Yea the hooks in the picture displayed by tinuz looks very much like malware (backdoor).
Can you post a screenshot of the code in one of those hooks perhaps?
sorry for the late reply but i had to change some passwords and had to check some stuff.... after reading the comment from djbaxter telling me that it's not an official vbulletin product i opened the plugin code and noticed this: images.imagenetcom.com. i did some searching and and found out that it was a malware/backdoor. i also found this blog post: https://blog.sucuri.net/2017/03/vbul...tisements.html and after reading that i followed all the steps from this post: https://www.vbulletin.com/forum/blog...ve-been-hacked on vbulletin.com