My Windows PC may be infected with malware or a remote-access trojan. The cursor moves without input, Command Prompt or PowerShell windows briefly appear and disappear, and the browser opens on its own and redirects to adult websites. I have disconnected the computer from the internet to limit possible unauthorized access. What offline tools and steps can I use to investigate and remove the infection? If cleaning the system is not reliable, what is the safest way to reinstall Windows without carrying the malware over?
2 Answers
Before wiping the computer, use a separate trusted device to change important passwords, enable multifactor authentication, and sign out other sessions. Avoid copying programs, scripts, browser profiles, or suspicious archives from the affected system. After reinstalling, fully update Windows, enable its built-in security features, and install software only from official sources.
You can first scan the machine offline with a reputable bootable antivirus or rescue USB, and tools such as Malwarebytes may help identify less persistent threats. Keep the computer disconnected while investigating, and do not create the installer or download security tools from the potentially infected system. Even if a scan finds and removes something, a reinstall is still the safer choice for a suspected RAT.

A scan can be useful for learning what happened, but it should not be treated as proof that a remote-access infection is completely gone. Back up only personal documents after checking them, then wipe and reinstall if possible.