I actually have created me a keylogger that gets started for this kind of stuff, but if you need to do it without using a program then:      just edit the security policy to audit logon successes. Run SECPOL.MSC and select audit Policy under the Local Policies in the tree view on the left. Enable auditing for logon events. Now these events will show up in the event viewer and can be viewed remotely.     i might post a blog about my keylogger -which i actually call ActivityLogger- at a later stage. its a neat tool that helps me keep track of my active times during the day in from of the pc