Click on screenshot to zoom
Danger level 9
Type: Rogue Anti-Spyware
Common infection symptoms:
  • Installs itself without permissions
  • Connects to the internet without permission
  • Shows commercial adverts
  • Annoying Pop-up's
  • Slow Computer
Other mutations known as:

Memory Scan

Although there may well be many variants of harmful and malicious rogue system optimizers and defragmenters scouring the Internet for victims, few can measure up to the acidic damage Memory Scan is capable of. This rogue defragmenter finds its roots in the same vitriolic family as Disk Defragmenter, Memory Optimizer and Good Memory. It is plain to see by the company Memory Scan keeps that it has no interest in being of any benefit to a PC, but only out to rip consumers off. What’s more distressing is the fact that Memory Scan will stop at nothing to realize its main goal, even being the instigator of permanent and irreversible damage to its victims’ systems.

Memory Scan certainly does not break new ground with its infection techniques. Making use of fake online malware scanners and illicit online domains acting as browser hijackers, Memory Scan will enter the user’s PC without his knowledge. This insidious and false application has also been known to surreptitiously bundle its Trojans and malware along with legitimate security updates and downloads obtained from third party websites.

Memory Scan’s presence will for the most part remain unnoticed by the PC owner, who will only become aware of Memory Scan once the rogue launches its attack on the system. This will happen by Memory Scan making use of various fake security alerts. These fake notifications were designed mainly to panic users into thinking their PCs aren’t operating optimally, but also in part to place Memory Scan in an authoritative light with its victims. All of the alerts received from and generated by Memory Scan is without basis and should enjoy no attention from the PC owner. Some of the more devious fake security notifications to be on the lookout for include the following:

Critical Error!
Damaged hard drive clusters detected. Private data is at risk.

Critical Error
Hard Drive not found. Missing hard drive.

Critical Error
RAM memory usage is critically high. RAM memory failure.

Critical Error
Windows can't find hard disk space. Hard drive error

Critical Error!
Windows was unable to save all the data for the file System32496A8300. The data has been lost. This error may be caused by a failure of your computer hardware.

Critical Error
A critical error has occurred while indexing data stored on hard drive. System restart required.
System Restore
The system has been restored after a critical error. Data integrity and hard drive integrity verification required.

Activation Reminder
Memory Optimizer Activation
Advanced module activation required to fix detected errors and performance issues. Please purchase Advanced Module license to activate this software and enable all features.

Low Disk Space
You are running very low disk space on Local Disk (C:)

Windows - No Disk
Exception Processing Message 0x0000013

Obviously none of these fake alerts can be trusted, and users are urged to treat all correspondence received by Memory Scan as highly suspicious. In order to minimize the certain damage posed by this harmful infection, erase Memory Scan from the system at the earliest opportunity. Do this by investing in a properly functioning security application which will not only remove Memory Scan but also protect against future attacks and threats.

Download Spyware Removal Tool to Remove* Memory Scan
  • Quick & tested solution for Memory Scan removal.
  • 100% Free Scan for Windows

How to manually remove Memory Scan

Files associated with Memory Scan infection:

%ALLUSERSPROFILE%\Application Data\[random].exe

Files associated with Memory Scan infection (Win7, Vista):


Memory Scan processes to kill:

%ALLUSERSPROFILE%\Application Data\[random].exe

Remove Memory Scan registry entries:

HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\Download "CheckExeSignatures" = 'no'
HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\Main "Use FormSuggest" = 'yes'
HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Policies\Associations "LowRiskFileTypes" = '/{hq:/s`s:/ogn:/uyu:/dyd:/c`u:/bnl:/ble:/sdf:/
HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Policies\Attachments "SaveZoneInformation" = '1'
HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Run "[random]"
HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Run "[random].exe"


  1. Sam Jan 20, 2011


Post comment — WE NEED YOUR OPINION!

Please enter security code:
This is a captcha-picture. It is used to prevent mass-access by robots.