Use OpenDNS to block winzipices.cn


Recommended Posts

I am really saddened to see another worm on the loose.

The easiest way to not get infected accidently is to block winzipices.cn from your network.

There is one easy way to do this.

Go to www.opendns.com/start

Setup OpenDNS on your network by changing the DNS..

Create an account at OpenDNS, add a new network, call it home or work, what ever you please.

Go into "Settings" then "Block Individual Domains"

Add winzipices.cn to the block list

Go to command prompt, type "ipconfig /flushdns" this will flush the DNS resolver cache

Conclusion: No more risk of getting worm.

Link to comment
https://www.neowin.net/forum/topic/635979-use-opendns-to-block-winzipicescn/
Share on other sites

cant i just do it by editing the HOSTS file?

Yes you can, but if you have multiple computers, or manage a large network this is the easiest way.

Once you use OpenDNS to take advantage of its great features, Adware blocking :D and blocking advertising sites, etc...

One click, and no more adware gets ever loaded onto your network

Yes you can, but if you have multiple computers, or manage a large network this is the easiest way.

Once you use OpenDNS to take advantage of its great features, Adware blocking :D and blocking advertising sites, etc...

One click, and no more adware gets ever loaded onto your network

Careful what you say there. They are a bit funny about talk of blocking adverts.

cant i just do it by editing the HOSTS file?

Sure, but if you are like I am, and have a home network, then this is sort of a one-stop-does-all type of fix, rather than going to several PCs and making changes.

EDIT: Beaten to the post about 3 times in one minute! :punch:

I have added the domain winzipices.cn to opendns global domain tagging

I tagged it as Adware, since the Malware category isnt up yet.

http://domain.opendns.com/winzipices.cn

If everyone can vote on that domain name as adware, I can get it blocked throughout all OpenDNS users who have the "Adware" category blocked on OpenDNS.

Can somebody help explain what the advantage to using Open DNS is? They probably have something on their website, but I am a bit short on time today. Thanks!

"OpenDNS protects millions of people a day across hundreds of thousands of schools, businesses and homes. We block phishing sites, give you the power to filter out adult sites and proxies among more than 50 categories, and provide the precision to block individual domains."

It also makes loading times way faster.

"OpenDNS protects millions of people a day across hundreds of thousands of schools, businesses and homes. We block phishing sites, give you the power to filter out adult sites and proxies among more than 50 categories, and provide the precision to block individual domains."

It also makes loading times way faster.

No offense but how? How would this be different from using my ISP's? Can't I already block/filter out tons of stuff with my router?

No offense but how? How would this be different from using my ISP's? Can't I already block/filter out tons of stuff with my router?

"OpenDNS is faster is because we run some of the largest DNS caches around and do it on our own high-performance network, running our own software. We can hold tens of millions of records and zones in local cache, saving you the extra round-trips to find the addresses.

OpenDNS gets better as our user base grows. Why? Our caches are really big. The more people using OpenDNS, the more addresses our caches are holding at any given time."

You just go into your Network adapter settings, click properties, change the DNS server address, reboot your computer.

Thats the simpliest way

If you have a router, change the DNS servers of your router.

Its really easy..

http://www.opendns.com/start

i never thought of using this service before, im glad i read this topic

The technology they use is simply amazing.. and it keeps getting better every day. Each day I hear about new improvements or ideas to the backend and frontend of OpenDNS and they are just simply amazing.

Does anyone have any details on the malware itself? What browsers does it affect? What exactly does the malware do, etc? Or better yet, can someone upload the actual malware someplace?

Too risky.

But this is what i could find

"WinZipIces.cn - Several thousand websites have been hacked by a MySQL exploit that redirects visitors to WinZipIces.cn where a phishing trojan is downloaded onto your PC.

Prominent sites affected by the WinZipIces.cn hack are WiredSeniors.com, CGSI.org, MoviesUnlimited, SeniorsTravelGuide.com, CancerIssues.com, USSC.edu, UCLA.edu, telluride-co.gov, and thousands more hacked websites which are similarly infected worldwide.

The WinZipIces phishing exploit launched by Chinese hackers using an automated script that searches for an unpatched SQL vulnerability on web servers downloads two files onto visitors computers, JS_DLOADER.AEHM and TROJ_REALPLAY.BR.

Both these initial files in turn download TROJ_AGENT.AKVP onto the infected system of visitors to these hacked websites.

Users should make sure their own personal computers are not infected by the WinZipIces hack by having current antivirus software and firewalls installed and active on their PCs.

You can go to download.com (a site run by PC Week & CNET) to get free versions of AVG antivirus and Zone Labs personal firewall there, so there?s no excuse for letting your own PC get hacked.

Website hosting providers should check their servers to be sure all patches have been applied to vulnerable servers. Experts expect the wave of infected sites to continue for the next week to ten days."

http://a11news.com/95/winzipices-cn/

This topic is now closed to further replies.
  • Recently Browsing   0 members

    • No registered users viewing this page.
  • Posts

    • Why was it necessary to use AI to help write this article? Can we no longer do our own research or our own writing?
    • The auto industry really needs to update it's terminology so a software update isn't called a recall.
    • Anybody that thinks flying cars were possible are idiots. Everyone would basically need a pilot licence, can you imagine how insane and dangerous that would be, people can barely handle driving on land safely right now.
    • Microsoft Edge 149.0.4022.80 by Razvan Serea Microsoft Edge is a super fast and secure web browser from Microsoft. It works on almost any device, including PCs, iPhones and Androids. It keeps you safe online, protects your privacy, and lets you browse the web quickly. You can even use it on all your devices and keep your browsing history and favorites synced up. Built on the same technology as Chrome, Microsoft Edge has additional built-in features like Startup boost and Sleeping tabs, which boost your browsing experience with world class performance and speed that are optimized to work best with Windows. Microsoft Edge security and privacy features such as Microsoft Defender SmartScreen, Password Monitor, InPrivate search, and Kids Mode help keep you and your loved ones protected and secure online. Microsoft Edge has features to keep both you and your family protected. Enable content filters and access activity reports with your Microsoft Family Safety account and experience a kid-friendly web with Kids Mode. The new Microsoft Edge is now compatible with your favorite extensions, so it’s easy to personalize your browsing experience. Microsoft Edge 149.0.4022.80 changelog: Fixes Fixed an issue that prevented QR code generation from working. Feature updates Intune MAM Protected Downloads. The protected downloads feature for Intune MAM will now save downloaded files to the Documents > Microsoft Edge > Downloads folder in OneDrive. Extensions monitoring in the Edge management service. The Microsoft Edge management service now allows admins to gain visibility into extensions installed across their managed users. From the extensions monitoring page, admins can see which extensions have been installed as well as manage user requests for blocked extensions. For more information, see Microsoft Edge Extensions Monitoring. Validate Edge builds early with enterprise preview. Enterprise preview provides a simpler way for admins to flight pre-release Edge builds to their users. To reduce friction and bolster usage, users will receive pre-release builds directly inside of their Stable Edge application. Admins can allow users to easily opt-out of the preview experience, using built-in rollback to switch between their pre-release and stable channels with ease. Microsoft 365 admin center users can configure the feature, view their flighting population, and receive personalized recommendations all in one place. For more information, see Get started with Enterprise Preview in Microsoft Edge. Download: Microsoft Edge (64-bit) | 193.0 MB (Freeware) Download: Microsoft Edge (32-bit) | 170.0 MB Download: Microsoft Edge (ARM64) | 188.0 MB View: Microsoft Edge Website | Release History Get alerted to all of our Software updates on Twitter at @NeowinSoftware
    • The machines are starting to fight back any way they can.
  • Recent Achievements

    • Week One Done
      Eurosoft10 earned a badge
      Week One Done
    • One Month Later
      Eurosoft10 earned a badge
      One Month Later
    • One Year In
      Skeet Campbell earned a badge
      One Year In
    • One Month Later
      Sharbel earned a badge
      One Month Later
    • First Post
      BizSAR earned a badge
      First Post
  • Popular Contributors

    1. 1
      +primortal
      598
    2. 2
      +Edouard
      189
    3. 3
      PsYcHoKiLLa
      78
    4. 4
      Michael Scrip
      76
    5. 5
      Steven P.
      69
  • Tell a friend

    Love Neowin? Tell a friend!