The mbook3.info.moredates.com redirect is a browser hijacker that manipulates your web browser's settings to force unwanted page redirections and display aggressive advertising. This threat typically infiltrates systems bundled with free software downloads and immediately alters browser configurations to redirect searches and homepage navigation through its own servers. While not as destructive as ransomware or data-stealing trojans, this hijacker degrades your browsing experience, exposes you to potentially malicious advertising networks, and collects your search queries and browsing habits without consent.
Users typically first notice this infection when their browser suddenly starts opening mbook3.info.moredates.com or related dating-themed landing pages instead of their intended destinations. The hijacker generates revenue for its operators by forcing traffic through affiliate advertising networks, often leading victims through multiple redirects before reaching a final destination filled with questionable dating site promotions, fake software update warnings, or other deceptive content.
Threat Profile
| Attribute | Details |
|---|---|
| Threat Type | Browser Hijacker / Redirect |
| Family | Search redirect hijackers with affiliate advertising payloads |
| Targeted Platforms | Windows (all versions), macOS; affects Chrome, Firefox, Edge, Safari |
| Distribution Method | Software bundling, fake installers, malicious browser extensions, deceptive advertising |
| Primary Domain | mbook3.info.moredates.com (with numerous variant subdomains) |
| Monetization | Pay-per-click advertising, affiliate commissions, search result manipulation |
| Data Collection | Search queries, browsing history, clicked links, IP address, system information |
| Browser Modifications | Homepage, default search engine, new tab page, browser shortcuts, extension installation |
| Persistence Mechanism | Browser extensions, scheduled tasks, registry modifications, browser policy enforcement |
| Associated Threats | Often delivered alongside adware, potentially unwanted programs (PUPs), and additional browser hijackers |
| Removal Difficulty | Moderate — resists simple browser resets and reinstalls components if not fully removed |
| Risk Level | Medium — primarily nuisance and privacy invasion, but gateway to more serious infections |
How It Spreads
The mbook3.info.moredates.com hijacker spreads primarily through deceptive software bundling, where it's packaged alongside legitimate-looking free applications. When users download video converters, PDF creators, download managers, or other utilities from third-party software hosting sites, the installer often includes optional (but pre-selected) components that include this hijacker. The installation wizard uses dark patterns — design tricks that manipulate users into accepting unwanted software — such as misleading button labels, tiny checkboxes in walls of text, or "Express" installation options that skip disclosure screens entirely.
Once the initial infection occurs, this hijacker proves particularly persistent because it modifies multiple browser components simultaneously. It doesn't just change your homepage — it installs browser extensions with administrative permissions, modifies browser policy files that prevent you from changing settings back, and sometimes creates scheduled tasks that reinfect your browser if you manually remove the extension. This multi-layered approach means that simply uninstalling a suspicious browser extension or resetting your browser settings often fails to fully eliminate the threat.
Common distribution vectors include:
- Bundled freeware and shareware — Download managers, media players, system optimizers, and other utilities from sites like Softonic, Download.com (in its less-curated sections), or torrent sites
- Fake software update notifications — Pop-ups claiming your Flash Player, Java, or media codec needs updating, leading to installers that contain the hijacker
- Malicious browser extensions — Extensions promoted through search ads or social media that promise features like "enhanced search," "coupon finding," or "video downloading"
- Compromised websites and malvertising — Legitimate websites infected with malicious advertising that automatically triggers download prompts or opens deceptive landing pages
- Email attachments and phishing links — Less common for this specific hijacker, but sometimes distributed through spam campaigns disguised as software notifications or security alerts
- Pirated software and crack tools — Keygen programs and software cracks frequently bundle multiple types of unwanted software including browser hijackers
What It Does On Your Machine
Once installed, the mbook3.info.moredates.com hijacker takes control of your web browser's navigation by intercepting search queries and URL entries. When you type a web address into your address bar or search for something, the hijacker redirects your request through its own servers first. This allows it to log your search terms, inject advertising into the results, and redirect you to partner sites that generate revenue through affiliate commissions. You might search for "weather forecast" and find yourself first landing on mbook3.info.moredates.com, then bouncing through several intermediate redirect domains, before finally reaching a search results page polluted with ads for dating services completely unrelated to your query.
The hijacker modifies your browser configuration at multiple levels to maintain persistence. It changes obvious settings like your homepage and default search engine, but it also installs browser extensions that run with elevated permissions, allowing them to read and modify data on all websites you visit. These extensions monitor your browsing activity continuously, tracking which sites you visit, what you search for, and which links you click. This behavioral data has value to advertising networks and data brokers, creating a privacy violation beyond the simple annoyance of unwanted redirects.
On the system level, this hijacker creates artifacts designed to survive basic removal attempts. It may install Windows scheduled tasks that reinstall the browser extension at regular intervals, or create registry entries that enforce specific browser policies preventing you from changing your homepage or search provider. The hijacker often arrives with companion adware that displays pop-up advertisements, injects sponsored links into legitimate websites, and opens new browser tabs advertising dating services, questionable browser extensions, or fake security software. This entire ecosystem of unwanted software works together to monetize your computer while degrading its performance and your security posture.
Manual Removal — Step by Step
Disconnect and Document
Disconnect your computer from the internet to prevent the hijacker from communicating with its command servers or downloading additional components. Take screenshots or write down any suspicious browser extensions, recently installed programs (check Programs and Features sorted by install date), and any unusual browser behavior patterns. This documentation helps ensure you remove all related components.
Uninstall Suspicious Programs
Open Control Panel > Programs and Features (or Settings > Apps on Windows 10/11) and sort by installation date. Look for programs installed around the time your browser problems started, especially anything with generic names like "Browser Assistant," "Search Manager," "Web Companion," or dating-related terms. Uninstall these programs, but be aware this step alone won't complete the removal since browser-level modifications will remain.
Remove Malicious Browser Extensions
Open each installed browser's extension management page (chrome://extensions/ for Chrome, about:addons for Firefox, edge://extensions/ for Edge). Enable "Developer mode" if available to see more details. Remove any extensions you don't recognize or didn't deliberately install, particularly those with vague names, no ratings, or permissions to "read and change all your data on websites you visit." Some hijackers install multiple extensions as backup — remove anything suspicious even if you're not certain.
Reset Browser Settings
In each browser, access the settings reset option: Chrome (Settings > Reset settings > Restore settings to original defaults), Firefox (Help > More Troubleshooting Information > Refresh Firefox), Edge (Settings > Reset settings > Restore settings to their default values). This removes the hijacker's configuration changes but preserves your bookmarks and saved passwords. However, reset alone often fails because hijackers reinstall their settings via scheduled tasks or browser policy files.
Check and Remove Scheduled Tasks
Press Win+R, type taskschd.msc, and press Enter to open Task Scheduler. Review the Task Scheduler Library for suspicious entries, particularly those with random names, no description, or actions that run executable files from %LOCALAPPDATA%, %APPDATA%, or %TEMP% directories. Delete any tasks related to browser management, search helpers, or anything that references the hijacker's program folder. Check the Actions tab for each suspicious task to identify associated files before deletion.
Clean Registry Policies
Press Win+R, type regedit, and press Enter (accept the UAC prompt). Navigate to HKEY_CURRENT_USER\Software\Policies\Google\Chrome and HKEY_LOCAL_MACHINE\SOFTWARE\Policies\Google\Chrome (or similar paths for Firefox/Edge). If these policy keys exist and contain homepage or search-related entries you didn't create, delete the entire Chrome (or browser-specific) policy key. Also check HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Run for any suspicious auto-start entries referencing unknown executables.
Delete Associated Files and Folders
Using File Explorer, navigate to %LOCALAPPDATA%, %APPDATA%, and %PROGRAMFILES(X86)% (paste these directly into the address bar). Look for folders with random names, generic terms like "BrowserHelper" or "SearchAssist," or anything referencing moredates, mbook, or similar terms. Delete these entire folders. Also check your Desktop, Downloads folder, and %TEMP% directory for any related installers or executables you may have accidentally downloaded.
Run Malwarebytes and Full Antivirus Scan
Reconnect to the internet, download Malwarebytes (the free version works fine), and run a full scan. Browser hijackers often install alongside other potentially unwanted programs that manual removal misses. After Malwarebytes completes and removes any detections, run a full scan with your primary antivirus software as a second verification layer. Some hijackers install rootkit components or system drivers that require specialized scanners.
Verify Browser Shortcuts
Some hijackers modify browser shortcut properties to include the hijacker URL as a launch parameter. Right-click your browser shortcuts (desktop, taskbar, Start menu), select Properties, and examine the Target field. It should end with the browser's .exe filename with no additional URLs or parameters after it. If you see a web address appended, remove everything after the closing quote mark around the .exe path, then click OK to save.
Test and Change Passwords
Restart your computer and test your browsers. Open each one, verify your homepage and search engine are now what you intended, and perform several searches to confirm redirects have stopped. If the hijacker was present for more than a few days, change passwords for important accounts (email, banking, social media) from a known-clean device first, since the hijacker's browser extensions could have logged keystrokes or stolen session cookies from these sites.
Prevention
- Download software only from official sources — Get programs directly from the developer's website or Microsoft Store, not from third-party download sites that rebundle installers with unwanted extras. Even reputable download aggregators sometimes wrap legitimate software in adware-laden installers.
- Always choose Custom/Advanced installation — Never click "Express Install" or "Recommended Settings" when installing free software. The Custom option reveals bundled software offers, allowing you to uncheck unwanted components. Read each screen carefully even if it's tedious.
- Keep a reputable ad blocker installed — Extensions like uBlock Origin prevent many malvertising attacks that distribute hijackers through compromised advertising networks on legitimate websites. This single layer stops numerous infection vectors before they reach your system.
- Maintain updated security software — Run Windows Defender at minimum (it's actually quite good now) or a reputable third-party antivirus, and keep it updated. Enable real-time protection to catch hijacker installers before they execute. Schedule weekly full scans to catch anything that slips through.
- Review installed extensions monthly — Set a calendar reminder to audit your browser extensions once per month. Remove anything you don't actively use or don't remember installing. Hijackers sometimes install extensions that lie dormant initially, activating days or weeks later to avoid detection.
- Disable unnecessary browser features — Turn off Chrome's "Continue running background apps when closed" setting and similar features in other browsers. This prevents extensions from operating when you think your browser is closed, reducing hijacker persistence opportunities.
- Ignore unexpected update notifications — Legitimate software updates through the application itself or Windows Update, not through random pop-ups while browsing. If a website claims you need to update Flash, Java, or codecs, close the page — Flash is dead anyway, and Java/codecs update through their own mechanisms.
- Use a standard user account for daily activities — Run Windows with a standard user account rather than an administrator account for everyday browsing and work. This limits malware's ability to install system-level persistence mechanisms, making infections easier to remove if they occur.
Bring It In
Browser hijackers like mbook3.info.moredates.com seem minor until you realize they're tracking every search you make and exposing you to advertising networks that distribute more dangerous malware. The manual removal process above works, but it requires comfort with Task Scheduler, Registry Editor, and tracking down scattered filesystem artifacts. If any step feels uncertain or if your redirects persist after attempting removal, you're dealing with a more sophisticated infection that needs professional attention.
Bring your computer to Computer Repair Roswell at 1322 Hembree Road in Roswell, or call us at (770) 856-1690 to discuss your situation. We'll remove the hijacker completely, verify no additional malware arrived with it, check for any browser-based credential theft, and configure your system to prevent reinfection. Most hijacker removals take an hour or two, and we'll explain exactly what was infected and how it got there so you can avoid the same trap in the future. Don't let this nuisance degrade into a serious security problem — let's get your browser back under your control today.