Our November Competition
User Reviews - Add Yours!
The PCHF Lounge
Go Back   PC Help Forum » Security & Safety » [Pending] HJT Logs
Register for a Free Account

[Pending] HJT Logs - E-mail issue that involves firewall posted in the Security & Safety forums; This question involves e-mail and firewalls so I am posting it in each forum. I run XP Home 2002 SP2. I have the latest version of Zone Alarm Free installed ...


Reply
Recommended Driver Scanner
Old 09-10-2008   #1
Bronze Member
 
Join Date: Sep 2008
Posts: 5
PC Experience: Experienced
Default E-mail issue that involves firewall

This question involves e-mail and firewalls so I am posting it in each forum.

I run XP Home 2002 SP2. I have the latest version of Zone Alarm Free installed along with AVG Free 8.0. I also scan with Ad-Aware and SpyBot. I use Mozilla Thunderbird for my e-mail.

My issue is that Thunderbird seems to be doing an "end run" around Zone Alarm. Even though Thunderbird is listed in Zone Alarm as an "ask permission" program, it will get e-mail without ever asking permission.

Just to back up a but, I had several problems before I recently updated my Zone Alarm. My AVG update would not connect, Internet Explorer would not always open when clicked, and 3 of my 4 e-mail accounts would not download mail. (Oddly they would send but could not receive.) And when my one e-mail account would work, it did not ask permission through Zone Alarm like its supposed to.

I decided to upgrade Zone Alarm to see if it fixed things and it seemed to. IE worked fine. My AVG updates fine. Even my Thunderbird e-mail was asking permission to get on the internet, but that lasted only one day.

Now Thunderbird is back to accessing the internet without asking permission from Zone Alarm. How is this possible? Could I have a virus or malware that is rerouting my internet ports? Any input would be welcomed.

Promo
promorobot is offline   Reply With Quote
Advertisement - Register to Remove
Old 09-10-2008   #2
Gold Member
 
norris7850's Avatar
 
Join Date: May 2007
Location: Bath,South west UK
Posts: 229
PC Experience: Im learning more and more through PCHF!
Default Re: E-mail issue that involves firewall

Hi promorobot,

Very warm welcome to PCHF!

Looks like were really busy at the mo so ill help you get started.
seeing as we think there may be Malware/Virus involved please can you complete the prework in my signature and post back the Hijackthis log and then one of our expert security analysts will take a look.

I have moved your thread to the HJT forum

Many thanks,

Matt
__________________
Pre-Work
> Did we help you? If we did,Say thanks by rating the posts or please consider A Donation
norris7850 is offline   Reply With Quote
Old 09-10-2008   #3
Bronze Member
 
Join Date: Sep 2008
Posts: 5
PC Experience: Experienced
Default e-mail goes around zone alrm program control

My e-mail (Mozilla Thunderbird) has begun to "go around" my Zone Alarm program control. Meaning when I start e-mail, I no longer get a "permission" window from Zone Alarm asking if I should allow Thunderbird access to the internet. Thunderbird is on the Zone Alarm program list. I recently updated Zone Alarm and my e-mail went through Zone Alarm once, now no more. Any ideas?

Logfile of HijackThis v1.99.1
Scan saved at 3:13:17 PM, on 9/10/2008
Platform: Windows XP SP2 (WinNT 5.01.2600)
MSIE: Internet Explorer v6.00 SP2 (6.00.2900.2180)

Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\Ati2evxx.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\system32\Ati2evxx.exe
C:\WINDOWS\Explorer.EXE
C:\WINDOWS\system32\spoolsv.exe
c:\program files\common files\logitech\lvmvfm\LVPrcSrv.exe
C:\PROGRA~1\AVG\AVG8\avgwdsvc.exe
C:\Program Files\Common Files\LightScribe\LSSrvc.exe
C:\WINDOWS\system32\WDBtnMgr.exe
C:\Program Files\Synaptics\SynTP\SynTPLpr.exe
C:\Program Files\Synaptics\SynTP\SynTPEnh.exe
C:\Program Files\ATI Technologies\ATI Control Panel\atiptaxx.exe
C:\Program Files\D-Tools\daemon.exe
C:\PROGRA~1\AVG\AVG8\avgtray.exe
C:\Program Files\Zone Labs\ZoneAlarm\zlclient.exe
C:\Program Files\iolo\System Mechanic 6\SMSystemAnalyzer.exe
C:\Program Files\Dantz\Retrospect\retrorun.exe
C:\Program Files\Spybot - Search & Destroy\TeaTimer.exe
C:\WINDOWS\system32\ctfmon.exe
C:\PROGRA~1\Dantz\RETROS~1\wdsvc.exe
C:\WINDOWS\system32\svchost.exe
C:\Program Files\DNA\btdna.exe
C:\Program Files\Hawking Technologies\Hawking_HWU54G_Utility\HWU54G.exe
C:\PROGRA~1\AVG\AVG8\avgrsx.exe
C:\PROGRA~1\AVG\AVG8\avgemc.exe
C:\WINDOWS\system32\taskmgr.exe
C:\WINDOWS\system32\ZoneLabs\vsmon.exe
C:\WINDOWS\system32\wuauclt.exe
C:\Program Files\Mozilla Thunderbird\thunderbird.exe
C:\Program Files\Mozilla Firefox\firefox.exe
C:\Program Files\Adobe\Acrobat 6.0\Reader\AcroRd32.exe
C:\WINDOWS\system32\WISPTIS.EXE
C:\WINDOWS\eFaxView.exe
C:\Program Files\Microsoft Office\Office12\WINWORD.EXE
C:\Program Files\Cooledit\coolpro.exe
C:\Program Files\Windows NT\Accessories\wordpad.exe
C:\Program Files\Internet Explorer\IEXPLORE.EXE
C:\Program Files\HijackThis\HijackThis.exe

R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = Yahoo!
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = AOL.com - Welcome to AOL
R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Local Page =
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Local Page =
O2 - BHO: AcroIEHlprObj Class - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Adobe\Acrobat 6.0\Reader\ActiveX\AcroIEHelper.dll
O2 - BHO: WormRadar.com IESiteBlocker.NavFilter - {3CA2F312-6F6E-4B53-A66E-4E65E497C8C0} - C:\Program Files\AVG\AVG8\avgssie.dll
O2 - BHO: Spybot-S&D IE Protection - {53707962-6F74-2D53-2644-206D7942484F} - C:\PROGRA~1\SPYBOT~1\SDHelper.dll
O2 - BHO: Google Toolbar Helper - {AA58ED58-01DD-4d91-8333-CF10577473F7} - c:\program files\google\googletoolbar1.dll
O2 - BHO: ZoneAlarm Spy Blocker BHO - {F0D4B231-DA4B-4daf-81E4-DFEE4931A4AA} - C:\Program Files\ZoneAlarmSB\bar\1.bin\SPYBLOCK.DLL
O3 - Toolbar: &Google - {2318C2B1-4965-11d4-9B18-009027A5CD4F} - c:\program files\google\googletoolbar1.dll
O3 - Toolbar: ZoneAlarm Spy Blocker - {F0D4B239-DA4B-4daf-81E4-DFEE4931A4AA} - C:\Program Files\ZoneAlarmSB\bar\1.bin\SPYBLOCK.DLL
O4 - HKLM\..\Run: [WD Button Manager] WDBtnMgr.exe
O4 - HKLM\..\Run: [SynTPLpr] C:\Program Files\Synaptics\SynTP\SynTPLpr.exe
O4 - HKLM\..\Run: [SynTPEnh] C:\Program Files\Synaptics\SynTP\SynTPEnh.exe
O4 - HKLM\..\Run: [ATIPTA] C:\Program Files\ATI Technologies\ATI Control Panel\atiptaxx.exe
O4 - HKLM\..\Run: [DAEMON Tools-1033] "C:\Program Files\D-Tools\daemon.exe" -lang 1033
O4 - HKLM\..\Run: [ioloDelayModule] C:\Program Files\iolo\System Mechanic 6\delay.exe
O4 - HKLM\..\Run: [AVG8_TRAY] C:\PROGRA~1\AVG\AVG8\avgtray.exe
O4 - HKLM\..\Run: [ZoneAlarm Client] "C:\Program Files\Zone Labs\ZoneAlarm\zlclient.exe"
O4 - HKCU\..\Run: [SMSystemAnalyzer] "C:\Program Files\iolo\System Mechanic 6\SMSystemAnalyzer.exe"
O4 - HKCU\..\Run: [SpybotSD TeaTimer] C:\Program Files\Spybot - Search & Destroy\TeaTimer.exe
O4 - HKCU\..\Run: [ctfmon.exe] C:\WINDOWS\system32\ctfmon.exe
O4 - HKCU\..\Run: [BitTorrent DNA] "C:\Program Files\DNA\btdna.exe"
O4 - Global Startup: Hawking HWU54G Utility.lnk = C:\Program Files\Hawking Technologies\Hawking_HWU54G_Utility\HWU54G.exe
O8 - Extra context menu item: E&xport to Microsoft Excel - res://C:\PROGRA~1\MICROS~4\Office12\EXCEL.EXE/3000
O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.5.0_02\bin\npjpi150_02.dll
O9 - Extra 'Tools' menuitem: Sun Java Console - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.5.0_02\bin\npjpi150_02.dll
O9 - Extra button: Research - {92780B25-18CC-41C8-B9BE-3C9C571A8263} - C:\PROGRA~1\MICROS~4\Office12\REFIEBAR.DLL
O9 - Extra button: (no name) - {DFB852A3-47F8-48C4-A200-58CAB36FD2A2} - C:\PROGRA~1\SPYBOT~1\SDHelper.dll
O9 - Extra 'Tools' menuitem: Spybot - Search & Destroy Configuration - {DFB852A3-47F8-48C4-A200-58CAB36FD2A2} - C:\PROGRA~1\SPYBOT~1\SDHelper.dll
O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O14 - IERESET.INF: START_PAGE_URL=http://ie.redirect.hp.com/svs/rdr?TYPE=3&tp=iehome&locale=EN_US&c=Q305&bd=presar io&pf=laptop
O16 - DPF: {14C1B87C-3342-445F-9B5E-365FF330A3AC} (Hewlett-Packard Online Support Services) - http://h20278.www2.hp.com/HPISWeb/Cu...ataManager.CAB
O16 - DPF: {4EC99A0B-E57C-4FBE-B9C4-8428424FBF88} (McciUtilsSpecialFolder Class) - http://supportcenter.verizon.net/euserv/jsp/VOLAWeb.cab
O16 - DPF: {4F1E5B1A-2A80-42CA-8532-2D05CB959537} (MSN Photo Upload Tool) - http://by19fd.bay19.hotmail.msn.com/...s/MsnPUpld.cab
O16 - DPF: {9600F64D-755F-11D4-A47F-0001023E6D5A} (Shutterfly Picture Upload Plugin) - http://web1.shutterfly.com/downloads/Uploader.cab
O16 - DPF: {9A9307A0-7DA4-4DAF-B042-5009F29E09E1} (ActiveScan Installer Class) - http://acs.pandasoftware.com/actives...ree/asinst.cab
O18 - Protocol: linkscanner - {F274614C-63F8-47D5-A4D1-FBDDE494F8D1} - C:\Program Files\AVG\AVG8\avgpp.dll
O18 - Protocol: livecall - {828030A1-22C1-4009-854F-8E305202313F} - C:\PROGRA~1\MSNMES~1\MSGRAP~1.DLL
O18 - Protocol: ms-help - {314111C7-A502-11D2-BBCA-00C04F8EC294} - C:\Program Files\Common Files\Microsoft Shared\Help\hxds.dll
O18 - Protocol: msnim - {828030A1-22C1-4009-854F-8E305202313F} - C:\PROGRA~1\MSNMES~1\MSGRAP~1.DLL
O18 - Filter hijack: text/xml - {807563E5-5146-11D5-A672-00B0D022E945} - C:\PROGRA~1\COMMON~1\MICROS~1\OFFICE12\MSOXMLMF.DL L
O20 - AppInit_DLLs: avgrsstx.dll
O20 - Winlogon Notify: WgaLogon - C:\WINDOWS\SYSTEM32\WgaLogon.dll
O23 - Service: Ati HotKey Poller - ATI Technologies Inc. - C:\WINDOWS\system32\Ati2evxx.exe
O23 - Service: AVG Free8 E-mail Scanner (avg8emc) - AVG Technologies CZ, s.r.o. - C:\PROGRA~1\AVG\AVG8\avgemc.exe
O23 - Service: AVG Free8 WatchDog (avg8wd) - AVG Technologies CZ, s.r.o. - C:\PROGRA~1\AVG\AVG8\avgwdsvc.exe
O23 - Service: Google Updater Service (gusvc) - Google - C:\Program Files\Google\Common\Google Updater\GoogleUpdaterService.exe
O23 - Service: HP WMI Interface (hpqwmi) - Hewlett-Packard Development Company, L.P. - C:\Program Files\HPQ\SHARED\HPQWMI.exe
O23 - Service: LightScribeService Direct Disc Labeling Service (LightScribeService) - Unknown owner - C:\Program Files\Common Files\LightScribe\LSSrvc.exe
O23 - Service: Process Monitor (LVPrcSrv) - Logitech Inc. - c:\program files\common files\logitech\lvmvfm\LVPrcSrv.exe
O23 - Service: LVSrvLauncher - Logitech Inc. - C:\Program Files\Common Files\Logitech\SrvLnch\SrvLnch.exe
O23 - Service: Pml Driver HPZ12 - HP - C:\WINDOWS\system32\HPZipm12.exe
O23 - Service: Intuit QuickBooks FCS (QBFCService) - Intuit Inc. - C:\Program Files\Common Files\Intuit\QuickBooks\FCS\Intuit.QuickBooks.FCS. exe
O23 - Service: Retrospect Launcher (RetroLauncher) - Dantz Development Corporation - C:\Program Files\Dantz\Retrospect\retrorun.exe
O23 - Service: Retrospect WD Service (RetroWDSvc) - Dantz Development Corporation - C:\PROGRA~1\Dantz\RETROS~1\wdsvc.exe
O23 - Service: TrueVector Internet Monitor (vsmon) - Zone Labs, LLC - C:\WINDOWS\system32\ZoneLabs\vsmon.exe

promorobot is offline   Reply With Quote
Old 09-10-2008   #4
Gold Member
 
norris7850's Avatar
 
Join Date: May 2007
Location: Bath,South west UK
Posts: 229
PC Experience: Im learning more and more through PCHF!
Default Re: E-mail issue that involves firewall

Thanks for this promorobot, ill ask a tech to take a look.

Apologies about the delay
__________________
Pre-Work
> Did we help you? If we did,Say thanks by rating the posts or please consider A Donation
norris7850 is offline   Reply With Quote
Old 09-10-2008   #5
Site Manager
 
madmonkey's Avatar
 
Join Date: Oct 2006
Location: South Wales
Posts: 8,984
PC Experience: ...
Default Re: E-mail issue that involves firewall

Hey Prom,

I'm just trying to find you a tech who has a little more experience with Zone Alarm. Not personally keen on it myself. However, can you tell us what the purpose would be of blocking an application you intend on using? I can think of a few very small reasons, but nothing that would explain the hasle of accepting each and every single e-mail that comes in and out? I would bug me!

Also remember that Zone Alarm is capable of blocking ports as well as applications. Is port 25 or 110 listed there, and what settings do you have assigned to them?
__________________

madmonkey is offline   Reply With Quote
Old 09-11-2008   #6
Senior Security Analyst
 
Pancake's Avatar
 
Join Date: Jun 2006
Location: Victoria, Australia
Posts: 6,867
PC Experience: Elite PC Guru
Default Re: E-mail issue that involves firewall

I dont see any sign of malware.It looks fine.
__________________
  • An Australian Member of
  • and
My real name is Eddy
Pancake is online now   Reply With Quote
Old 09-11-2008   #7
Bronze Member
 
Join Date: Sep 2008
Posts: 5
PC Experience: Experienced
Default Re: E-mail issue that involves firewall

Originally Posted by madmonkey View Post
Hey Prom,

I'm just trying to find you a tech who has a little more experience with Zone Alarm. Not personally keen on it myself. However, can you tell us what the purpose would be of blocking an application you intend on using? I can think of a few very small reasons, but nothing that would explain the hasle of accepting each and every single e-mail that comes in and out? I would bug me!

Also remember that Zone Alarm is capable of blocking ports as well as applications. Is port 25 or 110 listed there, and what settings do you have assigned to them?
Zone Alarm is a firewall that prevents any unauthorized access to or from the internet by a program that could be hijacked. So if you set a program to ask permission, a window will pop up asking you want Mozilla Thunderbird or Internet Explorer to have access to the internet at that moment. It's handy to know what programs are secretly "phoning home."

Ports are something I'm not too knowledgeable of. I don't really understand them, but I figured there must be something going on if my e-mail program can suddenly access the internet without asking for permission from Zone Alarm first.

Someone just posted that nothing suspicious seems to be on my HJT log. Everything seems to work okay. This e-mail/firewall issue is not keeping me from working, but I'd just like to know what is going on.

PR
promorobot is offline   Reply With Quote

Reply


Bookmarks

Tags
alrm, control, email, firewall, involves, issue, program, zone

Thread Tools
Display Modes

Posting Rules
You may not post new threads
You may not post replies
You may not post attachments
You may not edit your posts

BB code is On
Smilies are On
[IMG] code is On
HTML code is Off
Trackbacks are Off
Pingbacks are Off
Refbacks are On




All times are GMT. The time now is 04:57 AM.
Powered by vBulletin
Copyright ©2000 - 2009, Jelsoft Enterprises Ltd.
SEO by vBSEO 3.3.2