Snapple's profile

New Contributor

 • 

2 Messages

Closed

Zeus Zbot Cox pop up

2 computers got a pop from cox (verified) that we had a device infected with Zeus on our network.  I ran Norton zbot removal, Norton power erase, norton scan, malwarebyte, spybot, avg zbot removal, and microsoft security scanner.  nothing.  Can someone tell me what to look for in the cmd>netstat -a (-o or -r) command. 

New Contributor

 • 

82 Messages

The very brief research I did seems to indicate that the actual bot will transmit and/or receive a bunch of UDP traffic on a wide variety of port ranges.

My best suggestion would be to throw a strong software firewall, such as Comodo, on the devices and watch the UDP traffic.  You might also be able to find that via netstat or your router's log.

Valued Contributor III

 • 

4.2K Messages

I would try turning off or disabling all your known connections and then see if the router has a netstat or some kind of traffic logging system. What ever traffic you see left I would be suspicious on. 

As for ports, I don't think  the warning is triggered that way. Instead, I think it's based on a DNS request for certain domains that the infection uses to "dial home", so maybe start by looking at port 53?

Moderator

 • 

4.3K Messages

Hi Shar103,

Disabling all known connections as Health Edge suggested and looking for continued traffic is a good plan. What router are you using?

Do you have the latest Norton updates installed on both computers? Are full Norton scans now showing no infections? Since you are using Norton, you might want to check their Zeus support site and their other array of online tools.