Mementrandingswcom is a browser hijacker and potentially unwanted program (PUP) that forcibly redirects users through deceptive advertising networks and alters browser settings without consent. This threat typically manifests as unwanted homepage changes, new tab redirects to mementrandingsw.com, and persistent pop-up advertisements that disrupt normal browsing. While not classified as a virus in the traditional sense, Mementrandingswcom exhibits malicious behavior by installing browser extensions, modifying search engine defaults, and collecting browsing data for advertising purposes—all while resisting standard uninstallation attempts.
Users commonly encounter this hijacker after installing free software bundles that disguise the PUP within "recommended" installation options. Once active, Mementrandingswcom generates revenue for its operators through pay-per-click advertising fraud, forced traffic redirection, and affiliate marketing schemes. The threat affects all major browsers including Chrome, Firefox, Edge, and Safari across Windows and Mac platforms.
Threat Profile
| Attribute | Details |
|---|---|
| Threat Type | Browser Hijacker, Potentially Unwanted Program (PUP), Adware |
| Aliases | Mementrandingsw, Mementrandingsw.com redirect, Mementrandings adware |
| Affected Platforms | Windows (7, 8, 10, 11), macOS (10.12+), browser extensions (Chrome, Firefox, Edge, Safari) |
| First Observed | 2021 (active variants continue to evolve) |
| Distribution Methods | Software bundling, fake updates, malvertising, deceptive download buttons, torrent files |
| Persistence Mechanisms | Browser extension installation, Windows registry modifications, scheduled tasks, launch agents (macOS), browser policy manipulation |
| Primary Capabilities | Homepage/search engine modification, forced redirects, ad injection, browsing data collection, cookie tracking, affiliate link substitution |
| Common File Locations | %LOCALAPPDATA%\Google\Chrome\User Data\Default\Extensions\, %APPDATA%\Mozilla\Firefox\Profiles\, ~/Library/Application Support/Google/Chrome/Default/Extensions/ (macOS) |
| Registry Keys Affected | HKCU\Software\Microsoft\Internet Explorer\Main, HKCU\Software\Policies\Google\Chrome, HKLM\SOFTWARE\Policies\Mozilla\Firefox |
| Network Behavior | Redirects through multiple intermediary domains, connects to advertising networks, beacon/tracking requests to analytics servers |
| Data at Risk | Browsing history, search queries, clicked links, IP address, geographic location, device identifiers |
| Removal Difficulty | Moderate — resists standard uninstallation, reinstalls components if removal incomplete, may require registry/filesystem cleanup |
How It Spreads
Mementrandingswcom primarily distributes through software bundling operations where legitimate-looking free applications include the hijacker as an "optional offer" during installation. These bundles deliberately obscure the unwanted program within "Express" or "Recommended" installation modes, while only the "Custom" or "Advanced" options reveal checkboxes to decline the hijacker. Many users click through installation dialogs quickly, inadvertently granting permission for Mementrandingswcom to modify browser settings and install extensions.
The threat also spreads through fake update notifications that mimic legitimate Adobe Flash Player, Java, or browser update prompts. When users click these deceptive alerts—often displayed while visiting questionable streaming sites or torrent platforms—they download an executable that installs the hijacker instead of the promised update. Some variants embed themselves in pirated software downloads, particularly in cracked games, productivity applications, and media tools distributed through peer-to-peer networks.
Common distribution vectors include:
- Freeware installers from download portals that monetize through bundled PUPs (particularly video converters, PDF tools, download managers)
- Fake update notifications for Flash Player, browser updates, media codecs, or security software
- Malicious advertising (malvertising) on legitimate websites that redirects to download pages
- Deceptive download buttons on file-sharing and streaming sites designed to confuse users
- Email attachments disguised as invoices, shipping notifications, or business documents containing dropper scripts
- Compromised browser extensions updated with hijacker functionality after gaining user trust
- Torrent files for popular software, games, or media that include the hijacker in the package
What It Does On Your Machine
Once installed, Mementrandingswcom immediately modifies browser configurations to redirect your homepage, new tab page, and default search engine to mementrandingsw.com or related advertising domains. These changes persist even after you manually reset browser settings because the hijacker installs a browser extension or applies group policy settings that override user preferences. Every time you open your browser or attempt to search, you're redirected through a chain of advertising networks designed to generate revenue through forced impressions and clicks.
The hijacker injects advertisements into web pages you visit, displaying pop-ups, banner ads, and in-text advertisements that weren't placed by the legitimate website. These injected ads often promote questionable products, fake tech support services, potentially unwanted programs, and occasionally more serious malware. Some variants perform affiliate link substitution—silently replacing legitimate product links with versions that credit the hijacker's operators with affiliate commissions when you make purchases.
Mementrandingswcom collects extensive browsing data throughout its operation. This includes your search queries, visited URLs, clicked links, time spent on pages, and geographic location based on IP address. While the threat doesn't typically steal passwords or financial data directly, this tracking information is valuable to advertising networks and data brokers. The privacy implications are significant, as your browsing habits create a detailed profile that may be sold to third parties without your knowledge or consent.
Performance degradation is another hallmark of this hijacker. The constant redirects, injected advertisements, and background data collection consume system resources, slowing browser responsiveness and increasing page load times. Multiple browser processes may run simultaneously, RAM usage increases, and laptop battery life suffers. On older machines, the performance impact can be severe enough to interfere with normal work.
Manual Removal — Step by Step
Disconnect from the Internet
Unplug your Ethernet cable or turn off Wi-Fi to prevent the hijacker from downloading additional components or communicating with command servers. This isolation also stops real-time data collection while you work on removal.
Boot Into Safe Mode with Networking
Restart your computer and enter Safe Mode to prevent the hijacker's startup processes from loading. On Windows, hold Shift while clicking Restart, then navigate to Troubleshoot > Advanced Options > Startup Settings > Restart and select Safe Mode with Networking (option 5). On Mac, restart while holding the Shift key until you see the login screen.
Uninstall Suspicious Programs
Open Control Panel (Windows) or Applications folder (Mac) and carefully review installed programs for unfamiliar entries installed around the time your browser issues began. Look for programs with suspicious names, unknown publishers, or installation dates matching when problems started. Uninstall anything you don't recognize or didn't intentionally install.
Remove Browser Extensions
Open each affected browser and navigate to the extensions/add-ons manager (chrome://extensions/ for Chrome, about:addons for Firefox, edge://extensions/ for Edge). Remove any extensions you didn't install, especially those that appeared recently or have suspicious permissions like "Read and change all your data on the websites you visit." Disable developer mode if it's enabled, as hijackers sometimes use it to install unpacked extensions.
Reset Browser Settings
After removing extensions, reset each browser to default settings. In Chrome, go to Settings > Reset settings > Restore settings to their original defaults. Firefox: Help > More troubleshooting information > Refresh Firefox. Edge: Settings > Reset settings > Restore settings to their default values. This clears homepage overrides, search engine changes, and startup page modifications that the hijacker implemented.
Clean Registry and Policy Settings (Windows)
Press Windows+R, type "regedit", and navigate to HKEY_CURRENT_USER\Software\Policies\Google\Chrome and HKEY_LOCAL_MACHINE\SOFTWARE\Policies\Google\Chrome. Delete any Chrome, Firefox, or Microsoft\Edge policy keys you find unless you know they were set by your organization. Similarly, check HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\Main and delete any suspicious "Start Page" or "Search Page" values pointing to mementrandingsw.com or related domains.
Check Scheduled Tasks and Startup Items
Open Task Scheduler (Windows) or System Preferences > Users & Groups > Login Items (Mac) and look for tasks that run unfamiliar programs or scripts. Delete any scheduled tasks with random names, particularly those configured to run at login or at regular intervals. On Windows, also check msconfig (System Configuration) under the Startup tab for suspicious entries and disable them.
Delete Remaining Files
Navigate to %LOCALAPPDATA%, %APPDATA%, and %PROGRAMFILES% (Windows) or ~/Library/Application Support/ (Mac) and delete any folders with random names created around the time of infection. Check browser profile directories for leftover extension folders. Be cautious—when in doubt, research folder names online before deleting to avoid removing legitimate program files.
Run Malwarebytes or Similar Scanner
Download and install Malwarebytes Free (from the official malwarebytes.com site only) and perform a full system scan. The software will detect remaining components that manual removal may have missed, including registry entries, scheduled tasks, and hidden files. Quarantine all detected items and allow the program to restart your computer if prompted.
Verify Removal and Change Passwords
Reboot into normal mode, reconnect to the internet, and verify that browser behavior has returned to normal. Open your browser, confirm your homepage is correct, search for something, and verify no redirects occur. As a precaution, change passwords for important accounts (email, banking, shopping) since the hijacker may have logged your browsing activity. Use a different, known-clean device for the most sensitive password changes if possible.
Prevention
- Always use Custom/Advanced installation modes when installing free software, and carefully read each screen to uncheck bundled offers. Never click through installers using "Express" or "Recommended" options without reviewing what's being installed.
- Download software only from official sources—vendor websites, the Microsoft Store, or the Mac App Store. Avoid third-party download portals like Softonic, Download.com, or CNET Downloads, which commonly bundle PUPs with legitimate software.
- Keep browsers and operating systems updated with the latest security patches. Enable automatic updates so you don't rely on "update notifications" that might be fake prompts designed to distribute hijackers.
- Install a reputable ad blocker like uBlock Origin to reduce exposure to malicious advertisements and fake download buttons on legitimate websites. This dramatically reduces malvertising risk.
- Be skeptical of update prompts that appear while browsing. Legitimate software updates come through official updaters built into the program, not through browser pop-ups. Adobe Flash Player is discontinued; any "Flash update" is malicious.
- Review browser extensions regularly and remove anything you don't actively use or don't remember installing. Hijackers sometimes arrive as extensions that silently update with malicious functionality after installation.
- Use standard user accounts for daily computing rather than administrator accounts. This prevents software from making system-wide changes without explicit permission, adding a layer of protection against automatic hijacker installation.
- Maintain an anti-malware solution with real-time protection enabled. While not perfect, quality security software catches many PUP installations before they complete and can block connections to known hijacker domains.
Bring It In
While manual removal is possible for technically comfortable users, browser hijackers like Mementrandingswcom often leave behind persistence mechanisms that regenerate the infection even after seemingly thorough cleanup. Registry modifications, scheduled tasks with obfuscated names, and policy settings can restore the hijacker after reboot if a single component is missed. Computer Repair Roswell has specialized tools and years of experience with these exact threats—we can typically identify and remove all components in a single session, usually same-day.
We're located at 1735 Woodstock Rd in Roswell, Georgia, and we handle both PC and Mac systems. Give us a call at (770) 964-9954 to describe what you're seeing, or just bring the machine in. We'll run a comprehensive diagnostic, remove the hijacker and any other threats we find, verify your browser settings are restored, and explain what happened so you can avoid similar infections in the future. No jargon, no upselling—just straightforward repair work that gets your computer back to normal.