Hi, Rick,
What is the problem. If you could access anything without Admin Password, then it is a standard user account accessing the file.
when are you getting this Homeland alert?. If anything could be logged it will be stored in the event viewer.
If you want to see the boot log, then you have to go to msconfig and then tick the bootlog. Accept the alert and boot, and you will find the result of the bootlog in c: windows,ntbtlog.txt, which could be opened with notepad. See what drivers and otherfiles, When booting is done.
Update: There is one more way ,by command prompt
netstat -ano. This will list the existing connection that your computer have. Go to the Task Manager, view menu, enable PID, and then close. Go to command prompt, and type netstat -ano,you will know all the connections the computer has at the point of time, open the task manager and note the connected PIDs, then check that with the processes in the task manager. Kill those processes ID which you think that it is accessing remotely