problem fixed, it was a wordpress hack. even though i dont use wordpress. if its installed on your box then youre vulnerable. basically a low level hack some fuck embedded some <script> calling from a https:// secure connect in the index.html to some file. traced it back to country code "GA" somewhere near congo, west africa. likely a proxy server user. the offending script code i found in the source linked back to: (do not click or go to it)
'http s : / / l etsmakeparty3 . ga / l.js?n=1'
its a common wordpress hack to sandbox/redpage your site and take it off google. who is behind it, not sure at the moment but im combing through logs. problem solved.
|