Author Topic: Outwitting Conficked blocked sites..........  (Read 3213 times)

0 Members and 1 Guest are viewing this topic.

Offline polonus

  • Avast Überevangelist
  • Probably Bot
  • *****
  • Posts: 33926
  • malware fighter
Outwitting Conficked blocked sites..........
« on: April 03, 2009, 06:10:58 PM »
Hi malware fighters,

There is a way to outwit the Conficker worm to still be able to get to sites it has blocked, by disabling local DNS, the way to do that is explained here:
http://countermeasures.trendmicro.eu/restore-access-to-blocked-sites-on-conficked-systems/

polonus
Cybersecurity is more of an attitude than anything else. Avast Evangelists.

Use NoScript, a limited user account and a virtual machine and be safe(r)!

Offline DavidR

  • Avast Überevangelist
  • Certainly Bot
  • *****
  • Posts: 89286
  • No support PMs thanks
Re: Outwitting Conficked blocked sites..........
« Reply #1 on: April 03, 2009, 08:57:31 PM »
Seems like the instructions are somewhat flawed as simply stopping the DNSCache and DNSClient services is only good for that session, once you reboot they will be started again.

The DNSClient is the important one as if that isn't running there will be no dnscache.

So this really is a one off measure to just access security sites whilst trying to remove conficker if you had it.
Windows 10 Home 64bit/ Acer Aspire F15/ Intel Core i5 7200U 2.5GHz, 8GB DDR4 memory, 256GB SSD, 1TB HDD/ avast! free 24.5.6116 (build 24.5.9153.762) UI 1.0.808/ Firefox, uBlock Origin, uMatrix/ MailWasher Pro/ Avast! Mobile Security

YoKenny

  • Guest
Re: Outwitting Conficked blocked sites..........
« Reply #2 on: April 03, 2009, 09:29:47 PM »
The DNS Client service is really only needed if the system is part of an corporation's network using Active Directory and can really slow down browsing when using a large HOSTS file and thankfully HostsMan disables DNS Client service if it is installed to manage the HOSTS file.
http://www.sturmnet.org/blog/2005/02/09/xp-dnsclient

I use OpenDNS as it has detection for known bad sites and prevents visiting there:
http://www.opendns.com

Offline DavidR

  • Avast Überevangelist
  • Certainly Bot
  • *****
  • Posts: 89286
  • No support PMs thanks
Re: Outwitting Conficked blocked sites..........
« Reply #3 on: April 03, 2009, 09:44:03 PM »
I said important only in that of the two that is the one to stop as without it the other won't work. I have my DNS Client set to Manual so it is available to those that require it (noting depends on it in my system).

I'm loath to disable services as that can really cause problems at least on manual it would be started if there was a dependency. I wouldn't recommend either manual or Disabled in somewhere like the forums as you don't know if there is something on their system that requires it, outside of conficker that is ;D

I too use OpenDNS a great service.
Windows 10 Home 64bit/ Acer Aspire F15/ Intel Core i5 7200U 2.5GHz, 8GB DDR4 memory, 256GB SSD, 1TB HDD/ avast! free 24.5.6116 (build 24.5.9153.762) UI 1.0.808/ Firefox, uBlock Origin, uMatrix/ MailWasher Pro/ Avast! Mobile Security

Offline polonus

  • Avast Überevangelist
  • Probably Bot
  • *****
  • Posts: 33926
  • malware fighter
Re: Outwitting Conficked blocked sites..........
« Reply #4 on: April 03, 2009, 09:50:51 PM »
Hi DavidR,

I agree with you that is more of a theoretical story than it is of practical value, but I passed the link as I found it, I hand it down, we share our views together in the thread and we are all so much the wiser.Well, this was the way I learned a lot on several issues here. So thanks for your reactions, ye all, learning about security is a mutual process,

polonus
Cybersecurity is more of an attitude than anything else. Avast Evangelists.

Use NoScript, a limited user account and a virtual machine and be safe(r)!

Offline DavidR

  • Avast Überevangelist
  • Certainly Bot
  • *****
  • Posts: 89286
  • No support PMs thanks
Re: Outwitting Conficked blocked sites..........
« Reply #5 on: April 04, 2009, 03:55:16 PM »
Why are you spamming the forums with these commercial links in your posts, advertising is against the forums rules, spammers will be reported.
Windows 10 Home 64bit/ Acer Aspire F15/ Intel Core i5 7200U 2.5GHz, 8GB DDR4 memory, 256GB SSD, 1TB HDD/ avast! free 24.5.6116 (build 24.5.9153.762) UI 1.0.808/ Firefox, uBlock Origin, uMatrix/ MailWasher Pro/ Avast! Mobile Security