Malicious URL on diyaudio website? [RESOLVED]

Status
Not open for further replies.
Sigh... Thanks for checking!

I have a ping into to Jason to have a look at it.

Pano,
I've got that message too. Started today, didn't have it yesterday.

I have been using the "free" avast for over 10 years, I run it on every computer I own personally and build for others. Avast has recently begun advising an option to upgrade their standard Anti-Virus software. However,
I have NEVER had them try to "spoof" or "Scam" me into buying anything!
This is NOT a gimmick from Avast.
It is Malware. Start by running Malwarebytes.

Ron
 
Pano,

I'm not seeing it. We'll let Jason know. Thanks for reporting it. Can anyone follw the "More Details" link and see what it says?

Dave
 

Attachments

  • diyaudiowarning.png
    diyaudiowarning.png
    6.9 KB · Views: 235
It doesn't show up as a file using locate32 with nothing hidden. Also did a full Avast scan of it's reported location in the user folder with no discovery. It looks like it's redirecting to the Google cloud itself. They may have caught it already and broken whatever link was embedded.
 
This is the segment that is red flagged in the Java history. Maybe you programmers can sniff something out.

_ _ _ _ _ _ _ _ _ _ _ _ _ _ _ _

</script>
<script type="text/javascript" src="/openx/www/delivery/spcjs.php,qid=1,avbm=1,asection=128.pagespeed.ce.UtrDUgdFRR.js"></script>
GET http://www.cloud-jscript.com/gate.php
<script type="text/javascript" src="//files.diyaudio.com/min/g=vb7"></script>


<link rel="alternate" type="application/rss+xml" title="diyAudio RSS Feed" href="external.php?type=RSS2"/>

<link rel="alternate" type="application/rss+xml" title="diyAudio - Analog Line Level - RSS Feed" href="external.php?type=RSS2&forumids=128"/>


<script type="text/javascript" src="//files.diyaudio.com/forums/clientscript/tcattd_imageresizer.js,qv=1.2.7.pagespeed.ce.zxE64V_ceQ.js"></script>
<script type="text/javascript">
<!--
var tcimgrResizeMsg = 'Click the image to open in full size.';
var tcimgrWidthMax = 400;
var tcimgrWidthSizeTo = 400;
var tcimgrHeightMax = 600;
var tcimgrHeightSizeTo = 600;
var tcimgrWidthSizeToSigs = 400;
var tcimgrHeightSizeToSigs = 100;

YAHOO.util.Event.onDOMReady(tcattdImageResize);
//-->
 
Switches things on and off again
Joined 2000
Paid Member
Looks like the same problem lots of other forums have encountered in the last few days (Eg: 1) where malicious code was inserted into a template. I traced it to happening approximately 6 hours ago. There are a number of possible ways that it could have happened, and we've taken steps to ensure it won't happen again, including upgrading to the latest patch level of vBulletin (we weren't on the latest patch).

The code has been identified, removed and things should be fine for now. We are continuing our diagnostics and forensics.
 
Hi,
I am glad that was found I have had all kinds of pointer errors,Driving me krazier that I was ,lol. Now on to better things,lol
Thanks for fixing it !!!!!!!!!!!!!!!

I got frustrated and added google chrome and dumped firefox,Io orbit malware ,free version too, found all the bad files I think it was 5 of them ,
 
Last edited:
Status
Not open for further replies.