Skip to main content

Simply Computers

Call For a Free Quote:

Available by Appointment

Diane Saw Her Mouse Moving on Its Own: Hidden Remote Access Had Been Installed

Diane knew something was wrong when her computer showed what looked like a Windows blue-screen warning and the mouse began moving without her touching it. That was more than an ordinary pop-up. It suggested that someone or something might still have remote control of the computer.

A closer inspection found several unauthorized ScreenConnect remote-access services along with an unfamiliar device-management enrollment. These were separate from the legitimate remote-support software Diane knowingly used. The trusted software was not treated as the problem simply because another remote-access tool had been installed without permission.

The first priority was to interrupt the unwanted access without destroying useful evidence. The suspicious services, processes, and folders were documented. Their services were disabled, related processes were stopped, and the associated files were quarantined so they could no longer keep reconnecting in the background.

The incident also exposed a second problem: the computer’s backup had not completed successfully since January 2026. That limited the clean recovery points available. The service provider was contacted, and important passwords needed to be reset from a trusted device rather than from the affected computer.

The immediate remote connections were disabled, but a computer that has been managed by an unknown third party cannot automatically be declared completely clean. A conservative recovery using a known-good backup or clean Windows installation was safer than assuming that removing the visible tools had removed every possible change.

Related service: Virus, Malware & Browser Cleanup.

Diane focused on her computer during an investigation of unauthorized remote access