Getting redirected when visiting mediafire download pages

ThisIsMadness91

New member
Member
VIP
Local time
5:08 PM
Messages
204
The last two times I have visited a mediafire download page, I have been redirected to a dodgy page asking me update programs such as Firefox and Java (even though I uninstalled Java over a year ago). The two domains I've seen for the page are lpmxp2.com and updowntot.com. I didn't stick around long enough to get a screenshot, but the two pages appeared to be identical with the exception of the alleged program update displayed. The first time this happened was three days ago, and the redirect only happened once that day. I visited mediafire again today, and the same thing happened.

I can't find any recent discussion on this anywhere so it doesn't appear to be a recent known problem. Any help would be appreciated.

Update: I ran a scan with AdwCleaner, and it found and removed this key from my registry: HKCU\Software\AppDataLow\Software. I'm going to run a Malwarebytes scan now.
 

My Computer My Computer

At a glance

Windows 7 Home Premium 64bit (Service Pack 1)Intel Core i76.00 GBNVIDIA GeForce GTX 550 Ti
Computer type
PC/Desktop
Computer Manufacturer/Model Number
Packard Bell ipower G5800
OS
Windows 7 Home Premium 64bit (Service Pack 1)
CPU
Intel Core i7
Memory
6.00 GB
Graphics Card(s)
NVIDIA GeForce GTX 550 Ti
Antivirus
Avira Free Antivirus
Browser
Firefox
ThisIsMadness91,

Is there anything else added to this:

HKCU\Software\AppDataLow\Software
 

My Computer My Computer

At a glance

Windows 7 Home Premium
Computer type
PC/Desktop
Computer Manufacturer/Model Number
An ol' eMachines
OS
Windows 7 Home Premium
Internet Speed
Fine for me...I'm retired!
I couldn't find anything. The only other detections were my homepages for Internet Explorer and Firefox (GMail for both, which I set myself). I can upload the logs from before and after running the cleaner if it helps.

Also, I forgot to mention that Malwarebytes didn't detect anything (it's the free version, if that makes any difference).

Update: It also happens on zippyshare. The domain I saw this time was lp.sharelive.net.
 
Last edited:

My Computer My Computer

At a glance

Windows 7 Home Premium 64bit (Service Pack 1)Intel Core i76.00 GBNVIDIA GeForce GTX 550 Ti
Computer type
PC/Desktop
Computer Manufacturer/Model Number
Packard Bell ipower G5800
OS
Windows 7 Home Premium 64bit (Service Pack 1)
CPU
Intel Core i7
Memory
6.00 GB
Graphics Card(s)
NVIDIA GeForce GTX 550 Ti
Antivirus
Avira Free Antivirus
Browser
Firefox
Try the following Microsoft fix it on this article,

How can I reset the Hosts file back to the default?

Then I suggest the following just to see if anything turns up:

1.) Download AdwCleaner by Xplode and save to your Desktop.

  • Double click on AdwCleaner.exe to run the tool

  • Vista/Windows 7/8 users right-click and select Run As Administrator.
  • Click on the Scan button.
  • AdwCleaner will begin...be patient as the scan may take some time to complete.
  • After the scan has finished, click on the Report button...a logfile (AdwCleaner[R#].txt) will open in Notepad for review (where the largest value of # represents the most recent report).
  • The contents of the log file may be confusing. Unless you see a program name that you know should not be removed, don't worry about it. If you see an entry you want to keep, let me know about it.
  • Upload the contents of that logfile in your next reply using the paper clip on the reply box.
  • A copy of all logfiles are saved in the C:\AdwCleaner folder which was created when running the tool.

2.) Using AdwCleaner v3: Scan & Clean:

Double click on AdwCleaner.exe to run the tool again.
Click on the Scan button.
AdwCleaner will begin to scan your computer like it did before.
After the scan has finished...

This time click on the Clean button.
Press OK when asked to close all programs and follow the onscreen prompts.
Press OK again to allow AdwCleaner to restart the computer and complete the removal process.
After rebooting, a logfile report (AdwCleaner[S#].txt) will open automatically (where the largest value of # represents the most recent report).
Upload the contents of that logfile in your next reply using the paper clip on the reply box.

Junkware Removal tool:


3.) Please download Junkware Removal Tool to your desktop.



  • Shutdown your antivirus to avoid any conflicts.
  • Right click over JRT.exe and select Run as administrator on Windows Vista or Windows 7, double-click on XP.
  • The tool will open and start scanning your system.
  • Please be patient as this can take a while to complete.
  • On completion, a log (JRT.txt) is saved to your desktop and will automatically open.
  • Upload the contents of that logfile in your next reply using the paper clip on the reply box.
  • When completed make sure to re-enable your antivirus
 

My Computer My Computer

At a glance

Windows 10 ProAMD Ryzen 5 2400G Processor with Radeon RX Ve...G.SKILL Ripjaws V Series 16GB (2 x 8GB) 288-P...2047MB NVIDIA GeForce GTX 1060 6GB (EVGA)
Computer type
PC/Desktop
Computer Manufacturer/Model Number
Custom Built
OS
Windows 10 Pro
CPU
AMD Ryzen 5 2400G Processor with Radeon RX Vega 11 Graphics
Motherboard
ASRock X470 Master SLI/AC AM4 AMD Promontory X470 SATA 6Gb/s
Memory
G.SKILL Ripjaws V Series 16GB (2 x 8GB) 288-Pin DDR4 SDRAM D
Graphics Card(s)
2047MB NVIDIA GeForce GTX 1060 6GB (EVGA)
Sound Card
Motherboard Built in
Monitor(s) Displays
Acer R240HY bidx 23.8-Inch IPS HDMI DVI VGA (1920 x 1080) Wi
Screen Resolution
1920 x 1080
Hard Drives
1TB Sandisk SSD PLUS (Main drive)
500 GB Seagate 7200 RPM (Games)
500 GB Western Digital 7200 RPM (Virtual Machines)
PSU
CORSAIR TX Series TX650M 650W 80+ Gold Modular Power Supply
Case
CORSAIR CARBIDE SPEC-02 Mid-Tower Gaming Case, Red LED Fan
Cooling
220mm, two 120mm, and four 60mm fans
Keyboard
Wired Dell keyboard
Mouse
Wireless Logitech mouse
Internet Speed
250mb down, 30mb up
Antivirus
Panda Cloud Antivirus
Browser
Chrome-ish x64
Other Info
Your awesome for reading this.
When resetting the hosts file, would it be better to use the "fix it for me" method or the "let me fix it myself" method?
 

My Computer My Computer

At a glance

Windows 7 Home Premium 64bit (Service Pack 1)Intel Core i76.00 GBNVIDIA GeForce GTX 550 Ti
Computer type
PC/Desktop
Computer Manufacturer/Model Number
Packard Bell ipower G5800
OS
Windows 7 Home Premium 64bit (Service Pack 1)
CPU
Intel Core i7
Memory
6.00 GB
Graphics Card(s)
NVIDIA GeForce GTX 550 Ti
Antivirus
Avira Free Antivirus
Browser
Firefox
I would use the fix it for me.
 

My Computer My Computer

At a glance

Windows 10 ProAMD Ryzen 5 2400G Processor with Radeon RX Ve...G.SKILL Ripjaws V Series 16GB (2 x 8GB) 288-P...2047MB NVIDIA GeForce GTX 1060 6GB (EVGA)
Computer type
PC/Desktop
Computer Manufacturer/Model Number
Custom Built
OS
Windows 10 Pro
CPU
AMD Ryzen 5 2400G Processor with Radeon RX Vega 11 Graphics
Motherboard
ASRock X470 Master SLI/AC AM4 AMD Promontory X470 SATA 6Gb/s
Memory
G.SKILL Ripjaws V Series 16GB (2 x 8GB) 288-Pin DDR4 SDRAM D
Graphics Card(s)
2047MB NVIDIA GeForce GTX 1060 6GB (EVGA)
Sound Card
Motherboard Built in
Monitor(s) Displays
Acer R240HY bidx 23.8-Inch IPS HDMI DVI VGA (1920 x 1080) Wi
Screen Resolution
1920 x 1080
Hard Drives
1TB Sandisk SSD PLUS (Main drive)
500 GB Seagate 7200 RPM (Games)
500 GB Western Digital 7200 RPM (Virtual Machines)
PSU
CORSAIR TX Series TX650M 650W 80+ Gold Modular Power Supply
Case
CORSAIR CARBIDE SPEC-02 Mid-Tower Gaming Case, Red LED Fan
Cooling
220mm, two 120mm, and four 60mm fans
Keyboard
Wired Dell keyboard
Mouse
Wireless Logitech mouse
Internet Speed
250mb down, 30mb up
Antivirus
Panda Cloud Antivirus
Browser
Chrome-ish x64
Other Info
Your awesome for reading this.
Here are the logs for AdwCleaner and JRT. I didn't use AdwCleaner's cleaner because it didn't detect anything apart from the homepages I'd set. Unfortunately, I forgot to disable my anti-virus when running the latter. Should I run it again with the AV disabled?
 

Attachments

My Computer My Computer

At a glance

Windows 7 Home Premium 64bit (Service Pack 1)Intel Core i76.00 GBNVIDIA GeForce GTX 550 Ti
Computer type
PC/Desktop
Computer Manufacturer/Model Number
Packard Bell ipower G5800
OS
Windows 7 Home Premium 64bit (Service Pack 1)
CPU
Intel Core i7
Memory
6.00 GB
Graphics Card(s)
NVIDIA GeForce GTX 550 Ti
Antivirus
Avira Free Antivirus
Browser
Firefox
Logs look fine, and do not worry about turning off the av. We just have that in there in case for some reason the AV is being not smart (FP)and calling it a virus.

Are you still having the redirect issues after repairing the host file? I have a lot more steps we can try if that is the case.
 

My Computer My Computer

At a glance

Windows 10 ProAMD Ryzen 5 2400G Processor with Radeon RX Ve...G.SKILL Ripjaws V Series 16GB (2 x 8GB) 288-P...2047MB NVIDIA GeForce GTX 1060 6GB (EVGA)
Computer type
PC/Desktop
Computer Manufacturer/Model Number
Custom Built
OS
Windows 10 Pro
CPU
AMD Ryzen 5 2400G Processor with Radeon RX Vega 11 Graphics
Motherboard
ASRock X470 Master SLI/AC AM4 AMD Promontory X470 SATA 6Gb/s
Memory
G.SKILL Ripjaws V Series 16GB (2 x 8GB) 288-Pin DDR4 SDRAM D
Graphics Card(s)
2047MB NVIDIA GeForce GTX 1060 6GB (EVGA)
Sound Card
Motherboard Built in
Monitor(s) Displays
Acer R240HY bidx 23.8-Inch IPS HDMI DVI VGA (1920 x 1080) Wi
Screen Resolution
1920 x 1080
Hard Drives
1TB Sandisk SSD PLUS (Main drive)
500 GB Seagate 7200 RPM (Games)
500 GB Western Digital 7200 RPM (Virtual Machines)
PSU
CORSAIR TX Series TX650M 650W 80+ Gold Modular Power Supply
Case
CORSAIR CARBIDE SPEC-02 Mid-Tower Gaming Case, Red LED Fan
Cooling
220mm, two 120mm, and four 60mm fans
Keyboard
Wired Dell keyboard
Mouse
Wireless Logitech mouse
Internet Speed
250mb down, 30mb up
Antivirus
Panda Cloud Antivirus
Browser
Chrome-ish x64
Other Info
Your awesome for reading this.
Is this happening on any other browsers of yours?
 

My Computer My Computer

At a glance

Windows 8 Pro x64i7 3820 @ 4.68GHzF3-12800CL9D-8GBXL (32GB)GTX 480 SLI
Computer type
PC/Desktop
OS
Windows 8 Pro x64
CPU
i7 3820 @ 4.68GHz
Motherboard
ASUS Rampage IV Extreme RoG BF3
Memory
F3-12800CL9D-8GBXL (32GB)
Graphics Card(s)
GTX 480 SLI
Sound Card
Auzentech X-Fi HomeTheater HD
Monitor(s) Displays
Sony 32V5500
Screen Resolution
1920 x 1080
Hard Drives
LSI MR9260-4i (RAID10):
Toshiba DT01ACA300 x 4
iaStorA:
OCZ Vertex Enterprise 120GB
ST3500320AS 500GB
Intel 520 Series 120GB
PSU
OCZ ZX 1250W
Case
HAF X
Cooling
H80
Keyboard
Cyborg V.7
Mouse
Razer Lachesis 3.5G 5600dpi
Internet Speed
23296kbps ds / 812kbps us ADSL2+
Browser
Mozilla/5.0 (Windows NT 6.3; Win64; x64; rv:32.0) Gecko/2010
Other Info
AverMedia C127 Game Broadcaster HD
Sounds like a typical warez site scam. You go to a site offering 'free' stuff, click the link, and get re-directed to malware. This is how the warez sites make their money. Sleep with dogs, get fleas etc. Mediafire hosts mainly copyright infringing content - there's the clue. This ain't a computer problem, it's an illegal download problem, and the op is asking for help to do it.
 

My Computer My Computer

At a glance

Windows 7 pro x64 SP1Intel i7-2600k o/c to 4.6GHz8GB Mushkin 1866MHzNvidia GTX 750 Ti 2GB
Computer type
PC/Desktop
Computer Manufacturer/Model Number
self build
OS
Windows 7 pro x64 SP1
CPU
Intel i7-2600k o/c to 4.6GHz
Motherboard
MSI Z68-GD80
Memory
8GB Mushkin 1866MHz
Graphics Card(s)
Nvidia GTX 750 Ti 2GB
Sound Card
integrated
Monitor(s) Displays
Liyama ProLite 27"
Screen Resolution
1920*1080 px
Hard Drives
Seagate 2TB
PSU
Coolermaster GX 750W
Case
Antec 300 case + 5 fans
Cooling
Dark Rock Pro
Internet Speed
62Mbit down 18Mbit up
Antivirus
MSE
Browser
Firefox
Other Info
Blackgold BGT3650 Quad HD TV card. Also have various 3770 + 4770K render boxes.
Sounds like a typical warez site scam. You go to a site offering 'free' stuff, click the link, and get re-directed to malware. This is how the warez sites make their money. Sleep with dogs, get fleas etc. Mediafire hosts mainly copyright infringing content - there's the clue. This ain't a computer problem, it's an illegal download problem, and the op is asking for help to do it.

Mediafire goes out of their way to prevent illegal and copyright infringing content from being shared on their servers.

The OP's issue has nothing to do with clicking on scams. There is a real security issue here that is probably related to a toolbar infestation or hosts file jack, both of which are legitimate and innocent from any angle that you look at them.

The OP did not ask for help to download anything illegally.
 

My Computer My Computer

At a glance

Windows 8 Pro x64i7 3820 @ 4.68GHzF3-12800CL9D-8GBXL (32GB)GTX 480 SLI
Computer type
PC/Desktop
OS
Windows 8 Pro x64
CPU
i7 3820 @ 4.68GHz
Motherboard
ASUS Rampage IV Extreme RoG BF3
Memory
F3-12800CL9D-8GBXL (32GB)
Graphics Card(s)
GTX 480 SLI
Sound Card
Auzentech X-Fi HomeTheater HD
Monitor(s) Displays
Sony 32V5500
Screen Resolution
1920 x 1080
Hard Drives
LSI MR9260-4i (RAID10):
Toshiba DT01ACA300 x 4
iaStorA:
OCZ Vertex Enterprise 120GB
ST3500320AS 500GB
Intel 520 Series 120GB
PSU
OCZ ZX 1250W
Case
HAF X
Cooling
H80
Keyboard
Cyborg V.7
Mouse
Razer Lachesis 3.5G 5600dpi
Internet Speed
23296kbps ds / 812kbps us ADSL2+
Browser
Mozilla/5.0 (Windows NT 6.3; Win64; x64; rv:32.0) Gecko/2010
Other Info
AverMedia C127 Game Broadcaster HD
Kind of funny in a way,
mabm flags everything from Mediafire as corrupt and blocks it automatically ;)
Did it to me attempting to download something Nick = PoomanUK posted there ?
I doubt it would of worked anyway different version of CorelDraw ;)
Can't remember the other item I attempted to download ? a free photoshop file I believe from another reputable host I think Blue lightening t.v offering or tip squirrel ?
Cheers.
 

My Computer My Computer

At a glance

Win-7-Pro64bit 7-H-Prem-64biti7-5930K 2nd i9-9940x both water blocked VRM'...Trident-z 3200C14 2nd Trident-z 3600C16EVGA 1080ti ftw3 2nd Titan Xp both water blocked
Computer type
PC/Desktop
Computer Manufacturer/Model Number
Custom assembled by me :}
OS
Win-7-Pro64bit 7-H-Prem-64bit
CPU
i7-5930K 2nd i9-9940x both water blocked VRM's too
Motherboard
ASUS SABERTOOTH X99 2nd ASUS x299 Apex
Memory
Trident-z 3200C14 2nd Trident-z 3600C16
Graphics Card(s)
EVGA 1080ti ftw3 2nd Titan Xp both water blocked
Sound Card
Built-in Realtek
Monitor(s) Displays
1-AOC G2460PG 24"G-Sync 144Hz/ 2nd 1-ASUS VG248QE 24" 144Hz
Screen Resolution
1920 x 1080 144Hz
Hard Drives
2-Samsung M.2 Evo & Evo Plus
2-Samsung 850 EVO 500GB SSD's/ 3-2.5 W.D. Black 1tb-&3-1tb/3-3.5 WD Black 1tb hdd's
PSU
EVGA SuperNOVA 1000-P2 2nd 1200-P2
Case
2-Corsair Obsidian Series 450D Black ATX Mid Tower
Cooling
Custom water loops
Keyboard
Logitech G710+/ 2nd Logitech G910
Mouse
2-RedDragon M901 Perdition 16400 dpi Gaming mouse = wired
Internet Speed
Comcast Ping 19ms 89.31mbps download speed 6.12mbps upload
Antivirus
Malwarebytes Pro/ Superantispyware Pro
Browser
FireFox & Pale moon
Other Info
2nd ASUS X299 Apex/Intel i9-9940x with Custom water loop/7H-Prem-x64/Corsair 450D case/Ram Trident-z 3600C16 4x8gb / Samsung970Evo plus 500gb SSD/Dual ssd EZ swap evo/PSU EVGA SuperNova 1200w-P2 80+Platinum/GPU Titan Xp /8-ML-140 on push-pull on 2-280GTX rads
I'm still being redirected, unfortunately. I've only checked in Firefox so far, so I'm not sure if it happens in Internet Explorer as well.
 

My Computer My Computer

At a glance

Windows 7 Home Premium 64bit (Service Pack 1)Intel Core i76.00 GBNVIDIA GeForce GTX 550 Ti
Computer type
PC/Desktop
Computer Manufacturer/Model Number
Packard Bell ipower G5800
OS
Windows 7 Home Premium 64bit (Service Pack 1)
CPU
Intel Core i7
Memory
6.00 GB
Graphics Card(s)
NVIDIA GeForce GTX 550 Ti
Antivirus
Avira Free Antivirus
Browser
Firefox
What version of Internet Explorer do you have?

Be careful if you go checking a website like this when using IE8.
 

My Computer My Computer

At a glance

W7 Pro SP1 64biti78GBIntel HD Graphics
Computer type
Laptop
Computer Manufacturer/Model Number
Employer provided Dell Latitude
OS
W7 Pro SP1 64bit
CPU
i7
Memory
8GB
Graphics Card(s)
Intel HD Graphics
Hard Drives
crappy SSD
Antivirus
Employer mandated Symantec Endpoint Protection
Browser
Pale Moon 64bit, IE11 64bit & Chrome 64bit
I'm pretty sure I'm using a more recent version than IE8, but is there a way for me to check?
 

My Computer My Computer

At a glance

Windows 7 Home Premium 64bit (Service Pack 1)Intel Core i76.00 GBNVIDIA GeForce GTX 550 Ti
Computer type
PC/Desktop
Computer Manufacturer/Model Number
Packard Bell ipower G5800
OS
Windows 7 Home Premium 64bit (Service Pack 1)
CPU
Intel Core i7
Memory
6.00 GB
Graphics Card(s)
NVIDIA GeForce GTX 550 Ti
Antivirus
Avira Free Antivirus
Browser
Firefox

My Computer My Computer

At a glance

W7 Pro SP1 64biti78GBIntel HD Graphics
Computer type
Laptop
Computer Manufacturer/Model Number
Employer provided Dell Latitude
OS
W7 Pro SP1 64bit
CPU
i7
Memory
8GB
Graphics Card(s)
Intel HD Graphics
Hard Drives
crappy SSD
Antivirus
Employer mandated Symantec Endpoint Protection
Browser
Pale Moon 64bit, IE11 64bit & Chrome 64bit
Thanks. I just checked and it's IE11. Should I check mediafire in that?
 

My Computer My Computer

At a glance

Windows 7 Home Premium 64bit (Service Pack 1)Intel Core i76.00 GBNVIDIA GeForce GTX 550 Ti
Computer type
PC/Desktop
Computer Manufacturer/Model Number
Packard Bell ipower G5800
OS
Windows 7 Home Premium 64bit (Service Pack 1)
CPU
Intel Core i7
Memory
6.00 GB
Graphics Card(s)
NVIDIA GeForce GTX 550 Ti
Antivirus
Avira Free Antivirus
Browser
Firefox
Last edited:

My Computer My Computer

At a glance

W7 Pro SP1 64biti78GBIntel HD Graphics
Computer type
Laptop
Computer Manufacturer/Model Number
Employer provided Dell Latitude
OS
W7 Pro SP1 64bit
CPU
i7
Memory
8GB
Graphics Card(s)
Intel HD Graphics
Hard Drives
crappy SSD
Antivirus
Employer mandated Symantec Endpoint Protection
Browser
Pale Moon 64bit, IE11 64bit & Chrome 64bit
If it does not happen in internet explorer, reset firefox under help, or uninstall and then reinstall again making sure to check the box to clear personal settings.
 

My Computer My Computer

At a glance

Windows 10 ProAMD Ryzen 5 2400G Processor with Radeon RX Ve...G.SKILL Ripjaws V Series 16GB (2 x 8GB) 288-P...2047MB NVIDIA GeForce GTX 1060 6GB (EVGA)
Computer type
PC/Desktop
Computer Manufacturer/Model Number
Custom Built
OS
Windows 10 Pro
CPU
AMD Ryzen 5 2400G Processor with Radeon RX Vega 11 Graphics
Motherboard
ASRock X470 Master SLI/AC AM4 AMD Promontory X470 SATA 6Gb/s
Memory
G.SKILL Ripjaws V Series 16GB (2 x 8GB) 288-Pin DDR4 SDRAM D
Graphics Card(s)
2047MB NVIDIA GeForce GTX 1060 6GB (EVGA)
Sound Card
Motherboard Built in
Monitor(s) Displays
Acer R240HY bidx 23.8-Inch IPS HDMI DVI VGA (1920 x 1080) Wi
Screen Resolution
1920 x 1080
Hard Drives
1TB Sandisk SSD PLUS (Main drive)
500 GB Seagate 7200 RPM (Games)
500 GB Western Digital 7200 RPM (Virtual Machines)
PSU
CORSAIR TX Series TX650M 650W 80+ Gold Modular Power Supply
Case
CORSAIR CARBIDE SPEC-02 Mid-Tower Gaming Case, Red LED Fan
Cooling
220mm, two 120mm, and four 60mm fans
Keyboard
Wired Dell keyboard
Mouse
Wireless Logitech mouse
Internet Speed
250mb down, 30mb up
Antivirus
Panda Cloud Antivirus
Browser
Chrome-ish x64
Other Info
Your awesome for reading this.
Sorry for the late reply. I had to go out today. I just took a quick look at the tutorial, and I'm a little confused. On my PC, the "enable protected mode" box in the security tab is ticked, and the "enable enhanced protected mode" box in the advanced tab is unticked. Should I tick them both or only one?
 

My Computer My Computer

At a glance

Windows 7 Home Premium 64bit (Service Pack 1)Intel Core i76.00 GBNVIDIA GeForce GTX 550 Ti
Computer type
PC/Desktop
Computer Manufacturer/Model Number
Packard Bell ipower G5800
OS
Windows 7 Home Premium 64bit (Service Pack 1)
CPU
Intel Core i7
Memory
6.00 GB
Graphics Card(s)
NVIDIA GeForce GTX 550 Ti
Antivirus
Avira Free Antivirus
Browser
Firefox
Back
Top