ForwardsMDSPru is a browser hijacker that forcibly redirects your web searches and homepage to unfamiliar search engines, typically as part of an aggressive advertising operation. Once installed—often bundled with free software downloads or disguised as a browser extension—it modifies your browser settings without permission and resists straightforward removal attempts. While not as destructive as ransomware or banking trojans, this hijacker degrades your browsing experience, exposes you to potentially malicious advertisements, and can serve as a gateway for additional unwanted programs.
The hijacker primarily targets Windows systems running Chrome, Firefox, and Edge, though Mac variants have been observed. Users typically notice unexpected search redirects, new toolbar installations they didn't authorize, and a flood of pop-up advertisements on previously clean websites. The persistence mechanisms employed by ForwardsMDSPru make it particularly frustrating for non-technical users attempting self-removal.
Threat Profile
| Attribute | Details |
|---|---|
| Threat Family | Browser Hijacker / PUP (Potentially Unwanted Program) |
| Aliases | ForwardMDSPru, Forwards-MDS-pru, MDS Forwarder |
| Platforms Affected | Windows 7/8/10/11 (all editions); limited macOS variants observed |
| First Documented | Mid-2019, with variants appearing through 2023 |
| Primary Distribution | Software bundling, fake browser updates, misleading download buttons on freeware sites |
| Persistence Methods | Browser extensions, scheduled tasks, registry Run keys, shortcut target modifications |
| Key Capabilities | Search redirection, homepage hijacking, new tab replacement, advertising injection, browsing data collection |
| File System Artifacts | AppData folders with randomized names, DLL files in browser extension directories, LNK shortcut modifications |
| Registry Modifications | HKCU\Software policies for browser control, Run keys for persistence, browser preference overrides |
| Network Behavior | Redirects through multiple intermediate domains before reaching final search engine or ad destination |
| Data Exposure Risk | Moderate—collects browsing history, search queries, potentially form data depending on variant |
| Removal Difficulty | Moderate—requires manual registry and filesystem cleanup beyond simple uninstallation |
How It Spreads
ForwardsMDSPru rarely arrives alone. The most common infection vector is software bundling, where the hijacker is packaged with legitimate-looking free software installers. Users download what they believe is a PDF converter, video player, or system optimizer, then rush through the installation wizard clicking "Next" without reading the fine print. Buried in the "Custom Installation" options—which most people skip—is the consent checkbox for installing "recommended browser enhancements" or similar vague language. By choosing the default "Express Installation," you're agreeing to the whole package.
We also see infections originating from fake update notices displayed on questionable websites. These convincing-looking pop-ups claim your Flash Player, Chrome, or Java is out of date and needs an immediate security update. The download button leads to an installer that may update nothing at all, or may update the legitimate software while simultaneously installing ForwardsMDSPru as a "bonus." This tactic exploits people's good security instincts—the desire to keep software updated—against them.
Common distribution methods include:
- Bundled freeware installers from download portals like Softonic, Download.com (in their ad-supported versions), and torrent sites offering "cracked" software
- Fake browser update warnings on streaming sites, file-sharing platforms, and adult content websites
- Malicious browser extensions disguised as productivity tools, ad blockers, or shopping assistants in unofficial extension marketplaces
- Email attachments claiming to be invoice PDFs or shipping notifications that actually contain installer scripts
- Compromised legitimate websites where attackers inject redirect code that leads to download prompts
- Social engineering on social media with links promising exclusive content, coupons, or free trials
What It Does On Your Machine
Once installed, ForwardsMDSPru immediately sets to work reconfiguring your browser environment. The first change you'll notice is your homepage and default search engine switching to an unfamiliar domain—often something ending in questionable TLDs or mimicking legitimate search engines with slight misspellings. Every new tab you open displays this hijacked page instead of your customized start page. When you type searches into the address bar, your queries route through the hijacker's servers before showing results, allowing it to log what you're searching for and insert sponsored results at the top of your search listings.
The hijacker achieves control through multiple redundant mechanisms. It may install itself as a browser extension with administrative privileges that prevent you from removing it through normal means. It modifies the target path of your browser shortcuts, appending command-line arguments that force the browser to load the hijacker's URL on startup. Registry keys are created or modified to enforce these settings at the system level, so even if you manually change your homepage in browser settings, it reverts within seconds or upon the next browser restart.
Beyond search redirection, ForwardsMDSPru injects advertisements into websites you visit. Clean news sites suddenly display banner ads in unusual positions. Pop-unders open in background tabs advertising questionable products or services. Some variants employ more aggressive monetization, opening new windows with surveys, fake virus warnings designed to scare you into purchasing useless "cleanup" software, or redirect chains that bounce you through multiple advertising networks before landing you somewhere unrelated to your intended destination. This advertising injection works by intercepting your HTTP traffic and modifying the HTML before your browser renders it—a technique that also positions the hijacker as a man-in-the-middle capable of seeing unencrypted data you transmit.
The data collection component raises privacy concerns beyond mere annoyance. ForwardsMDSPru variants typically harvest your browsing history, search queries, clicked links, and sometimes form data including email addresses entered into website fields. This information feeds into advertising profiles sold to third parties, but in some cases may be accessed by more malicious actors if the hijacker's command-and-control infrastructure is compromised. While we haven't observed ForwardsMDSPru stealing banking credentials directly, its presence indicates poor system hygiene that often correlates with additional infections that do target sensitive data.
Manual Removal — Step by Step
Disconnect from the Internet
Unplug your Ethernet cable or disable Wi-Fi. This prevents the hijacker from downloading additional components during the removal process and stops any data transmission to its command servers. It also ensures you won't accidentally click on injected ads while working.
Boot into Safe Mode with Networking
Restart your computer and press F8 repeatedly during boot (or Shift+Restart on Windows 10/11, then navigate to Troubleshoot > Advanced > Startup Settings > Restart > press 5 for Safe Mode with Networking). Safe Mode loads only essential system processes, preventing ForwardsMDSPru from launching its protection mechanisms that interfere with removal.
Uninstall Suspicious Programs
Open Control Panel > Programs and Features (or Settings > Apps on Windows 10/11). Sort by installation date and look for programs installed around the time the hijacking started. Common names include variations on "Forwards," "MDS," "BrowserHelper," or generic names like "Updater" or "PC Optimizer." Uninstall anything suspicious, but be cautious—some legitimate software shares generic names. When in doubt, search the program name online before removing.
Remove Browser Extensions
Open each installed browser and navigate to the extensions/add-ons manager (chrome://extensions/ for Chrome, about:addons for Firefox, edge://extensions/ for Edge). Look for extensions you didn't intentionally install, especially those with vague names, no ratings, or developer names that don't match the extension's supposed function. Remove them. ForwardsMDSPru often names its extension something innocuous like "Helper" or "SearchAssist."
Reset Browser Shortcuts
Right-click your browser shortcut (on desktop, taskbar, and Start menu), select Properties, and examine the Target field. It should end with the browser's .exe filename and nothing else. If you see additional URLs or switches appended after the .exe, delete everything after the closing quote mark around the exe path, click Apply, then OK. Repeat for all browser shortcuts.
Clean Registry Entries
Press Win+R, type "regedit" and press Enter. Navigate to HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Run and look for entries referencing AppData folders with GUID-style names or anything containing "forwards," "mdspru," or "update" in suspicious paths. Delete these entries. Also check HKEY_CURRENT_USER\Software\Policies for Google, Microsoft\Edge, or Mozilla subkeys that might contain homepage enforcement policies. Delete any Policies subkeys that reference the hijacker's search domain. Always export a backup before deleting registry keys.
Delete File System Remnants
Open File Explorer and navigate to C:\Users\[YourUsername]\AppData\Local. Enable viewing of hidden files (View > Show > Hidden items). Look for folders with randomized GUID-style names (long strings of numbers and letters in curly braces). Check inside these folders for executables with suspicious names. If you find the main hijacker binary identified in earlier steps, delete the entire parent folder. Repeat the search in AppData\Roaming. Empty the Recycle Bin when finished.
Remove Scheduled Tasks
Press Win+R, type "taskschd.msc" and press Enter to open Task Scheduler. Click on Task Scheduler Library and review the list for suspicious tasks, particularly those with triggers set to run at logon or daily. Look for task names containing "update," "forwards," "browser," or similar generic terms. Right-click suspicious tasks and select Delete. Check the Actions tab to see what program each task runs—if it points to AppData folders or the files you've already identified, delete it.
Run a Reputable Anti-Malware Scanner
Reconnect to the internet, download Malwarebytes (the free version works fine), and run a full system scan. Even if you've manually removed the obvious components, scanners catch remnants you might have missed—leftover registry keys, additional DLLs in system folders, or companion PUPs that arrived with the hijacker. Quarantine everything the scanner finds and follow its removal instructions.
Reset Browser Settings
After removal, open each browser's settings and perform a settings reset. In Chrome: Settings > Reset and clean up > Restore settings to original defaults. Firefox: Help > More Troubleshooting Information > Refresh Firefox. Edge: Settings > Reset settings > Restore settings to default values. This clears any lingering configuration changes the hijacker made that weren't stored in obvious extension or shortcut locations.
Change Important Passwords
If ForwardsMDSPru was present for more than a few days, change passwords for critical accounts (email, banking, shopping sites) from a known-clean device or after thorough removal verification. Browser hijackers can log form data, and you don't know if yours was transmitting credentials. Use unique, strong passwords and enable two-factor authentication where available.
Reboot and Verify
Restart your computer normally (not in Safe Mode) and test your browsers. Your homepage and search engine should remain as you set them. Open multiple new tabs, perform several searches, and browse a few familiar websites—you shouldn't see unexpected redirects, pop-ups, or injected advertisements. Monitor the system for 24-48 hours to confirm the infection hasn't returned.
Prevention
- Always choose Custom Installation when installing free software, even from sources you trust. Read every screen carefully and uncheck any boxes offering to install additional programs, browser toolbars, or change your search settings. If the installer doesn't offer a custom option or makes it deliberately confusing, consider that a red flag and find alternative software.
- Download software only from official sources—the developer's website or verified app stores. Avoid third-party download portals that repackage installers with bundled adware. When searching for software, type the official website URL directly rather than clicking the first search result, which might be a sponsored ad leading to a bundler.
- Keep your system and browsers updated through official channels. Real updates come from Windows Update, Chrome's built-in updater, Firefox's built-in updater—never from pop-up warnings on websites. If you see an update prompt on a webpage, close it and check for updates manually through the application's own settings menu.
- Install a reputable ad blocker like uBlock Origin. This prevents many malicious advertisements from displaying in the first place, eliminating a major infection vector. Ad blockers also often block the redirect scripts used by browser hijacker distribution networks.
- Review installed extensions monthly. Open your browser's extension manager once a month and remove anything you don't actively use or don't remember installing. Extension permissions creep is real—that extension you installed for one task years ago might have been sold to an advertising company and updated with new tracking capabilities.
- Use a standard user account for daily computing instead of an administrator account. Browser hijackers and PUPs that require administrative privileges to install will prompt for elevation, giving you a warning moment to reconsider. Many infections rely on users operating with admin rights all the time.
- Enable real-time protection in Windows Defender (or your preferred antivirus). Microsoft has significantly improved Defender's detection of PUPs and unwanted software in recent years. The real-time monitoring catches many bundled installers before they execute.
- Be skeptical of urgent messaging. Legitimate software doesn't demand immediate action with countdown timers, flashing red warnings, or threats that your computer is at risk right now. These pressure tactics are designed to bypass your critical thinking. When in doubt, close the tab and investigate the message's legitimacy independently.
When we remove malware at Computer Repair Roswell, it stays gone. Every service includes a 90-day warranty—if the same infection returns within three months, we'll fix it again at no charge. We don't just delete files; we find and eliminate every persistence mechanism, verify removal with multiple scanning tools, and test your system before you leave. That's the thoroughness you pay for.
Bring It In
Manual removal works when you're comfortable editing the registry, identifying suspicious processes, and troubleshooting if something goes wrong. But for many of our customers, the time and stress aren't worth the risk of missing something or accidentally breaking Windows. ForwardsMDSPru often travels with friends—additional PUPs, adware, or worse threats that piggyback on the same infection vector. A professional cleaning ensures we catch everything in one pass.
We're located in Roswell at 1520 Warsaw Road, open Monday through Friday 9 AM to 6 PM. Call ahead at (770) 892-5555 and we'll usually have you in and out the same day for an infection like this. Bring your machine by—we'll explain exactly what we find, show you how it got there, and make sure you leave with a clean system and the knowledge to avoid reinfection. That's the Computer Repair Roswell difference.