A dark cinematic close-up of a computer screen displaying abstract red warning indicators, with soft out-of-focus server rack lights glowing in the background, moody and tense atmosphere

Step-by-step removal guides for adware, browser hijackers, ransomware, trojans, and more — written for Windows and Mac users.

A wide shot of a laptop keyboard with a subtle red glow emanating from beneath the keys, shallow depth of field, dark and moody cybersecurity theme

Ransomware Removal Guides

Comprehensive ransomware removal instructions covering DJVU/STOP variants and other families. Includes references to decryptor tools from Emsisoft, Kaspersky, and NoMoreRansom, plus file recovery methods using Shadow Explorer.

Read More
A cinematic frame of a glowing padlock icon floating above a motherboard, cool blue tones with subtle amber warning lights, clean and technical atmosphere

Trojan Removal Guides

Step-by-step trojan identification and removal guides covering threats such as VB:Trojan.Agent.EIOB and Backdoor.PHP.WebShell.CT, with both manual and automatic removal methods.

Read More

Recent Stories

Helprestore@pcmalwareexpert.com Ransomware Removal Guide

How to restore the Windows snipping tool after malware disables it

Many Australians rely on the Windows snipping tool for quick screen captures during remote work, study, or sorting through MyGov paperwork. When this utility refuses to open, crashes at launch, or appears greyed out, it often signals something more serious than a minor software hiccup. Malware developers deliberately target built-in Windows utilities to limit a user's ability to gather evidence of an ongoing compromise.

Restoring the snipping tool requires more than reinstalling the application, because the underlying issue usually ties back to corrupted system files, altered registry entries, or an active infection. Skipping straight to repair tools without checking for malware can leave the door open for repeat incidents, especially for National Broadband Network households where shared printers multiply entry points. Treating repair and cleanup as two halves of the same job is the safest path forward.

This walkthrough covers practical steps for getting the snipping tool working again. It also covers how to identify the infection responsible and how to prevent similar interference in future. Before proceeding with any system changes, readers should review the site disclaimer outlining the scope of advice provided.

Recognising the symptoms of a tampered snip tool

A malware-affected snipping tool rarely fails in one obvious way. Users in Melbourne and Brisbane report the app crashing immediately after launch, while others see it vanish from the system tray. In aggressive cases, the executable is renamed, quarantined, or replaced with a stub returning a fake error. Screenshot-blocking code has appeared in banking trojans that mimic the login portals of Australian institutions such as Commonwealth Bank and ANZ, preventing victims from saving evidence of fraudulent transactions. Ransomware payloads also tamper with capture tools because operators do not want targets photographing ransom notes or payment addresses.

Other native apps may be affected at the same time. Snip and Sketch, the Steps Recorder, and the Camera app occasionally exhibit similar symptoms when a single infection damages shared system libraries. A pattern across multiple utilities indicates deliberate sabotage rather than a software bug.

Verifying the cause before you repair

Before reaching for any repair utility, confirm the tool really has been compromised. Open Task Manager and look for unfamiliar processes consuming unusual CPU or memory, especially those running as "svchost.exe" in unexpected locations. Check whether Windows Security is operational and whether recent scan results have been cleared. Australian users who suspect a serious intrusion can report the incident to the Australian Cyber Security Centre through the ReportCyber portal, where localised intelligence about regional threat actors is often available.

Once the broader system appears clean, attempt to open the snipping tool through a different method. Try launching it from a Run dialog using snippingtool, through PowerShell, or by navigating to its installation folder. If it fails across every path, the problem is system-level rather than a shortcut glitch.

Restoring through Windows settings and Store updates

The first repair avenue is the least invasive. Open Settings, navigate to Apps, then Installed apps, and locate the Snipping Tool entry. Selecting Repair triggers Windows to scan the app package and replace damaged files without touching user data. If Repair does not resolve the problem, Reset performs a fuller reinstall while keeping the app entry intact.

When the tool has been removed entirely or its Microsoft Store entry shows errors, reinstalling through the Store is the next step. Search for "Snipping Tool" in the Microsoft Store, confirm the publisher is Microsoft Corporation, and click Install. Users on metered connections in regional Western Australia should connect to an unmetered network first. If the Store itself behaves oddly, the Windows App Installer service may be disabled; open Services, locate Microsoft Store Install Service, set it to Automatic, then restart.

Using PowerShell and system repair commands

When Settings-based repairs fail, the issue often lives deeper in the operating system. Running the System File Checker from an elevated Command Prompt is a reliable starting point. Type sfc /scannow, allow the scan to complete, and restart. SFC replaces protected system files that have been altered, frequently restoring the libraries the snipping tool depends on.

For more stubborn corruption, the Deployment Image Servicing and Management tool, known as DISM, repairs the component store that SFC draws from. Running DISM /Online /Cleanup-Image /RestoreHealth pulls fresh copies of damaged components from Windows Update. Households in suburban Adelaide or Canberra will often find this completes without issue. The snipping tool can also be re-registered manually via PowerShell commands that reset the app package for both the modern and legacy versions.

External drives connected during the incident should be scanned before any rebuild is considered final. Advice on external drive cleanup walks through the safe isolation and cleanup process.

Cleaning the infection that caused the disruption

Repairing the snipping tool without removing the underlying infection is wasted effort. Boot the computer into Safe Mode with Networking to prevent most malware from launching alongside Windows. Run a full system scan using a reputable on-demand scanner, then follow up with whatever real-time antivirus is installed.

Ransomware families such as Cerber have been observed disabling screen capture tools as part of their early payload. Detailed guidance is provided in the Cerber removal walkthrough, which covers Safe Mode booting, shadow copy recovery, and file restoration tactics relevant to Australian households.

Repair methods compared for quick reference

The following table summarises the main repair approaches, their typical use cases, and their relative invasiveness. Choosing the right method depends on how deep the corruption appears to go and whether malware is still suspected.

Method Best for Time required Risk of data loss
Windows Settings Repair Single app behaving oddly 2 minutes None
Microsoft Store reinstall App missing or Store errors 5 minutes None
SFC scan Damaged protected files 20 minutes None
DISM restore Component store corruption 30–60 minutes None
PowerShell re-registration App package registration broken 5 minutes None
Malware scan and cleanup Suspected infection still active 1–3 hours Possible if files are quarantined

For most users in Australian capital cities, a layered approach works best: run the lighter repairs first, escalate to SFC and DISM if the issue persists, and only consider a full malware cleanup once the system-level damage has been addressed. Keeping Windows Update enabled and verifying unexpected emails from services such as Australia Post or the ATO remain the most reliable long-term defences.

Stydco Scam Email Virus Removal Guide

A scam displayed on the rogue website Stydco.com, typically encountered through redirects from potentially unwanted programs. This guide explains how the scam operates and how to clean affected systems.

Read More