Remove spyware that monitors mouse activity
Spyware that records mouse movements, clicks, active windows, or browsing behaviour can operate quietly in the background. It may arrive through a bundled installer, a fake browser update, a malicious email attachment, or a compromised download. Unusual cursor activity is also sometimes caused by remote-access malware rather than conventional tracking software.
Use this guide to investigate the computer methodically without deleting important system files. The steps apply to Windows and macOS, with extra precautions for shared households, workplace devices, and computers used for online banking in Australia.
Recognise suspicious input monitoring
Warning signs include a cursor moving without your input, unexplained clicks, new browser tabs, sudden performance problems, or security settings that have been disabled. You may also notice unfamiliar applications, extensions, login items, or remote-support tools. A single incident does not prove spyware, since a failing mouse, touchpad, Bluetooth device, or accessibility setting can create similar behaviour.
Begin by disconnecting the computer from Wi-Fi or unplugging its Ethernet cable. This can interrupt remote control and limit data transfers while you investigate. If the device is used for work, record the time and visible symptoms before making changes, then notify the relevant administrator. Pc Malware Expert offers broader malware removal guidance for identifying related threats.
Avoid logging into banking, email, cryptocurrency, or social media accounts from the affected computer. If someone may have accessed the device remotely, use a separate trusted phone or computer to change important passwords later.
Contain the computer safely
On Windows, open Task Manager with Ctrl+Shift+Esc and review unfamiliar processes, but do not end a process merely because its name looks technical. Search the exact name using a trusted device and check whether it belongs to Microsoft, a known hardware vendor, or software you deliberately installed. On macOS, Activity Monitor provides a similar view; Apple system processes should not be removed manually.
Unplug external drives and avoid copying suspicious programs to another device. If the mouse or trackpad is moving by itself, turn off Bluetooth and disconnect USB pointing devices. A hardware fault may stop when the peripheral is removed, while continued activity suggests software, a touchscreen issue, or remote access.
Check apps, extensions, and startup items
In Windows, go to Settings, Apps, and Installed apps, then sort by installation date. Remove software you do not recognise only after checking its publisher and purpose. Review Task Manager’s Startup apps for unexpected entries. In macOS, open System Settings, General, and Login Items to inspect programs that launch automatically. Look at browser extensions in Chrome, Edge, Firefox, or Safari and remove those you did not install.
Also check for remote-control utilities, keyboard or mouse recorders, and unofficial “system cleaners”. Some legitimate tools used by support technicians can be abused if an attacker installed or configured them without permission. If the computer belongs to an employer, school, or family member, confirm ownership and authorisation before removing managed software.
| Warning sign |
What to inspect |
Safer response |
| Cursor moves or clicks alone |
Bluetooth devices, remote-access apps, USB peripherals |
Disconnect devices and isolate the computer |
| New tabs or altered searches |
Browser extensions, proxy settings, homepage changes |
Remove unknown extensions and restore trusted settings |
| Security tools disabled |
Antivirus status, firewall, system policies |
Re-enable protection and run an offline scan |
| Unknown login item |
Startup apps, scheduled tasks, macOS Login Items |
Research the publisher before removal |
| Account alerts |
Email, banking, social media sessions |
Change passwords from a clean device |
Scan Windows or macOS thoroughly
On Windows, open Windows Security, select Virus & threat protection, update protection intelligence, and run a Full scan. If symptoms continue, use Microsoft Defender Offline scan from the same area; it restarts the computer and checks before normal Windows processes load. Save open work first and keep the device connected to power.
On macOS, update macOS and run a reputable security scanner downloaded from the vendor’s official website. Review browser permissions, notification permissions, and any unfamiliar configuration profiles under System Settings. On either platform, run one well-regarded scanner rather than installing several competing products, and quarantine detected items instead of manually deleting files from system folders.
If the malware blocks normal tools, start Windows in Safe Mode with Networking only when an updated scanner requires internet access. For routine cleanup, plain Safe Mode reduces the number of third-party processes. On a Mac, use the appropriate Safe Mode method for Apple silicon or Intel hardware, then repeat the checks for login items and browser extensions.
Secure accounts and recover safely
From a separate, trusted device, change the password for the primary email account first, followed by banking, shopping, cloud storage, and social platforms. Use unique passwords and enable multi-factor authentication with an authenticator app or security key where possible. Review active sessions and sign out unknown devices. Australian users should contact their bank immediately if they entered payment details while the spyware was active, and can report suspected scams through Scamwatch or the Australian Cyber Security Centre.
Check email forwarding rules, recovery addresses, newly created users, and browser-synchronised passwords. If work credentials were used, notify the organisation’s IT team rather than attempting to conceal the incident. Where files have also been encrypted or renamed, follow a dedicated ransomware recovery guide and preserve evidence before resetting the device.
A clean backup can help, but do not restore applications or unknown executables from it. Documents, photographs, and other personal files should be scanned before being copied back.
Prevent repeat monitoring
Install operating system and browser updates promptly, and download software from official vendor pages or established Australian retailers rather than adverts and pop-up prompts. Be cautious with “free” utilities promoted through search results; a cheap USB accessory from a local shop or an app obtained through an official store is safer than an unknown bundled installer, though neither is automatically risk-free.
On an NBN connection, keep the home router’s firmware updated and change its administrator password from the factory default. Use a separate guest network for unfamiliar smart devices, and review connected devices periodically. Households in Sydney, Melbourne, Brisbane, and other Australian cities often share computers, so separate user accounts can prevent children or visitors from installing software under an administrator profile.
Keep regular offline or versioned backups, test that files can be restored, and retain a trusted security tool with automatic updates enabled. If the cursor continues moving after peripherals are disconnected, scans are clean, and suspicious software has been removed, have the hardware examined and consider a full operating-system reset after preserving essential evidence.