Cursor Moved and Clicked on Its Own—Could This Be Malware?

0
0
Asked By MellowCedar47 On

While watching a video without touching the trackpad or mouse, my cursor suddenly began moving around, clicking things, zooming, switching tabs, and opening windows. Unplugging the USB mouse did not stop it, although I was also trying to regain control with the trackpad. I eventually shut the computer down, and the cursor behaved normally after restarting.

I disconnected Wi‑Fi and ran a Windows Defender offline scan, which found nothing. However, the scan unexpectedly asked for my BitLocker recovery key. Windows also reported that Memory Integrity was disabled because of a driver named ftdibus.sys, associated with oem146.inf. I have also noticed brief black command windows appearing occasionally for months, along with the fans suddenly becoming very loud.

My computer is currently offline and waiting at the BitLocker recovery screen. I enabled two-factor authentication on my Microsoft account, but I cannot currently sign in to retrieve the recovery key. I am worried about malware and do not want to reset the computer because many important files are stored on the desktop and are not fully backed up. I also had trouble opening a document from cloud storage on my phone, though that may be unrelated.

What should I do next? Could this have been malware or remote access, or are there more ordinary explanations such as a touchscreen, Bluetooth device, driver, or hardware problem?

3 Answers

Answered By PracticalBirch19 On

A BitLocker recovery prompt can appear after certain firmware, hardware, boot, or disk-configuration changes; it does not automatically mean someone infected the computer. Memory Integrity warnings are also commonly caused by older or incompatible drivers. The Microsoft sign-in failure may simply be a temporary account lockout after many rapid attempts, so wait before trying again and retrieve the recovery key from another trusted device if possible. Once you regain access, save the recovery key somewhere offline and establish a proper backup routine.

Answered By CopperLynx82 On

The ftdibus.sys file is normally a driver for FTDI USB-to-serial hardware, so its presence by itself does not indicate malware. The cursor incident is worth taking seriously, but it is not conclusive proof of remote access. A touchscreen registering phantom touches, a stuck input device, another Bluetooth keyboard or mouse, or a hardware/driver fault can all create behavior like this. Disconnect external input devices, check whether the laptop has a touchscreen, and look for nearby Bluetooth devices that could be sending input.

Since you are worried about compromise, change important passwords from a separate trusted device and keep two-factor authentication enabled. Before making major changes, copy irreplaceable files using a clean boot environment or have a reputable technician help you. Do not delete or reset the system until your data is safely backed up.

Answered By QuietOrbit6 On

The brief black command windows and loud fans are not enough to identify malware. They can come from scheduled tasks, startup utilities, updates, or a process using a lot of CPU. After your files are backed up, check startup and scheduled-task entries, update Windows and device drivers from the computer manufacturer, and run a second reputable offline scan. If the cursor problem returns, test with the mouse disconnected, Bluetooth disabled, and the touchscreen disabled if applicable; that can help distinguish an input or hardware problem from software control.

Related Questions

LEAVE A REPLY

Please enter your comment!
Please enter your name here

This site uses Akismet to reduce spam. Learn how your comment data is processed.