1. Remote registry (Remoteregistry) - allows remote users to change the registry settings on your computer; If you stop this service, the registry can only be changed by local users running on the computer.
  2. Terminal services (TermService) - In general, this service is intended for a remote connection to your machine over the network with the ability to control it. It provides the ability to interactively connect to a computer to several users and displays the desktop and applications on remote computers. It is the basis for a remote desktop, remote administration, remote assistant and terminal services.
  3. Service Messages (Messenger) - send administrative alerts to selected users and computers. In the absence of a network (and the administrator, respectively) is absolutely useless. It is also desirable to disable in order to prohibit net Send. Messages to hide your computer from automated spam mailings. No relation to the program Windows / MSN Messenger This service has no.
  4. SSDP detection service (SSDPSRV) - Includes the detection of UPNP devices in the home network. Upnp., or Universal Plug and Play - This is a universal automatic configuration and connection of network devices to each other, as a result of which the network (for example, home) can be an affordable more people.
  5. Hanging (Alerter) - send administrative alerts to selected users and computers. At home, the service is not needed.
  6. Task Scheduler (SHEDULE) - allows you to configure the schedule for automatic task execution on the computer. Automatically starts various applications, programs, scripts, the backup function to the time scheduled time (by default, these tasks can be found here: Start → Programs → Standard → Service → Assigned tasks). If you do not use this feature, disable this service. In addition, the vulnerability of this service is used by some viruses for autoloading.
    However, keep in mind that some Atenificities, for example Symantec. or McAfeeUse this service to update at certain times and scheduled scanning system. So in this case, turn off the task scheduler is not worth it.
  7. NetMeeting Remote Desktop Sharing (MNMSRVC) - Allows proven users to access the Windows desktop through corporate intranet using NetMeeting.
  8. Reference Session Manager for Remote Desktop Remote Desktop Help Session Manager) - manages capabilities Remote assistant.
  9. Telnet (Telnet) - allows the remote user to log in and run programs, supports various TCP / IP Telnet clients, including computers with UNIX and Windows operating systems. Provides the ability to connect and remotely work in the TELNET system (Teletype Network) using the command interpreter. This protocol does not use encryption and is therefore very vulnerable to attacks when applying it on the network. If this service is stopped, the remote user will not be able to run programs.

Other services that may not be used on your computer, but at the same time the memory is loaded, pretty braking the download and operation of the system:

Automatic update - Includes download and install Windows Updates). If you do not use this service, disconnect.

Secondary login - Allows you to run processes on behalf of another user. If your account is only your account (not counting the administrator entry), you can also turn off.

Seat queue manager (Print Spooler) - is responsible for processing, planning and distribution of documents intended for printing. If you do not have a printer, disconnect.

Help and support - If you do not use the Windows Reference Menu, disconnect.

Observer of computers - Serves a list of computers on the network and gives it programs on request. If you do not have a local network, disconnect this service.

Uninterruptible power system - If you do not have a uninterruptible power source, you can disable this service.

Before turning off this or that service, see which services can depend on it.
To view dependencies, you need to open the properties of the service, switch to the last tab - "dependencies" ("Dependencies"). The top list will show the service, on which the functioning selected depends on the operation. The lower list, on the contrary, contains services that are depending on this.
If any dependencies are missing at all, then the service can be turned off without fears.

The instruction is suitable for Windows XP, but in other Windows configurations actions are similar, although the service names may differ slightly.

programmistan.narod.ru.

Disable service remote registry in Windows XP

Service Remote Registry in Windows XP allows remote users to change the computer parameters. The following describes how to disable the remote registry service and the consequences of this.

If you worked for a long time with Windows XP, or any other version of Windows released over the past 10 years, then, undoubtedly, you are familiar with the Windows registry and you know that the registry is the heart of Windows. Almost any aspects of Windows work can be monitored through the registry. If you know what you are doing, then you can force Windows to make amazing things.

The fact is that the registry can be changed not only with positive intentions. Windows XP has a service that allows you to remotely change the Windows registry, without the PC user's knowledge, which makes changes. What do you say if you know that this service is enabled by default? If you do not want anyone to have access to the registry of your Windows OS, then the deleted registry service should be disabled.

Note: Before hurrying to turn off the remote registry service, you need to know what consequences will lead.

Since there are also the advantages and disabilities of disconnecting this service, you will ultimately decide whether you yourself do it or not. Decide that you need at work or at home. To help you with this, we will explain how the remote registry works, how to enable or disable this service, and which consequences will disable the service.

Work with remote registry

As mentioned earlier, the remote registry allows you to make a registry change on a remote machine. A small detail that can calm down a little - to remotely change the Windows XP registry anyone can not. To have the right to change the registry, the user must be a member of the administrators group on the remote machine.

To access the remote machine registry, you must first open the registry editor on your PC. After opening the registry editor, select File - Connect the network registry. After that, the Choice dialog box appears: Computer. Enter the computer name to which you want to connect and click OK. After that, the registry of the remote computer will open in the registry editor.

You must be at least careful, during the changes in the registry of the remote machine. Please note that during your registry changes, the first line of the registry editor is called my computer, below are HKEY_LOCAL_MACHINE, HKEY_CURRENT_USER, etc. When opening a remote computer registry, the recording of my computer remains, and its contents refers to your local computer. The registry of the remote computer is below and is called the remote PC. It is important not to confuse and correct the desired registry.

Enable / Disable Service Remote Registry

Now having an idea of \u200b\u200bworking with a remote registry, let's try to disable this service. Turning off the remote registry must be done directly on the computer where you want to disable remote access.

If you later need to re-use this service, then open the service management manager, right-click on the remote registry line, then select the Properties command. In the Launch Type dropping menu, set the auto value, click Apply, then click Start and OK. Service Remote Registry works again.

Consequences of shutdown

At the beginning of the article mentioned the consequences of a disconnection of the service. In 99% of all cases, disabling the remote registry will not cause any problems. Dependent applications from this service are very small.

If you worked for a long time with Windows XP., or any other version of Windows released over the past 10 years, then, undoubtedly, you are familiar with the Windows registry and you know that the registry is the heart of Windows. Almost any aspects of Windows work can be monitored through the registry. If you know what you do, then you can force Windowsmake amazing things.

On the other hand, if you do not know what you do (or do it with malicious intent), then you can destroy Windows, incorrectly changing the registry. Almost every article dedicated to the Windows registry changes, you can find a note that it says that you can disrupt Windows and / or applications if you make incorrect changes, and that you need to make a full backup of the system before changing the registry.

Work with remote registry

As mentioned earlier, the remote registry allows you to make a registry change on a remote machine. A small detail that can calm down a little - to change the registry remotely Windows XP.anyone can not. To have the right to change the registry, the user must be a member of the administrators group on the remote machine.

To access the remote machine registry, you must first open the registry editor on your PC. After opening the registry editor, select File - Connect the network registry. After that, the Choice dialog box appears: Computer. Enter the computer name to which you want to connect and click OK. After that, the registry of the remote computer will open in the registry editor.

Enable / Disable Service Remote Registry

At the beginning, open the control panel, and select the Administration icon, then click on the service icon.

The service management manager that opens will show a list of all available services. Scroll through the list and find the Remote Registry Service. Right-click on the Row Remote Registry, then select the Properties command in the menu. In the window that appears, click the Stop button to stop the service. Now in the drop-down menu of the start type, set the value disabled. Click OK, now the remote registry service is disabled, and no one can remotely change the registry of your system.

Please note that the remote registry service depends on the service Remote Procedure Calling (RPC) and if it is not enabled, you will not be able to include a remote registry.

Consequences of shutdown

At the beginning of the article mentioned the consequences of a disconnection of the service. In 99% of all cases, disconnecting a remote registry will not cause any problems. Dependent applications from this service are very small.

It should also be remembered that after disconnecting the remote registry service, you will lose the possibility of remote control over the machine. Sometimes you have to configure computers that are on very remote distances (another city, another country). It is necessary to realize what you will not be able to access such a computer, if, of course, do not personally go there where it is located.

www.interface.ru.

Remote Windows registry.

Windows registry Often it becomes the cause of improper work of individual programs or the entire operating system as a whole. Accordingly, to restore the computer or laptop, it is often "in manual mode" to edit the registry: delete, change or add records. If a specialist serving a computer has direct physical access to the latter, then the question considered in the article should not arise, however ... it often happens that the service is remotely and need to get remote access to the registry.

Make changes to remote Windows registry It is possible that the computer in which the adjustment needs to be added allows you to work with your system registry over the network. For this should be launched the corresponding windows service - It is already built into the developed by the developer (Microsoft). In the "Footers" of the "XP" version, it is activated by default, and in newer - it is necessary to manually activate it. Called the service is simple - " Remote Registry" You can enable it through the context menu of the "My Computer" label - "Management" - "Services and Applications" - "Services". Or launch directly from the command line: " net Start Remoteregistry." Of course, to activate remote access, you must have a local administrator rights.

Connect a remote Windows registry You can through the built-in editor. To do this, run the registry editor ("REGEDIT" from the command line) and the File menu, select "Connect the Network Registry". In the window that appears, specify the name or address of the computer to which you want to connect (and data for authorization on the remote system). After that, on the left side of the editor window under the nodes of your local registry, 2 branches will appear network registry With a remote machine: "HKEY_LOCAL_MACHINE" and "HKEY_USERS". In fact, you get access to the entire registry, just the rest of the branches are links to the subsections in the specified branches.

We recently considered the situation when only a black screen and cursor was visible when Windows startup. Solving the problem in the instructions proposed exactly checking records in the system register of the operating system. Following the above description, you can restore Windows Without direct access to the problematic computer. However, it should be attentive and followed - in whose registry you make changes - in your or remote machine! In the screenshot (in the status bar) it can be seen that now active branch of remote registry From a computer with a network name "GL-ING".

How to disable remote access to the computer on Windows 7

Data security First of all: how to delete remote access to the computer

Users, thinking how to delete remote access to the computer to protect yourself from the outside attacks, install third-party programs, without even suspecting that the main share of all hacks occurs due to the standard Windows settings. The default operating system allows deleted connections to a computer. Trying to facilitate the work of users, Windows developers included the ability to remotely configure and assist. Such assistance is only suitable for large corporations in which there is a system administrator who can eliminate problems in working with a computer in a second place. For home users, remote access can only facilitate the work of attackers, thirsting to hack someone else's system.

How to get into the remote access settings menu?

In just a few minutes, any user can independently delete remote access to the computer.




Did you like the article? Share it