I looked at my logs and
I received an unsolicited inbound connection via port 3389 from 64.217.219.120 which is an address in the range from my ISP, I had set a rule to block all unsolicited inbound on this port from all outside sources, how can this be happening then?
Connection: 64.217.219.120: 62852.
to MY-PC: ms-wbt-server(3389).
0 bytes sent.
0 bytes received.
0.007 elapsed time