My Dell DC15250 laptop is about eight months old and normally uses only 5–10% CPU while idle. Recently, Notepad.exe started consuming roughly 60% CPU, and ending the process in Task Manager only caused it to return shortly afterward. Microsoft Defender also detected a file named Runtime Broker.exe in a Local Disk folder. I know Runtime Broker can be a legitimate Windows component, but I'm unsure whether this copy is trustworthy. During a meeting, my trackpad pointer moved onto the camera area and then left the meeting without me touching it. I shut the laptop down because I was concerned someone—or some malware—might be controlling it. What should I check, and would scanning or reinstalling Windows be the safest approach?
4 Answers
The behavior is suspicious enough that I would treat the laptop as potentially compromised, especially because Defender found an unusual executable and the pointer appeared to move on its own. Disconnect it from the internet, avoid signing into accounts on it, and use another trusted computer to change important passwords. Back up only personal documents and photos—not programs or unknown executables—then perform a clean Windows installation. System Restore alone may not remove a persistent infection.
Runtime Broker is normally a legitimate Windows process, but its location matters. The genuine file is usually under a Windows system directory such as C:WindowsSystem32, not an arbitrary folder on the drive. Check the Defender detection details, file path, digital signature, and whether the file is actually named RuntimeBroker.exe. Don’t whitelist it just because the name looks familiar.
A bootable offline scanner can be useful before reinstalling, but it may be more technical than necessary here. If you have backups and can access another computer, a clean installation from official Windows media is generally the simplest way to regain confidence. Make sure you have your BitLocker recovery key and verify that the backup contains only files you recognize.
High CPU usage by Notepad could theoretically be a corrupted file or a fake executable with the same name, and accidental trackpad input is possible. Still, the combination of recurring processes, a Defender detection, and unexplained pointer movement shouldn’t be dismissed. Review Defender’s protection history and Task Manager’s file location, but don’t keep using the machine normally while investigating.

Related Questions
Can't Load PhpMyadmin On After Server Update
Redirect www to non-www in Apache Conf
How To Check If Your SSL Cert Is SHA 1
Windows TrackPad Gestures