Use OpenDNS to block winzipices.cn


Recommended Posts

I am really saddened to see another worm on the loose.

The easiest way to not get infected accidently is to block winzipices.cn from your network.

There is one easy way to do this.

Go to www.opendns.com/start

Setup OpenDNS on your network by changing the DNS..

Create an account at OpenDNS, add a new network, call it home or work, what ever you please.

Go into "Settings" then "Block Individual Domains"

Add winzipices.cn to the block list

Go to command prompt, type "ipconfig /flushdns" this will flush the DNS resolver cache

Conclusion: No more risk of getting worm.

Link to comment
https://www.neowin.net/forum/topic/635979-use-opendns-to-block-winzipicescn/
Share on other sites

cant i just do it by editing the HOSTS file?

Yes you can, but if you have multiple computers, or manage a large network this is the easiest way.

Once you use OpenDNS to take advantage of its great features, Adware blocking :D and blocking advertising sites, etc...

One click, and no more adware gets ever loaded onto your network

Yes you can, but if you have multiple computers, or manage a large network this is the easiest way.

Once you use OpenDNS to take advantage of its great features, Adware blocking :D and blocking advertising sites, etc...

One click, and no more adware gets ever loaded onto your network

Careful what you say there. They are a bit funny about talk of blocking adverts.

cant i just do it by editing the HOSTS file?

Sure, but if you are like I am, and have a home network, then this is sort of a one-stop-does-all type of fix, rather than going to several PCs and making changes.

EDIT: Beaten to the post about 3 times in one minute! :punch:

I have added the domain winzipices.cn to opendns global domain tagging

I tagged it as Adware, since the Malware category isnt up yet.

http://domain.opendns.com/winzipices.cn

If everyone can vote on that domain name as adware, I can get it blocked throughout all OpenDNS users who have the "Adware" category blocked on OpenDNS.

Can somebody help explain what the advantage to using Open DNS is? They probably have something on their website, but I am a bit short on time today. Thanks!

"OpenDNS protects millions of people a day across hundreds of thousands of schools, businesses and homes. We block phishing sites, give you the power to filter out adult sites and proxies among more than 50 categories, and provide the precision to block individual domains."

It also makes loading times way faster.

"OpenDNS protects millions of people a day across hundreds of thousands of schools, businesses and homes. We block phishing sites, give you the power to filter out adult sites and proxies among more than 50 categories, and provide the precision to block individual domains."

It also makes loading times way faster.

No offense but how? How would this be different from using my ISP's? Can't I already block/filter out tons of stuff with my router?

No offense but how? How would this be different from using my ISP's? Can't I already block/filter out tons of stuff with my router?

"OpenDNS is faster is because we run some of the largest DNS caches around and do it on our own high-performance network, running our own software. We can hold tens of millions of records and zones in local cache, saving you the extra round-trips to find the addresses.

OpenDNS gets better as our user base grows. Why? Our caches are really big. The more people using OpenDNS, the more addresses our caches are holding at any given time."

You just go into your Network adapter settings, click properties, change the DNS server address, reboot your computer.

Thats the simpliest way

If you have a router, change the DNS servers of your router.

Its really easy..

http://www.opendns.com/start

i never thought of using this service before, im glad i read this topic

The technology they use is simply amazing.. and it keeps getting better every day. Each day I hear about new improvements or ideas to the backend and frontend of OpenDNS and they are just simply amazing.

Does anyone have any details on the malware itself? What browsers does it affect? What exactly does the malware do, etc? Or better yet, can someone upload the actual malware someplace?

Too risky.

But this is what i could find

"WinZipIces.cn - Several thousand websites have been hacked by a MySQL exploit that redirects visitors to WinZipIces.cn where a phishing trojan is downloaded onto your PC.

Prominent sites affected by the WinZipIces.cn hack are WiredSeniors.com, CGSI.org, MoviesUnlimited, SeniorsTravelGuide.com, CancerIssues.com, USSC.edu, UCLA.edu, telluride-co.gov, and thousands more hacked websites which are similarly infected worldwide.

The WinZipIces phishing exploit launched by Chinese hackers using an automated script that searches for an unpatched SQL vulnerability on web servers downloads two files onto visitors computers, JS_DLOADER.AEHM and TROJ_REALPLAY.BR.

Both these initial files in turn download TROJ_AGENT.AKVP onto the infected system of visitors to these hacked websites.

Users should make sure their own personal computers are not infected by the WinZipIces hack by having current antivirus software and firewalls installed and active on their PCs.

You can go to download.com (a site run by PC Week & CNET) to get free versions of AVG antivirus and Zone Labs personal firewall there, so there?s no excuse for letting your own PC get hacked.

Website hosting providers should check their servers to be sure all patches have been applied to vulnerable servers. Experts expect the wave of infected sites to continue for the next week to ten days."

http://a11news.com/95/winzipices-cn/

This topic is now closed to further replies.
  • Recently Browsing   0 members

    • No registered users viewing this page.
  • Posts

    • What I like about Paint is using it almost exclusively for cropping and resizing images I get elsewhere--it's quick, easy and cheap... I keep it glued to my taskbar, in fact. Also, the clipping tool comes in handy, as well (hit print scrn on the keyboard and it activates immediately.)
    • I still remember it fondly today. It was so cool to work in 64-color Half Bright mode and 4.096-color HAM mode (interlaced) when x86 was still in 4-color CGA or 16-color EGA low res. C= never realized what it had until it was far too late--the failure of C= was the failure of its top management. The C= Amiga was 20 years ahead of its time, I always thought. It didn't hurt that in only 512k of chip memory, the Amiga could preemptively multitask when Apple was still doing gray scale graphics on tiny screens and along with everyone else was doing cooperative multitasking (running more than one app at a time in resident memory, but you could only run one of them at a time--had to manually switch between them.) I had a ball with AREXX scripting running between programs that had AREXX ports so that when you sent other applications data and instructions, those running applications could process the same in real time to output! Memories...
    • I'm not sure about that, but it at least "does" a version of 7.1 that this brand new card doesn't....
    • Floorp 12.15.2 by Razvan Serea Floorp is a cutting-edge web browser that combines the trusted foundation of Mozilla's Firefox with a unique Japanese perspective, offering users an exceptional online experience. This open-source browser prioritizes privacy, customization, and security. Floorp is transparent, with no user tracking or data sharing, and it's completely open source. With a strict no-tracking policy and full transparency, your personal information remains private. As an open-source project, Floorp not only shares its source code but also its build environment, inviting users to contribute and build their unique versions. The regular updates, based on Firefox ESR, ensure that you always have the latest features and security enhancements. Floorp key features: Strong Tracking Protection: Floorp offers robust tracking protection, safeguarding users from malicious tracking and fingerprinting on the web. Flexible Layout: Customize Floorp's layout to your heart's content, including moving the tab bar, hiding the title bar, and more for a personalized browsing experience. Switchable Design: Choose from five distinct designs for the Floorp interface, and even switch between OS-specific designs for a unique look Regular Updates: Based on Firefox ESR, Floorp receives updates every four weeks, ensuring up-to-date security even before Firefox's releases. No User Tracking: Floorp prioritizes user privacy by abstaining from collecting personal information, tracking users, or selling user data, with no affiliations with advertising companies. Completely Open Source: The full source code for Floorp is open to the public, allowing transparency and enabling anyone to explore and build their own version. Dual Sidebar: Floorp features a versatile built-in sidebar for webpanels and browsing tools, making it perfect for multitasking and quick access to bookmarks, history, and websites. Flexible Toolbar & Tab Bar: Customize your browser with Tree Style Tabs, vertical tabs, and bookmark bar modifications, catering to both beginners and experts in customization. User-Centric Web Experience: Floorp prioritizes user privacy and collaboratively blocks harmful trackers. Floorp 12.15.2 changelog: fix: reset tab drag state on dragend to prevent position offset (#2488) by @Ryosuke-Asano in #2497 fix(workspaces): hide split view wrapper when all tabs are hidden by @Ryosuke-Asano in #2495 fix(split-view): prevent stuck pointer-events:none after drag on web content by @Ryosuke-Asano in #2492 feat(design): add Gecko 152 CSS variable aliases and Lepton compatibility layer by @Ryosuke-Asano in #2494 fix(workspaces): exitOnLastTabClose no longer quits Floorp when closing the last tab by @Ryosuke-Asano in #2498 Download: Floorp 64-bit | 95.0 MB (Open Source) Links: Floorp Website | Github Website | Screenshot Get alerted to all of our Software updates on Twitter at @NeowinSoftware
    • I can barely recall getting web results from a file search... I must've turned it off long ago. 26H2 is Insider's Preview build 26300.8697, which I am running, atm. It is not available for people running the standard commercial builds of Windows--only for the beta test Insider's group. But anyway, as mentioned in the thread, this feature has been around for a long time...
  • Recent Achievements

    • Dedicated
      Almohandis earned a badge
      Dedicated
    • Dedicated
      JuvenileDelinquent earned a badge
      Dedicated
    • First Post
      DrWankel earned a badge
      First Post
    • Reacting Well
      DrWankel earned a badge
      Reacting Well
    • Week One Done
      Supreme Spray LV earned a badge
      Week One Done
  • Popular Contributors

    1. 1
      +primortal
      507
    2. 2
      +Edouard
      185
    3. 3
      PsYcHoKiLLa
      84
    4. 4
      Michael Scrip
      78
    5. 5
      Steven P.
      76
  • Tell a friend

    Love Neowin? Tell a friend!