<?xml version="1.0" encoding="UTF-8"?><rss version="2.0"
	xmlns:content="http://purl.org/rss/1.0/modules/content/"
	xmlns:dc="http://purl.org/dc/elements/1.1/"
	xmlns:atom="http://www.w3.org/2005/Atom"
	xmlns:sy="http://purl.org/rss/1.0/modules/syndication/"
	xmlns:itunes="http://www.itunes.com/dtds/podcast-1.0.dtd"
	xmlns:media="http://search.yahoo.com/mrss/"
	>
<channel>
	<title>Comments on: Rogue DNS Servers on the Move</title>
	<atom:link href="http://asert.arbornetworks.com/2008/11/rogue-dns-servers-on-the-move/feed/" rel="self" type="application/rss+xml" />
	<link>http://asert.arbornetworks.com/2008/11/rogue-dns-servers-on-the-move/</link>
	<description>A weblog dedicated to educating the community on security threats that matter</description>
	<lastBuildDate>Fri, 23 Jul 2010 13:52:39 +0000</lastBuildDate>
	<sy:updatePeriod>hourly</sy:updatePeriod>
	<sy:updateFrequency>1</sy:updateFrequency>
	<generator>http://wordpress.org/?v=abc</generator>
	<item>
		<title>By: KevHog</title>
		<link>http://asert.arbornetworks.com/2008/11/rogue-dns-servers-on-the-move/comment-page-1/#comment-219723</link>
		<dc:creator>KevHog</dc:creator>
		<pubDate>Wed, 22 Jul 2009 12:58:05 +0000</pubDate>
		<guid isPermaLink="false">http://asert.arbornetworks.com/?p=521#comment-219723</guid>
		<description>dirt bags got me too. 1. on another machine download Microsoft Windows Defender and the &#039;malicious Software removal tool&#039; to a USB / Pen drive. 2. on the infected machine change your DNS and install the two apps. Run them and you should be right.
There are other articles on the net for Malware Bytes but I could not get these running with the infection. Windows defender picks up this one but misses plenty more. Tool of choice for this mission</description>
		<content:encoded><![CDATA[<p>dirt bags got me too. 1. on another machine download Microsoft Windows Defender and the &#8216;malicious Software removal tool&#8217; to a USB / Pen drive. 2. on the infected machine change your DNS and install the two apps. Run them and you should be right.<br />
There are other articles on the net for Malware Bytes but I could not get these running with the infection. Windows defender picks up this one but misses plenty more. Tool of choice for this mission</p>
]]></content:encoded>
	</item>
	<item>
		<title>By: Prabu</title>
		<link>http://asert.arbornetworks.com/2008/11/rogue-dns-servers-on-the-move/comment-page-1/#comment-184750</link>
		<dc:creator>Prabu</dc:creator>
		<pubDate>Fri, 12 Dec 2008 13:23:08 +0000</pubDate>
		<guid isPermaLink="false">http://asert.arbornetworks.com/?p=521#comment-184750</guid>
		<description>Hi Guys.. I got this trojan too.. please let us know if there is any cure to this.. My system is running very slow becoz of this...cant reinstall computer as this is running very important programs</description>
		<content:encoded><![CDATA[<p>Hi Guys.. I got this trojan too.. please let us know if there is any cure to this.. My system is running very slow becoz of this&#8230;cant reinstall computer as this is running very important programs</p>
]]></content:encoded>
	</item>
	<item>
		<title>By: ckhown</title>
		<link>http://asert.arbornetworks.com/2008/11/rogue-dns-servers-on-the-move/comment-page-1/#comment-184482</link>
		<dc:creator>ckhown</dc:creator>
		<pubDate>Thu, 11 Dec 2008 03:10:00 +0000</pubDate>
		<guid isPermaLink="false">http://asert.arbornetworks.com/?p=521#comment-184482</guid>
		<description>Me, also have same problem DNS 85.255.112.61. i have try to set back my original local DNS, but after restart pc, it&#039;s will be automatic set back to 85.255.112.61... anyone know how to kill this thing &gt;</description>
		<content:encoded><![CDATA[<p>Me, also have same problem DNS 85.255.112.61. i have try to set back my original local DNS, but after restart pc, it&#8217;s will be automatic set back to 85.255.112.61&#8230; anyone know how to kill this thing &gt;</p>
]]></content:encoded>
	</item>
	<item>
		<title>By: bayden</title>
		<link>http://asert.arbornetworks.com/2008/11/rogue-dns-servers-on-the-move/comment-page-1/#comment-184407</link>
		<dc:creator>bayden</dc:creator>
		<pubDate>Wed, 10 Dec 2008 20:40:24 +0000</pubDate>
		<guid isPermaLink="false">http://asert.arbornetworks.com/?p=521#comment-184407</guid>
		<description>This is malware but removing it as of today is a problem.  I have now seen this on 4 PC&#039;s in one office of about 40. My question is, can the internal DNS server be some how populating clients (even if static as I have tested) populating DNS Servers as such - 85.255.113.112.91 and 85.255.113.91. The static setting does have the local DNS server which is 192.168.0.10 and it does not use this address dynamically or statically.

Is this a global threat or vulneralbility with Misrosoft DNS servers?? Is there a way to block any inbound queries?  

I&#039;m experiencing same issues as listed above.

Regards,</description>
		<content:encoded><![CDATA[<p>This is malware but removing it as of today is a problem.  I have now seen this on 4 PC&#8217;s in one office of about 40. My question is, can the internal DNS server be some how populating clients (even if static as I have tested) populating DNS Servers as such &#8211; 85.255.113.112.91 and 85.255.113.91. The static setting does have the local DNS server which is 192.168.0.10 and it does not use this address dynamically or statically.</p>
<p>Is this a global threat or vulneralbility with Misrosoft DNS servers?? Is there a way to block any inbound queries?  </p>
<p>I&#8217;m experiencing same issues as listed above.</p>
<p>Regards,</p>
]]></content:encoded>
	</item>
	<item>
		<title>By: Sascha</title>
		<link>http://asert.arbornetworks.com/2008/11/rogue-dns-servers-on-the-move/comment-page-1/#comment-184218</link>
		<dc:creator>Sascha</dc:creator>
		<pubDate>Tue, 09 Dec 2008 18:48:32 +0000</pubDate>
		<guid isPermaLink="false">http://asert.arbornetworks.com/?p=521#comment-184218</guid>
		<description>Hey I have the same shit Problem!!!
The DNS is always on manual....no change to auto possible!
need help</description>
		<content:encoded><![CDATA[<p>Hey I have the same shit Problem!!!<br />
The DNS is always on manual&#8230;.no change to auto possible!<br />
need help</p>
]]></content:encoded>
	</item>
	<item>
		<title>By: Devidas Khurd</title>
		<link>http://asert.arbornetworks.com/2008/11/rogue-dns-servers-on-the-move/comment-page-1/#comment-183855</link>
		<dc:creator>Devidas Khurd</dc:creator>
		<pubDate>Sun, 07 Dec 2008 21:00:43 +0000</pubDate>
		<guid isPermaLink="false">http://asert.arbornetworks.com/?p=521#comment-183855</guid>
		<description>Currently I am facing the same problem with my internet connectivity. I checked my IP config,the DNS server is presetting to 85 . 255 . 112 . 205.I have changed but no use.Still its pre-setting to 85 . 255 . 112 . 205.

Can anyone suggest how to resolve the same problem.</description>
		<content:encoded><![CDATA[<p>Currently I am facing the same problem with my internet connectivity. I checked my IP config,the DNS server is presetting to 85 . 255 . 112 . 205.I have changed but no use.Still its pre-setting to 85 . 255 . 112 . 205.</p>
<p>Can anyone suggest how to resolve the same problem.</p>
]]></content:encoded>
	</item>
	<item>
		<title>By: Lyrix</title>
		<link>http://asert.arbornetworks.com/2008/11/rogue-dns-servers-on-the-move/comment-page-1/#comment-181538</link>
		<dc:creator>Lyrix</dc:creator>
		<pubDate>Tue, 25 Nov 2008 22:31:24 +0000</pubDate>
		<guid isPermaLink="false">http://asert.arbornetworks.com/?p=521#comment-181538</guid>
		<description>It took me forever to work this out. I&#039;m not particularily an expert on computers, but I had a problem that all searches I made on google redirected me to a phishing website when I clicked a link. Basically, it brought up the right searches, but every link was a phishing link. Eventually I had a problem with my internet and checked my IP Config, and I saw my DNS server was pre-set to &quot;85 . 255 . 112 . 123&quot;. After changing it back to automatic, this no longer happened. It also prevented any Microsoft applications downloading, and also AVG from updating. Nothing malicious, but I wanted to share my personal experience with you about it, because it was annoying.</description>
		<content:encoded><![CDATA[<p>It took me forever to work this out. I&#8217;m not particularily an expert on computers, but I had a problem that all searches I made on google redirected me to a phishing website when I clicked a link. Basically, it brought up the right searches, but every link was a phishing link. Eventually I had a problem with my internet and checked my IP Config, and I saw my DNS server was pre-set to &#8220;85 . 255 . 112 . 123&#8243;. After changing it back to automatic, this no longer happened. It also prevented any Microsoft applications downloading, and also AVG from updating. Nothing malicious, but I wanted to share my personal experience with you about it, because it was annoying.</p>
]]></content:encoded>
	</item>
	<item>
		<title>By: Liquidmatrix Security Digest &#187; Security Briefing: November 21st</title>
		<link>http://asert.arbornetworks.com/2008/11/rogue-dns-servers-on-the-move/comment-page-1/#comment-180276</link>
		<dc:creator>Liquidmatrix Security Digest &#187; Security Briefing: November 21st</dc:creator>
		<pubDate>Fri, 21 Nov 2008 14:06:20 +0000</pubDate>
		<guid isPermaLink="false">http://asert.arbornetworks.com/?p=521#comment-180276</guid>
		<description>[...] Rogue DNS Servers on the Move &#124; Security to the Core [...]</description>
		<content:encoded><![CDATA[<p>[...] Rogue DNS Servers on the Move | Security to the Core [...]</p>
]]></content:encoded>
	</item>
</channel>
</rss>
