Simple (better) local check; Monitor windows event logs\ID's

Thanks, I will try it.