As it stands now, on Linksys routers, to avoid the exploit, set UPnP to 'DISABLED'.
Even though you only posted '85' as part of the DNS entry that you cleared out, I'd bet money that the second set of numbers was 255, i.e., '85.255.xxx.xxx which are InHoster servers. Wareout, which is a DNS...