My Windows PC may be infected with malware or a remote-access trojan. The cursor moves without input, Command Prompt or PowerShell windows briefly appear and disappear, and the browser opens on its own and redirects to adult websites. I have disconnected the computer from the internet to limit possible unauthorized access. What offline tools and steps can I use to investigate and remove the infection? If the system cannot be trusted, is a clean Windows reinstall the safest option?
3 Answers
If you want to attempt a scan before wiping the machine, use a reputable rescue environment or offline antivirus scanner created on another computer. Keep the affected PC disconnected, boot from the rescue USB, update the scanner if the environment supports it, and run a full scan. An offline Malwarebytes scan can also help, but a clean result does not prove that a sophisticated RAT is gone.
With symptoms this serious, a clean reinstall is generally the safest and most reliable solution. Create Windows installation media using a separate, known-clean computer, boot the affected PC from it, delete the existing system partitions, and install Windows again. Back up only personal documents you have checked carefully—do not preserve programs, scripts, browser extensions, or executable files. Afterward, change important passwords from the clean system and enable multifactor authentication.
Do not create the installation USB or download tools from the potentially compromised PC. Use a separate trusted computer, and consider the affected machine untrusted until Windows has been reinstalled. Once it is back online, install updates and restore applications from official sources rather than copying old installers or suspicious backups.

Related Questions
Can't Load PhpMyadmin On After Server Update
Redirect www to non-www in Apache Conf
How To Check If Your SSL Cert Is SHA 1
Windows TrackPad Gestures