Mcpuwpush.com is a browser hijacker and potentially unwanted program (PUP) that redirects your web traffic through a network of advertising servers, often delivering intrusive pop-ups, fake security alerts, and misleading download prompts. Users typically encounter this threat after installing bundled freeware or clicking deceptive "Update Required" notices on questionable websites. While not a traditional virus that replicates itself, this hijacker modifies browser settings without consent and can expose you to more dangerous threats through the sites it pushes you toward.
The threat operates by manipulating browser shortcuts, search engine defaults, and homepage settings—sometimes across multiple browsers on the same machine. Once embedded, it generates revenue for its operators through forced ad impressions and affiliate traffic redirection. Beyond the annoyance factor, mcpuwpush.com poses real risks: the sites it redirects to may host exploit kits, phishing pages, or malicious downloads that can compromise your system further.
Threat Profile
| Attribute | Details |
|---|---|
| Threat Type | Browser Hijacker, Potentially Unwanted Program (PUP), Adware |
| Family | Push notification abuse / browser redirect family |
| Aliases | Mcpuwpush, Mcpu-wpush, PushNotification.Mcpuwpush, BrowserModifier:Win32/Mcpuwpush |
| Affected Platforms | Windows 7/8/10/11; macOS (Safari, Chrome); targets Chrome, Firefox, Edge, Safari browsers |
| Distribution Methods | Software bundling, fake update prompts, malvertising, torrent/crack downloads, "Allow Notifications" clickbait |
| Persistence Mechanisms | Browser extension installation, shortcut modification (target field appends URLs), scheduled tasks, registry Run keys (Windows), LaunchAgents (macOS) |
| Primary Capabilities | Homepage/search engine hijacking, forced redirects, notification spam, browser setting lockdown, ad injection, affiliate tracking |
| Typical Artifacts | Modified browser shortcuts with appended URLs, unwanted extensions labeled "Helper" or similar, registry entries in HKCU\Software\Microsoft\Windows\CurrentVersion\Run, browser profile preference files altered |
| Network Behavior | Outbound connections to mcpuwpush.com and rotating ad-server domains; HTTP redirects through multiple intermediaries; may download additional payloads |
| Data at Risk | Browsing history, search queries, clicked links; sites visited may capture credentials through phishing |
| Removal Difficulty | Moderate—re-infects if all persistence points not removed; may reinstall extensions automatically |
| Associated Risks | Exposure to exploit kits, tech-support scams, fake antivirus downloads, credential theft via phishing redirects |
How It Spreads
Mcpuwpush.com rarely arrives alone. The most common infection vector is software bundling, where legitimate-looking free applications—video converters, PDF tools, download managers—conceal the hijacker in their installation wizards. During setup, pre-checked boxes buried in "Custom" or "Advanced" options grant permission to install "recommended" browser extensions or change your homepage. Many users click through on "Express" install mode and never see these disclosures. The hijacker's installer may be packaged by third-party download portals that monetize free software through these bundled offers.
Another major distribution method exploits browser push notification permissions. You visit a compromised or deliberately deceptive website that displays a fake error message—"Click Allow to verify you're not a robot," "Your Flash Player is out of date—click Allow to update," or simply a video player that won't start until you click Allow. Granting notification permission lets the site (mcpuwpush.com or its partners) bombard you with spam notifications even when your browser is closed. These notifications often mimic system alerts or antivirus warnings to trick you into clicking, which then opens more malicious sites.
Additional distribution vectors for this family include:
- Malvertising campaigns: Compromised or low-quality ad networks serve pop-unders and redirects that land on mcpuwpush.com, which attempts automatic extension installation or social-engineering tricks
- Torrent and crack sites: Pirated software downloads, key generators, and "cracks" frequently bundle browser hijackers as part of the package
- Fake update pages: Redirects claiming your browser, Flash, or video codec is outdated, offering a download that contains the hijacker instead of (or in addition to) the promised update
- Email attachments and links: Phishing emails with attachments or links that lead to trojan-downloaders, which in turn fetch browser hijackers as secondary payloads
- Compromised websites: Legitimate sites with outdated CMS software can be injected with scripts that redirect visitors to mcpuwpush.com or related landing pages
What It Does On Your Machine
Once installed, mcpuwpush.com immediately modifies your browser configuration to serve its monetization goals. The hijacker typically changes your default search engine to a custom search page that routes queries through affiliated ad networks, injecting sponsored results at the top of every search. Your homepage and new-tab page are redirected to mcpuwpush.com or a series of intermediary domains that display ads, fake security warnings, or "survey" pages designed to harvest personal information. Each click and impression generates micropayments for the operators through pay-per-click and affiliate schemes.
The technical implementation varies by browser but follows common patterns. On Chrome and Edge, the hijacker may install an extension with broad permissions to "read and change all your data on all websites" and "manage your downloads." Even if you remove the extension manually, a scheduled task or startup entry automatically reinstalls it at the next reboot. On Firefox, the hijacker modifies the user.js or prefs.js configuration files in your profile directory, setting locked preferences that override your attempts to change settings through the browser interface. Safari on macOS faces similar profile-level changes, plus potential LaunchAgent plists that reload the hijacker.
Browser shortcuts are a favored persistence mechanism. The hijacker appends a URL to the Target field of your browser shortcut—for example, chrome.exe "http://mcpuwpush.com/redirect?xyz". Every time you launch the browser via desktop or taskbar icon, it opens to that URL, and the site's JavaScript immediately modifies settings or opens additional tabs. Cleaning the infection requires editing every affected shortcut, including those in the Start Menu, Desktop, Quick Launch, and Taskbar pinned items.
Beyond browser hijacking, mcpuwpush.com serves as a distribution point for additional threats. The redirect chain often lands users on pages hosting exploit kits that probe for unpatched browser or plugin vulnerabilities. Tech-support scam pages are common destinations, displaying fake "Windows Defender Alert" pop-ups with phone numbers that connect to offshore call centers. The hijacker may also trigger downloads of fake antivirus tools (rogueware) or bundle additional PUPs that monitor your browsing for targeted advertising. Some variants in this family have been observed dropping cryptocurrency miners or information-stealers as tertiary payloads, though this is less common with the mcpuwpush specifically.
Manual Removal — Step by Step
Disconnect and Document
Unplug your Ethernet cable or disable Wi-Fi to prevent the hijacker from downloading additional components or communicating with command servers. Take note of any suspicious symptoms—specific redirect URLs, pop-up text, or extension names—as these details help identify all related components. If the hijacker has been present for a while, note when you first saw the behavior to assess what passwords or accounts may have been exposed.
Boot Into Safe Mode with Networking
Restart your computer into Safe Mode to prevent the hijacker's startup entries from loading. On Windows 10/11, hold Shift while clicking Restart, then navigate Troubleshoot → Advanced Options → Startup Settings → Restart and press F5 when the menu appears. On Windows 7/8, tap F8 during boot before the Windows logo appears. On macOS, restart and immediately hold Shift until you see the login screen. Safe Mode loads only essential system drivers, disabling most malware persistence mechanisms.
Uninstall Suspicious Programs
Open Settings → Apps (or Control Panel → Programs and Features on older Windows) and sort by Install Date. Remove any programs you don't recognize installed around the time the hijacking started—look for names like "Browser Helper," "SearchAssist," generic company names, or anything with "mcpu" in the title. On Mac, open Finder → Applications and drag suspicious apps to the Trash, then empty it. Some hijackers install "uninstallers" that actually reinstall the threat, so prefer the OS's native removal method.
Remove Persistence: Registry and Scheduled Tasks
Press Win+R, type taskschd.msc, and press Enter to open Task Scheduler. Expand Task Scheduler Library and look for tasks with suspicious names (generic strings, "Update," "Helper") that run at logon or periodically—check the Actions tab to see what executable they launch. Delete any that point to folders in %LOCALAPPDATA% or %APPDATA% with random names. Next, press Win+R, type regedit, navigate to HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Run, and delete any entries launching unknown executables. On Mac, check ~/Library/LaunchAgents and /Library/LaunchAgents for .plist files with suspicious labels.
Clean Browser Shortcuts
Right-click every browser shortcut (Desktop, Taskbar, Start Menu) and select Properties. In the Target field, ensure it points only to the browser executable with no URLs appended after it—for example, "C:\Program Files\Google\Chrome\Application\chrome.exe" and nothing more. If you see any web address after the .exe, delete everything after the closing quote. Click OK to save, then unpin and re-pin Taskbar shortcuts to ensure the change takes effect. Repeat for all browsers you use.
Remove Browser Extensions and Reset Settings
Open each affected browser and navigate to its extensions page (chrome://extensions, about:addons for Firefox, edge://extensions, or Safari → Preferences → Extensions). Remove any extensions you didn't intentionally install, especially those with vague names or permissions to "read and change all data." Then reset browser settings: in Chrome/Edge, go to Settings → Reset settings → Restore settings to their original defaults; in Firefox, type about:support, click Refresh Firefox; in Safari, go to Preferences and reset homepage/search engine manually, then clear history and website data.
Delete Malicious Files and Folders
Press Win+R, type %LOCALAPPDATA%, and press Enter. Look for folders with random GUID names or generic labels like "BrowserHelper" that contain executables. Delete these entire folders. Repeat for %APPDATA% and %TEMP%. Use Shift+Delete to bypass the Recycle Bin for immediate removal. If Windows prevents deletion (file in use), reboot into Safe Mode again or use a tool like Unlocker. On Mac, check ~/Library/Application Support and ~/Library/Caches for suspicious folders.
Revoke Notification Permissions
In Chrome/Edge, go to Settings → Privacy and security → Site Settings → Notifications, and remove mcpuwpush.com and any other unknown domains from the Allow list. In Firefox, go to Settings → Privacy & Security → Permissions → Notifications → Settings, and remove suspicious entries. In Safari, go to Preferences → Websites → Notifications and revoke permissions for unknown sites. This stops the spam even if residual components remain.
Scan with Malwarebytes and Your Antivirus
Download Malwarebytes (free trial includes cleanup) from malwarebytes.com directly—don't search for it, as hijacked search results may offer fake versions. Reconnect to the internet briefly if needed, download, disconnect again, then install and run a full scan. Quarantine everything it finds. Follow up with a full scan from your existing antivirus (Windows Defender is fine if it's up to date). These tools catch persistence mechanisms and related PUPs you might have missed manually.
Change Passwords and Reboot
If the hijacker was present for more than a few hours and you entered passwords during that time—especially for email, banking, or social media—change those passwords from a known-clean device or after the full cleanup. Browser hijackers themselves don't typically include keyloggers, but the sites they redirect to might, and any additional payloads they dropped could be stealing credentials. Reboot normally (not Safe Mode) and verify that browsers open to your chosen homepage without redirects, extensions stay removed, and no pop-ups appear.
Prevention
- Always choose Custom installation: When installing any free software, select the Advanced or Custom installation mode and read every screen. Uncheck any boxes offering to install extra toolbars, change your homepage, or add browser extensions. If the installer doesn't offer a Custom mode or won't let you decline add-ons, exit and find the software elsewhere—it's not worth the risk.
- Download only from official sources: Get software directly from the developer's website or trusted sources like the Microsoft Store, Mac App Store, or reputable repositories. Third-party download portals often repackage installers with bundled PUPs to monetize distribution. Avoid torrent sites and crack/keygen downloads entirely—they're the highest-risk sources.
- Deny notification requests by default: When a website asks to "Show notifications," click Block unless you have a specific, legitimate reason to allow it (like getting message alerts from a web app you actually use). Never click Allow in response to "verify you're human," fake errors, or video-player prompts—these are social-engineering traps.
- Keep browsers and plugins updated: Enable automatic updates for your browser, and remove or disable plugins you don't need (especially Flash, Java, and Silverlight, which are obsolete and dangerous). Exploit kits delivered through redirect chains target outdated browsers, so staying current closes those infection routes.
- Use an ad blocker and script blocker: Install uBlock Origin (not just "uBlock") and consider NoScript or uMatrix for advanced users. These tools prevent malicious ads from loading and block drive-by redirect scripts, significantly reducing your exposure to hijacker landing pages.
- Maintain a reputable antivirus and anti-malware setup: Windows Defender is adequate if kept updated and supplemented with periodic Malwarebytes scans. On Mac, consider Malwarebytes for Mac since macOS's built-in protections are less robust against PUPs. Don't install free "registry cleaner" or "PC optimizer" tools—they're often PUPs themselves.
- Create a standard user account for daily use: Don't run as Administrator (Windows) or with admin privileges (Mac) for everyday browsing. Many hijacker installers require admin rights to modify system-level persistence points; a standard account forces a prompt you can decline.
- Back up your browser profile periodically: On Windows, copy
%LOCALAPPDATA%\Google\Chrome\User Data(or equivalent for other browsers) to external storage when your browser is clean. If hijacked later, you can restore bookmarks, passwords, and settings without starting from scratch. Use the browser's built-in sync carefully—if one device is infected, it may sync malicious settings to others.
Bring It In
If the manual steps above feel overwhelming, or if you've tried them and the redirects keep coming back, you're not alone—browser hijackers are deliberately designed to resist casual removal. At Computer Repair Roswell, we see mcpuwpush.com and its variants regularly, and we have the tools and process to eliminate every trace in a single visit. We'll audit your system for related threats you might not even know are present, verify your browsers are truly clean, and harden your settings against reinfection—all while you wait or as a same-day drop-off.
Located right here in Roswell, Georgia, we're your local experts for PC and Mac malware removal, with transparent pricing and no upselling. Call us at (770) 594-0202 to describe your symptoms and get an estimate, or stop by our shop at your convenience—no appointment needed for diagnostics. We'll have you back to safe, fast browsing faster than you can say "browser hijacker," and we'll show you exactly what we found and fixed so you know how to avoid it next time.