I have since deleted the Minecraft demo and everything he downloaded, tried changing the permissions of the files in SafeSavings folder in ProgramData by changing the data in its backup file with gibberish, and its still running itself!
Does anyone else have experience with this malware? Does anyone have any clue what I can do to get rid of this bastardization of adware? Thanks in advance.
Here are the steps to do it manually:
Delete these folders:
C:\Program Files (x86)\SafeSavings
C:\ProgramData\SafeSavings\
C:\ProgramData\Microsoft\Windows\WindowsAccManager
Run regedit (Ctrl+Alt+Delete, Task Manager, File, Run, regedit):
Delete Folder: HKEY_CURRENT_USER\SOFTWARE\MySafeSavings
Delete Folder: HKEY_LOCAL_MACHINE\SOFTWARE\WOW6432Node\Microsoft\Windows\CurrentVersion\Uninstall\MySafeSavings
Delete Folder: HKEY_LOCAL_MACHINE\SOFTWARE\WOW6432Node\MySafeSavings
Delete Folder: HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Services\smass (ignore error, if any)
If any of the above locations are missing on your setup, see some of the other possibilities here: www.enigmasoftware...avings-removal/
Go back to normal windows mode: See the first link, basically type this into CMD (Command Prompt) bcdedit /deletevalue {current} safeboot
That should be it.
The computer was lagging and I opened Task Manager again try again to stop mysafesavings.exe from running long enough for me to edit the ".exe" to something else.
I think it worked. When I did that it couldn't reactivate itself because I made it an unopenable type of file the trojan couldn't recognize fast enough during the lag. The computer lagging was one of its weapons, but it looks like its evil plot backfired.
The only computer I can still play Q3 on now is our 15 year old Dell desktop that's slow as molasses until I get the computer in my room fixed or replaced.
Only registered members can post a reply.
Already registered? Sign in.