Memory Fixer Description
Memory Fixer is a rogue system optimization tool that generates fabricated security notifications in order to trick victims into believing that their computers have serious issues. The method of propagation used by Memory Fixer involves Trojans that secretly enter computer systems and install this rogue onto the machines. The Trojans will also create a start-up registry entry to ensure that Memory Fixer is executed every time the system is booted up. Access to the Registry Editor and Task Manager will also be blocked.
On successful installation and execution, Memory Fixer aka MemoryFixer will simulate a system scan and report the detection of several errors in the hard drive and memory. When a victim attempts to launch other programs or delete files, Memory Fixer will display error messages which will urge the victim to purchase the rogue’s full version which can apparently repair all the detected errors.
Memory Fixer is not able to optimize or defrag your system, do not be fooled by its legitimate appearance. It is a useless application that should never be purchased. Memory Fixer will alarm a victim even further by making it appear as though certain important folders in the computer are empty. Victims should ignore all these little tricks and get a reliable and updated rogueware removal tool to extinguish Memory Fixer from their computers as soon as possible.
Type: Misleading Product
How Can You Detect Memory Fixer?
Memory Fixer Technical Report
As new Memory Fixer details are reported by our customers and findings from our Threat Research Center, we will update this section.
Fake message for Memory Fixer:
The following fake error message(s) appears for Memory Fixer:
“Windows detected a hard drive problem.
A hard drive error occurred while starting the application.”
Hard Drive not found. Missing hard drive.”
RAM memory usage is critically high. RAM memory failure.”
Memory Fixer has typically the following processes in memory:
Memory Fixer creates the following registry entries:
- HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Run “[random].exe”
- HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Run “[random]”