Jonathan Yaniv Posted May 9, 2008 Share Posted May 9, 2008 I am really saddened to see another worm on the loose. The easiest way to not get infected accidently is to block winzipices.cn from your network. There is one easy way to do this. Go to www.opendns.com/start Setup OpenDNS on your network by changing the DNS.. Create an account at OpenDNS, add a new network, call it home or work, what ever you please. Go into "Settings" then "Block Individual Domains" Add winzipices.cn to the block list Go to command prompt, type "ipconfig /flushdns" this will flush the DNS resolver cache Conclusion: No more risk of getting worm. Link to comment https://www.neowin.net/forum/topic/635979-use-opendns-to-block-winzipicescn/ Share on other sites More sharing options...
Fit4130Rider Posted May 9, 2008 Share Posted May 9, 2008 I love OpenDNS so much, it's so damn fast and snappy. And I love how I can see how many DNS queries I make. Link to comment https://www.neowin.net/forum/topic/635979-use-opendns-to-block-winzipicescn/#findComment-589387682 Share on other sites More sharing options...
JustGeorge Posted May 9, 2008 Share Posted May 9, 2008 Done, thanks :) Link to comment https://www.neowin.net/forum/topic/635979-use-opendns-to-block-winzipicescn/#findComment-589387696 Share on other sites More sharing options...
Echilon Posted May 9, 2008 Share Posted May 9, 2008 Been using it for a couple of years. Thanks for the info. (Y) Link to comment https://www.neowin.net/forum/topic/635979-use-opendns-to-block-winzipicescn/#findComment-589387707 Share on other sites More sharing options...
rpgfan Posted May 9, 2008 Share Posted May 9, 2008 Thanks for the heads-up. This is why I use OpenDNS. ^_^ Link to comment https://www.neowin.net/forum/topic/635979-use-opendns-to-block-winzipicescn/#findComment-589387716 Share on other sites More sharing options...
Ivand Posted May 9, 2008 Share Posted May 9, 2008 cant i just do it by editing the HOSTS file? Link to comment https://www.neowin.net/forum/topic/635979-use-opendns-to-block-winzipicescn/#findComment-589387771 Share on other sites More sharing options...
JustGeorge Posted May 9, 2008 Share Posted May 9, 2008 cant i just do it by editing the HOSTS file? Yes, but that only applies to the individual PC. If you have more than one PC, this is much quicker :) Link to comment https://www.neowin.net/forum/topic/635979-use-opendns-to-block-winzipicescn/#findComment-589387778 Share on other sites More sharing options...
Jonathan Yaniv Posted May 9, 2008 Author Share Posted May 9, 2008 cant i just do it by editing the HOSTS file? Yes you can, but if you have multiple computers, or manage a large network this is the easiest way. Once you use OpenDNS to take advantage of its great features, Adware blocking :D and blocking advertising sites, etc... One click, and no more adware gets ever loaded onto your network Link to comment https://www.neowin.net/forum/topic/635979-use-opendns-to-block-winzipicescn/#findComment-589387783 Share on other sites More sharing options...
Fred Derf Veteran Posted May 9, 2008 Veteran Share Posted May 9, 2008 cant i just do it by editing the HOSTS file? Just add this to the end: 127.0.0.1 winzipices.cn www.winzipices.cn Link to comment https://www.neowin.net/forum/topic/635979-use-opendns-to-block-winzipicescn/#findComment-589387784 Share on other sites More sharing options...
metallithrax Posted May 9, 2008 Share Posted May 9, 2008 Yes you can, but if you have multiple computers, or manage a large network this is the easiest way.Once you use OpenDNS to take advantage of its great features, Adware blocking :D and blocking advertising sites, etc... One click, and no more adware gets ever loaded onto your network Careful what you say there. They are a bit funny about talk of blocking adverts. Link to comment https://www.neowin.net/forum/topic/635979-use-opendns-to-block-winzipicescn/#findComment-589387790 Share on other sites More sharing options...
markwolfe Veteran Posted May 9, 2008 Veteran Share Posted May 9, 2008 (edited) cant i just do it by editing the HOSTS file? Sure, but if you are like I am, and have a home network, then this is sort of a one-stop-does-all type of fix, rather than going to several PCs and making changes. EDIT: Beaten to the post about 3 times in one minute! :punch: Link to comment https://www.neowin.net/forum/topic/635979-use-opendns-to-block-winzipicescn/#findComment-589387791 Share on other sites More sharing options...
Jonathan Yaniv Posted May 9, 2008 Author Share Posted May 9, 2008 I have added the domain winzipices.cn to opendns global domain tagging I tagged it as Adware, since the Malware category isnt up yet. http://domain.opendns.com/winzipices.cn If everyone can vote on that domain name as adware, I can get it blocked throughout all OpenDNS users who have the "Adware" category blocked on OpenDNS. Link to comment https://www.neowin.net/forum/topic/635979-use-opendns-to-block-winzipicescn/#findComment-589387792 Share on other sites More sharing options...
Jonathan Yaniv Posted May 9, 2008 Author Share Posted May 9, 2008 Update: Now approved in the ADWARE category in OpenDNS. Link to comment https://www.neowin.net/forum/topic/635979-use-opendns-to-block-winzipicescn/#findComment-589387817 Share on other sites More sharing options...
Stuge Posted May 9, 2008 Share Posted May 9, 2008 I'm also using OPEN DNS :D Link to comment https://www.neowin.net/forum/topic/635979-use-opendns-to-block-winzipicescn/#findComment-589388003 Share on other sites More sharing options...
Jonathan Yaniv Posted May 9, 2008 Author Share Posted May 9, 2008 I'm also using OPEN DNS :D Awesome man. Link to comment https://www.neowin.net/forum/topic/635979-use-opendns-to-block-winzipicescn/#findComment-589388051 Share on other sites More sharing options...
+Mystic MVC Posted May 9, 2008 MVC Share Posted May 9, 2008 Can somebody help explain what the advantage to using Open DNS is? They probably have something on their website, but I am a bit short on time today. Thanks! Link to comment https://www.neowin.net/forum/topic/635979-use-opendns-to-block-winzipicescn/#findComment-589388056 Share on other sites More sharing options...
MMaster23 Posted May 9, 2008 Share Posted May 9, 2008 nice feature but I prefer my own DNS servers as they are only 25km's away from me, low ping and on the net as my ISPs Link to comment https://www.neowin.net/forum/topic/635979-use-opendns-to-block-winzipicescn/#findComment-589388099 Share on other sites More sharing options...
Jonathan Yaniv Posted May 9, 2008 Author Share Posted May 9, 2008 Can somebody help explain what the advantage to using Open DNS is? They probably have something on their website, but I am a bit short on time today. Thanks! "OpenDNS protects millions of people a day across hundreds of thousands of schools, businesses and homes. We block phishing sites, give you the power to filter out adult sites and proxies among more than 50 categories, and provide the precision to block individual domains." It also makes loading times way faster. Link to comment https://www.neowin.net/forum/topic/635979-use-opendns-to-block-winzipicescn/#findComment-589388154 Share on other sites More sharing options...
+Mystic MVC Posted May 9, 2008 MVC Share Posted May 9, 2008 "OpenDNS protects millions of people a day across hundreds of thousands of schools, businesses and homes. We block phishing sites, give you the power to filter out adult sites and proxies among more than 50 categories, and provide the precision to block individual domains."It also makes loading times way faster. No offense but how? How would this be different from using my ISP's? Can't I already block/filter out tons of stuff with my router? Link to comment https://www.neowin.net/forum/topic/635979-use-opendns-to-block-winzipicescn/#findComment-589388305 Share on other sites More sharing options...
Jonathan Yaniv Posted May 10, 2008 Author Share Posted May 10, 2008 No offense but how? How would this be different from using my ISP's? Can't I already block/filter out tons of stuff with my router? "OpenDNS is faster is because we run some of the largest DNS caches around and do it on our own high-performance network, running our own software. We can hold tens of millions of records and zones in local cache, saving you the extra round-trips to find the addresses. OpenDNS gets better as our user base grows. Why? Our caches are really big. The more people using OpenDNS, the more addresses our caches are holding at any given time." Link to comment https://www.neowin.net/forum/topic/635979-use-opendns-to-block-winzipicescn/#findComment-589388446 Share on other sites More sharing options...
k311 Posted May 10, 2008 Share Posted May 10, 2008 i never thought of using this service before, im glad i read this topic Link to comment https://www.neowin.net/forum/topic/635979-use-opendns-to-block-winzipicescn/#findComment-589388452 Share on other sites More sharing options...
+Mystic MVC Posted May 10, 2008 MVC Share Posted May 10, 2008 I guess I am just a bit hesitant to use it because I have such a delicate network structure here at home. How difficult is it to implement? Link to comment https://www.neowin.net/forum/topic/635979-use-opendns-to-block-winzipicescn/#findComment-589388454 Share on other sites More sharing options...
Jonathan Yaniv Posted May 10, 2008 Author Share Posted May 10, 2008 You just go into your Network adapter settings, click properties, change the DNS server address, reboot your computer. Thats the simpliest way If you have a router, change the DNS servers of your router. Its really easy.. http://www.opendns.com/start i never thought of using this service before, im glad i read this topic The technology they use is simply amazing.. and it keeps getting better every day. Each day I hear about new improvements or ideas to the backend and frontend of OpenDNS and they are just simply amazing. Link to comment https://www.neowin.net/forum/topic/635979-use-opendns-to-block-winzipicescn/#findComment-589388533 Share on other sites More sharing options...
[deXter] Posted May 10, 2008 Share Posted May 10, 2008 Does anyone have any details on the malware itself? What browsers does it affect? What exactly does the malware do, etc? Or better yet, can someone upload the actual malware someplace? Link to comment https://www.neowin.net/forum/topic/635979-use-opendns-to-block-winzipicescn/#findComment-589388548 Share on other sites More sharing options...
Jonathan Yaniv Posted May 10, 2008 Author Share Posted May 10, 2008 Does anyone have any details on the malware itself? What browsers does it affect? What exactly does the malware do, etc? Or better yet, can someone upload the actual malware someplace? Too risky. But this is what i could find "WinZipIces.cn - Several thousand websites have been hacked by a MySQL exploit that redirects visitors to WinZipIces.cn where a phishing trojan is downloaded onto your PC. Prominent sites affected by the WinZipIces.cn hack are WiredSeniors.com, CGSI.org, MoviesUnlimited, SeniorsTravelGuide.com, CancerIssues.com, USSC.edu, UCLA.edu, telluride-co.gov, and thousands more hacked websites which are similarly infected worldwide. The WinZipIces phishing exploit launched by Chinese hackers using an automated script that searches for an unpatched SQL vulnerability on web servers downloads two files onto visitors computers, JS_DLOADER.AEHM and TROJ_REALPLAY.BR. Both these initial files in turn download TROJ_AGENT.AKVP onto the infected system of visitors to these hacked websites. Users should make sure their own personal computers are not infected by the WinZipIces hack by having current antivirus software and firewalls installed and active on their PCs. You can go to download.com (a site run by PC Week & CNET) to get free versions of AVG antivirus and Zone Labs personal firewall there, so there?s no excuse for letting your own PC get hacked. Website hosting providers should check their servers to be sure all patches have been applied to vulnerable servers. Experts expect the wave of infected sites to continue for the next week to ten days." http://a11news.com/95/winzipices-cn/ Link to comment https://www.neowin.net/forum/topic/635979-use-opendns-to-block-winzipicescn/#findComment-589388560 Share on other sites More sharing options...
Recommended Posts