As you wish, don.

Countermeasures against DNSChanger:
1) Change your router default password to something complex. Make sure it's long, and contains symbols and numbers.
2) Configure your router to allow management access from specific machine only (e.g, Admin PC), this will prevent infected machines from reaching your router.
3) Update the current firmware to fix any security issues.
4) If possible, change the management port to something else. (e.g, port 80/443 to 555)
5) Configure Syslog/SNMP on the router to watch any configuration modifications or failed login.
6) Rename the admin account on the router, Or see next.
7) Disable/delete admin account, and create another one with different name and password.
8 ) Deploy an IDS on your network to detect malicious activities (e.g, router user/pass brute force attack / requests to rogue dns servers / video codec downloads )
9) Deploy an URL filtering software/appliance that filters access to any malicious websites/pages that provides codec/fake codecs.
10) Disable UPNP on your router, becuase it's not secure anymore. check here:
http://www.google.com/search?hl=en&q=upnp+exploit+router11) Block access to these IP's (85.255.116.164 / 85.255.112.81)
12) Use Purenetwork Security scan for wireless networks,
http://www.purenetworks.com/securityscan/13) Keep your machines up-to-date. Most malwares targets a specific vulnerability to reach the system.
14) Get legitimate video codecs, install them on your machines, and inform your users that their machines are ready to play any video format and there is no need to download codecs from untrusted sites. check
http://www.free-codecs.com/download/K_lite_codec_pack.htmSafe browsing ...
