Documentation

Installation and usage

1. Installation

There are two separate packages; which one you download depends on how you plan to use it.

Note: the application's interface language is Turkish, and so is the bundled readme.

Full installation (service)

  1. Run the installer you downloaded. There is no ZIP to extract and no batch file to run — a standard setup wizard opens.
  2. Windows asks for administrator rights; this is required because a service is being installed.
  3. If SmartScreen warns you: More infoRun anyway (the application is not signed yet).
  4. The wizard offers two options: a desktop shortcut (recommended) and diagnostic mode (tick it if you plan to report a problem; detailed logs are kept).
  5. You can choose the folder the application is installed into. If a previous version exists in a different location, the installer offers to clean it up.
  6. When it finishes, the panel opens with your ID and password, and the release notes document opens automatically.

On Windows Defender the installer tries to add the antivirus exclusion itself. With Kaspersky or another antivirus you must add it manually — see the antivirus warning.

Portable mode (no installation)

  1. Extract the ZIP completely into a folder. The Dokumanlar folder inside must stay next to the application — it is what lets you open the documents from within the app.
  2. Run CSRemoteDesk.exe.
  3. When the application opens it shows an ID and a password; give both to the other side.
  4. If someone will connect to this machine by IP address, the app asks for firewall permission and adds the rules itself once you approve. (Connecting by ID works without it.)

In this mode the application only runs within the current Windows session. Unattended access and control on the lock screen and UAC prompts are not available.

Uninstalling

For the full installation: open Settings › Apps › Installed apps, select CSRemoteDesk and choose Uninstall — the "CSRemoteDesk Kaldır" shortcut in the Start menu does the same. The service is stopped and removed, and files, shortcuts and the firewall rules that were added are cleaned up.

Portable use has no uninstall step; deleting the folder is enough.

Documents

The user guide and release notes ship in both packages. The easiest way to reach them is from inside the app: the Settings menu has Kullanım Kılavuzunu Göster (show user guide) and Sürüm Notları Dökümanını Göster (show release notes), which open in your default PDF reader.

2. First connection

You must fill in your card details before your first connection. Connecting anywhere requires your name and email address; if you have not entered them, the app takes you to the "Kartvizitim ve Ayarlarım" (My Card and Settings) screen automatically when you try to connect. Fill them in, save, and you can connect. This is so the person you connect to knows who is reaching them.

Do not confuse this with "Hesabım" (My Account): card details stay on your own computer and require no sign-in. An account is a separate, optional thing — see the note below.

  1. CSRemoteDesk must be running on both computers.
  2. Get the ID and password from the machine you want to reach. The other side can copy both to the clipboard in one click using the buttons next to them.
  3. Enter the ID on your own computer, press Connect, then type the password.
  4. Once connected, the remote desktop window opens. You can use it windowed or full screen.

The session password is easy to read out over the phone. Passwords use only lowercase letters and digits, and characters that look alike (0/o, 1/l) are left out — so there is no "was that upper or lower case?" confusion. The security level is unchanged.

Once connected, a security code appears on screen; it is the same on both sides. Read it out over the phone to confirm by eye that you have reached the right person with no one in between.

If the connection fails the app does not stay silent: it shows which address could not be reached and lists the likely reasons. If the other side refused the connection, the reason for the refusal is shown too.

Add machines you connect to often to "My Connections"; you can group and name them, see at a glance which are online from the green dot, and connect in one click. The list is stored only on your own computer.

3. Unattended access

Unattended access means connecting with nobody at the other end — even when the machine is locked or no user is signed in. This requires the full installation (service mode).

  1. Run the installer on the remote machine to perform the full installation.
  2. Set a permanent access password in the application.
  3. Note the machine's ID and that password. The ID does not change when the computer restarts.

In service mode the connection survives users signing in and out, switching accounts and locking the machine; mouse and keyboard keep working on the lock screen and on UAC prompts.

4. Connection approval

When someone wants to connect to your computer, an approval window appears before your screen is shared. If you do not approve, no connection is made.

The feature is off by default. To turn it on, open Kartvizitim ve Ayarlarım (My Card and Settings) and tick the operation types you want to be asked about.

Separate setting per operation type

  • Bağlan — remote control
  • İzleme — view-only
  • Dosya Transferi — file transfer

For example, you can require approval for remote control while leaving view-only connections open.

What the approval window shows

The name of the person asking, their ID and the operation they want to perform — so you decide knowing exactly who you are letting in.

  • If you do not answer within 30 seconds, the request is refused. Nothing opens on its own while you are away from the computer.
  • The default button is "Reddet" (Reject) — you cannot approve by accident.
  • The person connecting does not stare at a blank screen; they see a "waiting for the other side's approval" notice.

Unattended access is kept separate

These settings do not affect unattended (saved-password) connections. Unattended access has its own approval settings: one for the public password, and one for each ID you add to the list. That way machines you deliberately made reachable "when nobody is there" do not sit waiting.

5. Privacy mode — sharing only selected applications

When you let someone connect for support, your entire screen does not have to go with it. You can share only the application you need help with and hide everything else. The choice is always made by the person sharing.

  1. Open the "Allowed Applications" area of your control panel.
  2. Select the application you want to share. You can pick several — for example an accounting program together with the calculator.
  3. The area always shows what is currently being shared. With nothing selected it reads "Entire desktop".

While privacy mode is on:

  • Anything outside the selected windows reaches the other side as black. If another window moves on top of a shared one, that area is blacked out too, so nothing leaks from behind.
  • File transfer, clipboard and text pasting are disabled. Restricting only the picture while leaving those paths open would have defeated the purpose.
  • The other side can only click and type inside the shared windows. Their cursor turns into a "blocked" symbol over disallowed areas.
  • A yellow border is drawn around the shared windows on your own screen. It is never transmitted — it is only so you can see what is being shared. By default it appears while someone is connected; you can choose to show it at all times.

Because the taskbar is blacked out as well, you cannot restore a shared application once it is minimised — use the "Allowed Application" button on the top panel instead; it lists the shared windows and brings the one you pick to the front.

6. Connection logs and password protection

Two separate features let you see who connected to your computer and what they did. Both are opened from the Settings menu.

Connection logs ("Bana Yapılan Bağlantı Logları")

Who connected to your computer, when, with what permissions and what they did — all on one screen.

  • Session details: the connecting person's ID, IP address, computer and user name, connection type (full control / view-only / file transfer), which password was used, whether the connection was encrypted, its duration, and whether it ended normally or dropped.
  • File operations: every file left with you or taken from you, with full source and destination folder paths. Remote deletions, renames and folder creations are logged too.
  • Rejected attempts: people who tried to connect with the wrong password also appear. This is where you answer "did someone try to get into my computer?"
  • Search and export: records can be filtered by period and type, searched across all fields, and exported as CSV for review in Excel.

Records cannot be deleted or edited from this screen. An audit record is only worth something if it cannot be changed after the fact.

Session list and session details

The log screen opens the session list first: date, identity, computer, start, end, duration and connection type. Double-click a row to see only that session; “Show All” returns you to the full list. A single connection easily produces ten log lines — this layout exists so you can answer “what did the person who connected last night do?” without searching.

End-of-session summary report

When someone who connected to you leaves, a short summary appears from the icon next to the clock: who connected, when it started and ended, how long it lasted, with what permission they entered, whether the connection was encrypted and whether it ended normally.

  • It also states what did not happen: “no file or clipboard activity”, “your entire screen was shared and control was granted”, or “privacy mode was on”. A trust report has to state both.
  • Show Details: opens the log screen filtered to that session only.
  • Silencing: for a colleague who connects every day you can turn the notification off per identity — the record is still kept. Re-enable them from the “Muted identities” button on the log screen.

How the records are protected

The entire value of an audit record lies in the fact that it cannot be altered afterwards. There are four layers:

  • Location and permissions: records are kept in a protected sub-folder of the Windows common data folder; nobody is granted delete permission — only reading and appending.
  • The file is locked while running: it is held open in a mode that forbids deletion; Windows will not allow an open file to be deleted.
  • Chained signature: every line carries a signature bound to the one before it. If a line is deleted or altered, or the end of the file is truncated, the chain breaks. The screen states three cases separately: “verified”, “could not be verified” and “MODIFIED”. The middle one is not an accusation — the file may have been opened on another machine.
  • Not plain text: line bodies are stored encrypted.

An honest limit: someone with local administrator rights on your computer can take ownership of the folder and change the permissions; preventing that entirely is not possible on Windows. The goal is: impossible for a standard user, deliberate and multi-step for an administrator, and impossible to hide in any case. A person connecting remotely is normally not a local administrator.

Retention period. Records are kept in monthly files; in “My Card and Settings” you can choose 3, 6, 12, 24, 36 months or “Unlimited”. This period applies only when the software is installed (service mode): in portable use no component holds the delete right, so old files are not removed. This is a deliberate choice — not being able to delete the log matters more than enforcing the retention period.

Password attempt limit

Repeated wrong passwords get blocked automatically:

  1. After three failed attempts, a 5-minute wait begins.
  2. When the wait ends, two more attempts are granted.
  3. If those also fail, access is blocked permanently.

Only you can lift a permanent block: open Settings › Engellenen Bağlantılar (blocked connections), select the row and choose Giriş Denemesine İzin Ver (allow login attempt).

Someone who gets it wrong twice and right on the third try has their counter cleared, so accidental blocks do not happen. Blocks survive restarting the application or the computer.

7. Ports and firewall

CSRemoteDesk connection flow and ports Both computers register with the introduction server over outbound TCP 6000 and UDP 6001, then a direct connection is established between them over UDP 5501. Screen images and files never pass through the server. csremotedesk.com introduction (signaling) server TCP 6000 · UDP 6001 You (connecting) outbound access is enough 6000 · 6001 · 5501 Remote computer outbound access is enough 6000 · 6001 · 5501 ① register + introduce ② learn address ③ DIRECT (P2P) — UDP 5501 screen · files · keyboard/mouse — end-to-end encrypted Screen images and files never pass through the server; it only introduces the two sides. Connecting directly by IP on the same local network (optional): the remote computer needs inbound TCP 5500 · UDP 5501 · TCP 5503 open — setup adds these rules for you.
Connection flow: the server only introduces the two computers; screen, file and keyboard/mouse traffic flows directly between them (P2P) and is end-to-end encrypted.

Normal use (by ID, over the internet) — recommended

You do not need to open inbound ports or configure port forwarding on either side. All that is required is permission for the outbound connections below. Home and office routers allow these by default; only strict corporate firewalls may need an explicit rule.

DirectionPortPurpose
OutboundTCP 6000Registration and introduction with the CSRemoteDesk server
OutboundUDP 6001Direct-connection matchmaking (hole punching)
OutboundUDP 5501Direct (peer-to-peer) screen, file and control traffic

This is the information to pass on to the team that manages your corporate firewall. On the machine being connected to, the full installation adds the required Windows Firewall rules automatically.

Same network (LAN) / connecting by IP address

If both machines are on the same local network you can also connect directly by IP. In that case the following inbound ports must be open on the machine being connected to — the full installation adds these rules itself. In portable mode the program creates these permissions itself if it is running as administrator; if not, it asks you and creates them with your approval.

DirectionPortPurpose
InboundTCP 5500Control channel
InboundUDP 5501Screen and file transfer
InboundTCP 5503Fallback channel for file transfer

8. File and text transfer

There are four ways; use whichever suits the moment:

  • Drag and drop: drop a file, folder or text onto the remote desktop window. Files land in the folder you dropped them on; text is pasted into the window under the cursor.
  • File Manager: a dual-pane view. Best for large transfers, copying folders, and resuming an interrupted transfer.
  • Ordinary copy-paste: Ctrl+C / Ctrl+V works in both directions, for text and files.
  • Alternative channel: Shift+Ctrl+V. Use this when corporate security policy blocks Windows' clipboard plumbing. It sends the text or files from your clipboard to the remote computer.
  • The other direction: Shift+Ctrl+C. Pulls the selected content from the remote side into your clipboard; then paste it locally with Ctrl+V.

Because Shift+Ctrl+C pulls on demand, it can fetch something that was copied on the remote machine before you connected — ordinary clipboard sharing only reacts when the clipboard changes. If you would rather people who connect to you could not use it, turn it off from "Kartvizitim ve Ayarlarım"; the setting applies immediately, even mid-session.

9. Upgrading to a new version

You do not need to uninstall the old version. Just run the new installer; the running application and service are stopped and updated automatically.

Your settings are preserved: your "My Connections" list, connection history, unattended access settings and machine ID all survive the upgrade.

Updating from inside the app

When a newer release is published the app tells you at startup. If you want, you can download and install the update straight from inside the application — there is no need to visit the download page.

  • Installation runs through a wizard. There is no silent or background install — you confirm each step.
  • The downloaded file's signature is verified before installation; if the file is corrupt or altered, it is not installed.
  • If the app is installed as a service, the update stops and reinstalls the service, and you are asked not to abandon the wizard midway.
  • Portable (no-install) copies are not offered the update — you moved the file there yourself, so you control the version.
  • Tick "don't remind me for this version" to silence the notice for that release; you will hear about it again when something newer ships.

Because we are a new publisher, the update wizard may open with an "Unknown publisher" warning in Windows — continue with More infoRun anyway. This warning will be removed once a code-signing certificate is in place.

Mixed versions work: if one side has not been updated yet the connection still succeeds. But encryption requires both sides to be on a current version, so updating every computer is recommended.

10. Frequently asked questions

Does the picture adapt to my connection speed?
  • Yes. The quality profile you choose sets the target; underneath it the program measures the link itself. The viewer reports its loss rate every 5 seconds, on loss the data rate is reduced, and when the link is clean again it climbs back gradually.
  • If several people are connected to the same computer, each is adjusted to their own link; if one person’s link is slow only their picture degrades.
  • Picture fragments lost on the network are requested again individually instead of a whole new frame; the picture continues with a short delay instead of freezing.
Can I connect from my phone?
  • Yes. There is a separate app for Android phones and tablets, supplied as an APK on the download page (Android 6.0 or later, 64-bit). To install it you must allow “install from unknown sources” on the phone.
  • The app is the connecting side only: the phone’s screen is not shared, the phone has no permanent identity and nobody can connect to it.
  • A connection is made as on the desktop: the other computer’s ID (or its IP on the same network) and its password. Saved connections live in a grouped list; one tap selects, a second tap on the same card connects.
  • Gestures follow the familiar remote-desktop convention; a gesture card is shown on the first connection and the “?” button in the menu opens it again. File transfer, chat and clipboard sharing are not available on the phone in this version; there is no iPhone / iPad version yet.
Can I reverse the direction so the other person connects to me?
  • Yes. The "Swap Direction" button on the toolbar of the remote control window swaps the roles: the current session closes and the other side connects to you.
  • It is not a silent handover — the other side is asked to approve. The dialog defaults to "reject" and the request lapses if nobody answers.
  • Permission is asked again in the new direction, so nobody starts sharing their screen without noticing.
Is there help inside the program? Does it work offline?
  • Press F1: the user guide opens inside the program.
  • Type two characters into the "what do you want to do" box and the search starts as you type; clear the box and it returns to the opening section.
  • The text is embedded in the application: no internet is needed and no data leaves your computer. No AI service is used and your question is never sent to a server.
  • Drag the divider between the index and the reading pane to suit yourself; the size and position are remembered for next time.
Can I record what a visitor does on my computer?
  • Yes. The "Record this computer's screen while someone is connected" option under "Settings" is on by default in this version; clear the box if you do not want it.
  • Recording is never covert: the person connecting is told that recording is on and must accept. Anyone who declines cannot connect, and the connection closes if they do not answer. Older builds that do not understand the notice are refused as well.
  • What is recorded is your screen. The video stays with you and is sent nowhere; recordings have no sound and do not increase the other side's bandwidth use.
  • Files are kept as MP4 in the "Kayit" folder, in a separate sub-folder per identity. On the "Connections To Me" screen, select the session and choose "Show Session Recording" to play it.
  • When each recording finishes, its SHA-256 fingerprint is written into the tamper-proof connection log — that is how you show it has not been altered.
  • Two limits work together against disk use: recordings older than 30 days and anything above 5 GB in total are deleted, oldest first. Both can be changed under Settings; enter 0 to switch a limit off. If disk space runs low, recording stops itself.
I cannot connect — what should I check?
  • Make sure CSRemoteDesk is running on both computers.
  • Check that the ID and password were typed correctly, with no stray spaces.
  • Check whether the remote machine shows as "online" in the app.
  • On a corporate network, outbound TCP 6000 and UDP 6001 must be permitted (see Ports).
  • Your beta build may have expired — download the current release.
What is the ID, and does it change?

The ID is a permanent number assigned to each computer and is used instead of an address. It does not change when the computer restarts or its IP address changes.

Is the connection really encrypted?

Yes. Screen, mouse and keyboard, cursor, clipboard and file transfers are all encrypted with AES-256-GCM. A fresh, single-use session key is derived over ECDH P-256 for every connection and verified against the session password; this both blocks man-in-the-middle attacks and keeps your password off the wire. Encryption is automatic and needs no configuration.

Encryption is mandatory. A connection that cannot be encrypted is not accepted — there is no "falls back to plaintext" case. If a very old version tries to connect, the connection is refused and the other side is told it needs to update. So you do need to keep all of your computers on a current version.

Once connected, both ends show the same security code; read it out over the phone to confirm by eye that you reached the right machine with no one in between.

Does my data pass through your server?

No. The server only helps the two sides find each other; after that, screen, file and control traffic flow directly between the two computers. Only on networks where no direct connection can be established does the app fall back through the server — and even then the traffic stays end-to-end encrypted.

Two exceptions: when several people connect to the same machine at once, the direct path is not used and sessions are carried through the server. And if the direct path breaks mid-session, the app returns to the server route without data loss so the session continues uninterrupted.

Why am I asked for a name and email before connecting?

You need to enter these once before you can connect anywhere. The purpose is so that the person you connect to knows who is reaching them. If you have not entered them, the app takes you to the "Kartvizitim ve Ayarlarım" (My Card and Settings) screen automatically when you try to connect.

These details stay on your own computer and require no sign-in. A server account ("Hesabım") is a completely separate, optional thing.

Do I need to create an account?

No. The application works fully without one — you can connect, transfer files and use every feature.

An account is only for people who want to see all their computers in one place and, later on, keep track of a licence. You can create one with your email address from "Hesabım" (My Account), and remove machines you no longer use from "Cihazlarım" (My Devices). Your password is never stored as-is.

I want to know when someone connects — how?

Turn on connection approval from Kartvizitim ve Ayarlarım (My Card and Settings). After that, an approval window appears before your screen is shared; if you do not approve, no connection is made.

You can enable it for only the operation types you want (remote control / view-only / file transfer). If you do not answer within 30 seconds the request is refused. See section 4 for details.

Do I need to open ports on my router?

No. Normal use requires no inbound ports or port forwarding on either side; ordinary outbound internet access is enough. See Ports and firewall for details.

How do I enable unattended access?

Run the installer on the remote machine to do the full installation, and set a permanent access password. Unattended access only works in service mode; it is not available in portable mode. See section 3.

Does it work alongside RDP (Remote Desktop)?

Yes. CSRemoteDesk can be used together with Windows' own Remote Desktop.

My antivirus deleted a file — what now?

This is a known false positive. Because the application is a remote administration tool and injects remote mouse and keyboard input, some antivirus products — Kaspersky in particular — may delete the CSRemoteDeskHelper.exe component. When that happens you still get a picture, but mouse and keyboard do nothing.

The fix: add C:\Program Files\CSRemoteDesk to your antivirus exclusions, restore the deleted file from quarantine, and re-run the installer if needed. Details: antivirus warning.

Copy-paste does not work on my corporate network

In some organisations Windows' standard clipboard plumbing is blocked by security policy, so ordinary Ctrl+V does not work. CSRemoteDesk does the same job over its own transfer channel: use Shift+Ctrl+V — for text and files alike. Drag-and-drop and the File Manager are alternatives.

The application will not start / says it has expired

Beta builds stop running 30 days after they were compiled. Download the current build from the download page; if that one is also stale, write to us.

Can I wake a sleeping remote computer?

Yes — Wake-on-LAN is supported. Right-click the computer in "My Connections" and choose Wake computer. Because the network card address (MAC) is saved automatically the first time you connect, you usually don't have to enter anything by hand.

The wake signal only travels within the same local network. To wake a computer in a remote office, another CSRemoteDesk that is running (awake) on that network is used as a relay. For the settings needed on the computer itself, the app includes a step-by-step "How do I set this up?" help window.

Can I put a remote computer to sleep?

Yes. Right-click the entry in your "My Connections" list and choose Put Computer to Sleep. Unlike waking, this does not require you to be on the same local network; the request travels through CSRemoteDesk and works wherever you are. The only requirement is that the other computer is switched on.

The computer being slept grants the permission. On that machine, under "Settings › Unattended Access Management", your entry is opened and "Put this computer to sleep remotely" is ticked. The permission is off by default and is granted per identity; without it nothing happens and the reason is shown on screen.

If a program on the other side has unsaved work, Windows may postpone the sleep and the machine stays awake. The request is deliberately sent without forcing: it would not be right for a remote command to override someone else's unsaved work.

Can I see the second monitor?

Yes. When the remote computer has more than one screen, click the monitor button on the toolbar of the remote control window and pick one from the list. The picture switches to that screen immediately — you do not need to disconnect. Your choice is remembered separately for each computer. If the remote side has only one screen the button stays in place but is greyed out.

To watch them all at once, use the All Screens entry at the end of the list. Three things are worth knowing about it: if the screens are different sizes, one corner of the image is a black, unclickable area that belongs to no screen (that is how the Windows desktop layout works); in installed mode the option is not offered when the combined width of the screens is very large; and it uses more of the remote computer's processor than a single screen does.

Can I just exchange messages without connecting?

Yes. Right-click the person in your “My Connections” list and choose Chat; a separate chat window opens. No screen is shared, no files are transferred, and you do not need to know the other side’s session password. As well as chatting through the identity number, you can chat with a computer on your local network directly over its IP address.

If the other person is not connected at that moment you see it immediately and the typing area is disabled — you do not waste time waiting for a reply. There are no offline messages; chat requires both sides to be connected. A single tick at the end of the line you sent shows that the message reached the other computer; it is not a “read” indicator, and there is deliberately no read indicator.

Conversations are encrypted end to end: they are never kept on the server and never written to disk, and the history is gone when you close the window. The security code shown at the top of the window must be the same on both sides; if it matches, you can be confident that nobody is sitting in the middle.

You decide who may write to you. People in your list may write directly; for everybody else you choose “never accept”, “ask me first” or “always accept” in the My Card and Settings screen, and you can step outside that setting for a single person. When your approval is requested, only the identity of the sender is shown — the text they wrote never appears on your screen before you allow it.

Can I back up my settings and connection list?

Yes. Settings › Back Up Everything writes your “My Connections” list, connection history, card details, settings and window layout to a single file; Restore From Backup brings them all back.

Saved passwords and unattended access data are included only in a password-protected backup; they are never written to an unprotected one. Restoring unattended access requires the application to run as administrator.

To move the list to another computer, right-click the “My Connections” list and use Export / Import. A full backup is for restoring the same computer: if you restore it elsewhere, your identity and access passwords are not transferred.