How to remove spyware that takes screenshots every few minutes
Screenshot spyware is a quiet but invasive threat that periodically captures your display and sends it to a remote operator. For Australian households and small businesses, this exposes online banking at CBA or ANZ, myGov tax records, and client files handled through Xero from a Melbourne or Brisbane office. Even a few minutes between captures is enough to reveal passwords, TFNs, and private messages.
Most infections arrive through deceptive installers, cracked software, or phishing emails posing as Australia Post or AGL. Once active, the malware hides while you keep working in Sydney, Perth, or Adelaide, often blending in with legitimate processes. Every minute it runs is another window into your digital life.
A systematic approach combining internet disconnection, Safe Mode scanning, and persistence cleanup gives the best chance of a clean recovery.
Signs that screenshots are being captured
A machine that suddenly sounds like a jet turbine while idle, or a laptop that drains battery fast on a warm Brisbane afternoon, is sending a clear signal. Screenshot spyware relies on frequent capture and upload activity, forcing the CPU and network card to work harder than normal. A Melbourne household connected to the NBN may notice steady outbound traffic even when no browser is running.
Open Task Manager and look for unfamiliar process names, especially those with consistent CPU or memory use. Some variants disguise themselves as services with names like "svchost" spelled incorrectly. Random webcam activation when no app is in use is another red flag, since many screenshot tools also probe attached cameras.
Pop-ups, search engine changes, and odd font swaps in Chrome or Edge often point to a related infection. The same bundle may include adware that changes browser fonts and other browser-modifying code.
Disconnect and secure your accounts first
Before running any cleanup tool, pull the Ethernet cable or disable Wi-Fi. Cutting the network stops the spyware from transmitting the latest captures. If you need to stay online, use a phone on mobile data or a second, clean laptop to handle password resets.
Change passwords for every account open during the suspected infection. Australian services worth prioritising include myGov, ATO-linked portals, online banking, superannuation logins, and your primary email. Enable two-factor authentication using an authenticator app rather than SMS, since SIM-swap fraud remains common in Sydney. Review active sessions in Gmail, Microsoft 365, and banking apps, then sign out everywhere to invalidate captured cookies.
Boot into Safe Mode and run a deep scan
Safe Mode loads Windows with only essential drivers, preventing most spyware from launching. On Windows 10 or 11, hold Shift while clicking Restart, then choose Troubleshoot, Advanced Options, Startup Settings, and Restart. Press 4 or F4 for Safe Mode, or 5 or F5 for Safe Mode with Networking.
Run a full system scan using a reputable tool. Four options handle screenshot-capturing spyware reliably on Australian home networks:
| Tool |
Cost |
Offline Scan |
Behaviour Monitor |
Best For |
| Windows Defender |
Free |
Yes |
Yes |
First-pass cleanup |
| Malwarebytes Premium |
Subscription |
Yes |
Yes |
Second opinion |
| ESET Smart Security |
Subscription |
Yes |
Yes |
Heavy infections |
| Kaspersky Internet Security |
Subscription |
Yes |
Yes |
Ransomware defence |
After the scan, quarantine everything flagged and reboot into normal mode. If two tools report the same threat, you can be confident the detection is real.
Remove persistence from startup and scheduled tasks
Modern spyware rarely relies on a single executable. It plants entries in multiple startup locations so deleting one copy still leaves the threat alive. Open Task Manager and disable anything in the Startup tab you did not intentionally install, especially entries with no publisher or random character strings in the path.
Next, open Task Scheduler and review the library for tasks triggering on logon or at frequent intervals. Many screenshot tools create tasks named after Windows components to avoid suspicion. Right-click unfamiliar tasks, read the Actions tab, and delete any pointing to temp folders or random AppData directories.
Screenshot-collecting malware frequently arrives as a second-stage payload dropped by a trojan that downloads extra payloads, so removing that loader is just as important as killing the capture component. Registry keys under HKCU and HKLM...\Run are another common hiding spot, best cleaned after the main infection is gone.
Clear browsers, reset permissions, and check webcams
Return to your browser and open the extensions page. Remove anything you did not install yourself, especially tools claiming to speed up browsing or manage tabs. Screenshot spyware often bundles a browser helper object that keeps the infection alive after the main executable is removed.
Reset the browser to default settings and clear cookies, cached files, and site permissions for the camera and microphone. Tools like Teams and Zoom request those permissions legitimately, but spyware can piggyback on a previously granted prompt. Revoking camera access limits what a background process can capture on a Perth household webcam or Sydney office camera.
Check installed applications in Settings and uninstall anything that appeared around the time symptoms began. Sort by install date and remove any unfamiliar "drivers" or "codecs."
Rebuild the system for long-term safety
Once clean, install all pending Windows updates and enable automatic delivery. Turn on the built-in firewall if it was disabled, and confirm your NBN modem firmware is current. Consider a clean install of Windows if the infection was severe, then restore files from a backup created before the breach.
Stick to official download sources and avoid pirated applications, which remain a common carrier of screenshot malware in Australia. Treat unexpected invoices from AusPost or AGL with caution, and verify them through the official app rather than clicking the link. Run a full scan monthly and keep real-time protection active to catch the next attempt before it settles in.