I do indeed
Dont for goodness sakes click this and if you do and your PC explodes it was not me!
Spoiler: show
Spoiler: show
An LS member just ran HJT, has the proxy line. Not hacked, and doesn't surf the web. Anyone else not hacked have the line?
Re: R1 - HKCU\Software\Microsoft\Windows\CurrentVersion\Int ernet Settings,ProxyOverride = local
Someone replied with this on LJ: 'I believe that key is ok. I think it's a default registry setting for IPv6. If your proxy is enabled, it is saying to not use the proxy server for local addresses.'
No idea how accurate that is.
There were some WoW sites that had a virus that popped up near the beginning of August. The viruses were in Quantserve ads and used a flash exploit. No idea if it's related or not, but it seems like the same type of thing.
I have that line too, not hacked so far. So does my husband.
Think someone is going to have to get a VM going and monitor all changes, since we can assume the exploit at least attempts to implement itself without the presence of FFXI.
what's interesting though is that a poster above stated that before surfing the web, their computer did not have that value set and after they did on a brand new install. the machine also had the trojan on it, which indicates that it might be viable to at least give an indication if a system is infected.
I also have the line R1 - HKCU\Software\Microsoft\Windows\CurrentVersion\Int ernet Settings,ProxyOverride = *.local on my home PC. I haven't been hacked yet but now I'm kind of worried.
Currently setting up VMs since no one else probably will, will return with some data in some time. (new to VMing so will probably take a bit)
just to keep in mind (tho i'll eat my hat if they did) some of the more complicated tools can detect if they're running in a VM. it's not entirely beyond belief that you might come home with nothing. not likely, like i said, but not impossible.
At this point, I think it's OK to just be trying to do something. (raptor me)
These hackings are a bit scarier than the standard seeing as it's overwhelmingly more sophisticated than we'd like to believe(bypasses token). And if that were the case, I'd assume everyone would be in jeopardy (including me) of losing their account.
To be honest I don't see why this isn't sparking all the professionals of the trait that plays FFXI to help find out what's going on.
Was just reading up ACP stuff to help a friend and was running through white gate and suddenly got the Playonline stopped responding message, I'm a computer wiz, I build, I program, and this never ever ever happens to me, so im extremely skeptical.
I use firefox at all times.
I did find this forum earlier so I hit my router reset, rebooted and changed my password on a net book just in-case.
I am actually surprised this hasn't been posted on wiki forums.
EDIT
I did a scan with HJT (this is after the reboot)
There is no: Re: R1 - HKCU\Software\Microsoft\Windows\CurrentVersion\Int ernet Settings,ProxyOverride = local
Or any of the like (shorted the string and did multiple finds all fail)
I've already done the same in Virtual XP Mode and VMWare Workstation.
I am unable to duplicate what Akisu did earlier on a clean install of Windows XP, newly installed FFXI, with a spare account. I did the same thing as her-- install XP, Flash, Java, visit Alla/FFXI AH/FFXI Wiki and ran Hijack This before and after restarts. That ProxyOverride is still not in HijackThis log. This is with a new install of Playonline Viewer.
Also, checking Internet Options on both virtual guest OS installations, proxy server option "Bypass proxy server for local addresses" is grayed out with no proxy server entered. It is also not listed in the registry. Therefore, that option is not there by default on any installation of Internet Explorer or Windows itself.
All the banner ads so far on Wiki and Alla are for Buick and GM cars, Aion and World of Warcraft. Nothing has thrown red flags so far, including hidden iFrames.
No changes to registry or any other files.
I wonder what Akisu did exactly to get that entry in HiJack This though, or if she remembers what ad she got the moment her spare account got hacked.
I'm still wondering how these people are being targeted. Everyone visits Wiki at some point, so are the people getting hacked the ones with poor security?