Xxian's profile

New Contributor

 • 

6 Messages

Closed

Zeus browser alert link goes nowhere.

Is anyone else getting Cox browser alerts for Zeus? This has been going on for 2 days. When I click the link for the 'zeus browser alert page', I am taken to the main Cox page of advertisements.

Former Moderator

 • 

7.1K Messages

You're most likely seeing that because a device connected to your router or modem is communicating with a known Zeus botnet host.  I contacted our network security team and they have reported the problem with the link you were clicking and emailed you at both of your email addresses on file with more information concerning next steps to take.

New Contributor

 • 

1 Message

I'm getting the same problem too

New Contributor

 • 

6 Messages

I got three emails regarding from the forums, none of which had any instructions on what to do. I have the free AVG that runs every day and has reported no problems. Do I need to delay online banking/bill pay until this is resolved?

New Contributor

 • 

6 Messages

The only device connected to my modem is this desktop. I disconnected the wireless router until I get my phone fixed. That was done 2 months ago. If there is a problem, it is with this PC.

New Contributor

 • 

6 Messages

By the way, the only place that I was getting them was on the KOCO news articles accessed through facebook. I tested twice today and the alerts no longer happen. Please advise.

New Contributor

 • 

2 Messages

I just saw the same COX popup this morning about Zeus. I have two computers in the network and neither show a Zeus virus under MSE (Microsoft Security Essentials) or Malwarebytes. Not sure if  the alert is false or what is going on

Valued Contributor III

 • 

4.2K Messages

ChrisL said:
and emailed you at both of your email addresses on file with more information concerning next steps to take.

Could you post the steps here? Specifically what port is being listened to? Or are the steps specific for each person?"

New Contributor

 • 

6 Messages

This is what they sent me. I am using the microsoft one now. Maybe I'm too old school, but it seems a bit unreal to me that neither of those links to Microsoft or Symantec are using an encrypted connection. For that matter, neither is the connection to this forum. "This website does not provide identity information" on all three connections. smh

Dear Subscriber,
Cox has identified that one or more of the computers behind your cable modem are likely infected with the Zeus Trojan/bot, also known as Zbot.
While this malicious software is not new, it still poses a great risk to your computer and files that reside on your hard drive.
Zeus malware uses keylogging in order to access user names and passwords and infected over 13 million computers worldwide.
We recommend you take the following action:
1. Visit the Microsoft or Symantec website, download and run the FREE removal tool. The web addresses are:
http://www.microsoft.com/security/scanner/en-us/default.aspx
http://www.symantec.com/security_response/writeup.jsp?docid=2014-052915-1402-99
These tools does a great job of finding and cleaning many types of malicious software that may reside on your systems and will specifically target Zeus.
After running the free Microsoft removal tool, if you already have security software installed on your system:
2) Follow your security software's instructions to download the latest updates (also known as "virus definitions")
3) When the new definitions have been loaded, perform a full virus scan on your system.
If you do not already have security software on your computer, we recommend the Cox Security Suite powered by McAfee, which is included at no extra charge with your service.
To install the Cox Security Suite powered by McAfee:
1) Visit https://myaccount.cox.net/ and click on Internet Tools
2) Log-in with your primary account User ID
3) Select the Security Suite link to download and install the software
4) When the install is complete, the program will automatically conduct a full scan
If you have any questions regarding this matter, please call us at 800-753-6085 and provide the reference number provided in the subject of this email.
If you would like additional information on the Zeus botnet we recommend these articles:
http://www.us-cert.gov/ncas/alerts/TA14-150A
http://www.eweek.com/c/a/Security/Microsoft-Targets-Zeus-Botnets-with-Financial-Services-Partners-544534/
http://www.computerworld.com/s/article/9190758/Microsoft_tool_now_roots_out_Zeus_malware
Regards,
Cox Customer Safety

New Contributor

 • 

2 Messages

I agree on the https connections.

Small update but still not finding the virus

I ran MSE and Malwarebytes as state in my previous comment

I ran TrendMicro Housecall and Avira yesterday. Avira took >2 hrs to scan all my files.

Some questions

1) If you have two computers on the network and only one has been used for the last 5 days when the Cox alert popup showed, does that mean the alert should be related to that computer that was being used?

2) Would the Cox alert popup show every ime you use your computer to surf the internet if it wasn't removed or does the alert only show once or at a specific time?

3) From what I read Zeus can be very hard to detect ie 23% success rate with most virus checkers. There doesn't seem to be a clear way to check for it for 100%?

4) If the virus is not on my computers, what else would cause the alert popup to show as it did?

New Contributor

 • 

6 Messages

I have run both of the things they sent me. The one from Microsoft found nothing and the Symantec found nothing. Symantec recommended running the Norton Scrubber but would only download the 32 bit and I have 64 bit. The 32 bit just stalls out and you have to ctrl/alt/del out of it.
I have come to the conclusion that this is a Cox error and we never had the virus.

New Contributor

 • 

2 Messages

I think this is definitely some kind of error in the algorithm they use to scan for virus' on their end, because from what i've read Zeus only affects Windows machines, and i currently only have a MacBook Air, iPhone and iPad connected to my router. 

I started getting a popup in Safari today. 

My connection is very secure and i use Little Snitch to monitor my traffic. 

So i think the problem is in Cox's Virus checking protocol.

New Contributor

 • 

4 Messages

I got the same pop up and the link went nowhere. I have Avast on the running computer and a Malwarebyte and Avast scan show nothing. I only got the pop up once.

New Contributor

 • 

21 Messages

Yesterday, I saw the Cox browser alert about the Zeus virus.

http://ibncs.cox.net/ibncs/general/message.cox?MessageName=abuse-zeus

These applications report no problems.

* Avast! Free Antivirus
* Malwarebytes Anti-Malware
* Microsoft Windows Malicious Software Removal Tool
* Comodo Firewall

Microsoft Windows 7 SP1 32-bit (fully patched)

No one here found the Zeus virus on their computer?!

Valued Contributor III

 • 

4.2K Messages

Elsie said:
These applications report no problems.

Have you tried the scanners designed to specifically to detect the malware. Here is the Norton tool, and here is the AVG tool, but there is one for most major Antivirus out there.

New Contributor

 • 

21 Messages

Health Edge said:
Have you tried the scanners designed to specifically to detect the malware.

These tools report no infections.

* AVG Free Virus Remover for Win32/Zbot
* Symantec Necurs Driver Removal Tool
* Norton Power Eraser

Thanks for reply.

Related Content

  • Closed

    1

    0

  • Closed

    7

    0

  • Closed

    1

    0

  • Closed

    1

    0

  • Closed

    1

Recent Discussions

View More

Loading...