This question involves e-mail and firewalls so I am posting it in each forum.
I run XP Home 2002 SP2. I have the latest version of Zone Alarm Free installed along with AVG Free 8.0. I also scan with Ad-Aware and SpyBot. I use Mozilla Thunderbird for my e-mail.
My issue is that Thunderbird seems to be doing an "end run" around Zone Alarm. Even though Thunderbird is listed in Zone Alarm as an "ask permission" program, it will get e-mail without ever asking permission.
Just to back up a but, I had several problems before I recently updated my Zone Alarm. My AVG update would not connect, Internet Explorer would not always open when clicked, and 3 of my 4 e-mail accounts would not download mail. (Oddly they would send but could not receive.) And when my one e-mail account would work, it did not ask permission through Zone Alarm like its supposed to.
I decided to upgrade Zone Alarm to see if it fixed things and it seemed to. IE worked fine. My AVG updates fine. Even my Thunderbird e-mail was asking permission to get on the internet, but that lasted only one day.
Now Thunderbird is back to accessing the internet without asking permission from Zone Alarm. How is this possible? Could I have a virus or malware that is rerouting my internet ports? Any input would be welcomed.
Promo
![]() |
|
|||||||
| [Pending] HJT Logs - E-mail issue that involves firewall posted in the Security & Safety forums; This question involves e-mail and firewalls so I am posting it in each forum. I run XP Home 2002 SP2. I have the latest version of Zone Alarm Free installed ... |
|
|
|
#1 |
|
Bronze Member
![]() ![]() Join Date: Sep 2008
Posts: 5 PC Experience: Experienced
|
|
|
|
|
| Advertisement - Register to Remove | |
|
|
|
#2 |
|
Gold Member
![]() ![]() Join Date: May 2007
Location: Bath,South west UK
Posts: 229 PC Experience: Im learning more and more through PCHF!
|
Hi promorobot,
Very warm welcome to PCHF! ![]() Looks like were really busy at the mo so ill help you get started. seeing as we think there may be Malware/Virus involved please can you complete the prework in my signature and post back the Hijackthis log and then one of our expert security analysts will take a look. I have moved your thread to the HJT forum Many thanks, Matt
__________________
![]() > Did we help you? If we did,Say thanks by rating the posts or please consider A Donation
|
|
|
|
|
|
#3 |
|
Bronze Member
![]() ![]() Join Date: Sep 2008
Posts: 5 PC Experience: Experienced
|
My e-mail (Mozilla Thunderbird) has begun to "go around" my Zone Alarm program control. Meaning when I start e-mail, I no longer get a "permission" window from Zone Alarm asking if I should allow Thunderbird access to the internet. Thunderbird is on the Zone Alarm program list. I recently updated Zone Alarm and my e-mail went through Zone Alarm once, now no more. Any ideas?
Logfile of HijackThis v1.99.1 Scan saved at 3:13:17 PM, on 9/10/2008 Platform: Windows XP SP2 (WinNT 5.01.2600) MSIE: Internet Explorer v6.00 SP2 (6.00.2900.2180) Running processes: C:\WINDOWS\System32\smss.exe C:\WINDOWS\system32\winlogon.exe C:\WINDOWS\system32\services.exe C:\WINDOWS\system32\lsass.exe C:\WINDOWS\system32\Ati2evxx.exe C:\WINDOWS\system32\svchost.exe C:\WINDOWS\System32\svchost.exe C:\WINDOWS\system32\Ati2evxx.exe C:\WINDOWS\Explorer.EXE C:\WINDOWS\system32\spoolsv.exe c:\program files\common files\logitech\lvmvfm\LVPrcSrv.exe C:\PROGRA~1\AVG\AVG8\avgwdsvc.exe C:\Program Files\Common Files\LightScribe\LSSrvc.exe C:\WINDOWS\system32\WDBtnMgr.exe C:\Program Files\Synaptics\SynTP\SynTPLpr.exe C:\Program Files\Synaptics\SynTP\SynTPEnh.exe C:\Program Files\ATI Technologies\ATI Control Panel\atiptaxx.exe C:\Program Files\D-Tools\daemon.exe C:\PROGRA~1\AVG\AVG8\avgtray.exe C:\Program Files\Zone Labs\ZoneAlarm\zlclient.exe C:\Program Files\iolo\System Mechanic 6\SMSystemAnalyzer.exe C:\Program Files\Dantz\Retrospect\retrorun.exe C:\Program Files\Spybot - Search & Destroy\TeaTimer.exe C:\WINDOWS\system32\ctfmon.exe C:\PROGRA~1\Dantz\RETROS~1\wdsvc.exe C:\WINDOWS\system32\svchost.exe C:\Program Files\DNA\btdna.exe C:\Program Files\Hawking Technologies\Hawking_HWU54G_Utility\HWU54G.exe C:\PROGRA~1\AVG\AVG8\avgrsx.exe C:\PROGRA~1\AVG\AVG8\avgemc.exe C:\WINDOWS\system32\taskmgr.exe C:\WINDOWS\system32\ZoneLabs\vsmon.exe C:\WINDOWS\system32\wuauclt.exe C:\Program Files\Mozilla Thunderbird\thunderbird.exe C:\Program Files\Mozilla Firefox\firefox.exe C:\Program Files\Adobe\Acrobat 6.0\Reader\AcroRd32.exe C:\WINDOWS\system32\WISPTIS.EXE C:\WINDOWS\eFaxView.exe C:\Program Files\Microsoft Office\Office12\WINWORD.EXE C:\Program Files\Cooledit\coolpro.exe C:\Program Files\Windows NT\Accessories\wordpad.exe C:\Program Files\Internet Explorer\IEXPLORE.EXE C:\Program Files\HijackThis\HijackThis.exe R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = Yahoo! R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = AOL.com - Welcome to AOL R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Local Page = R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Local Page = O2 - BHO: AcroIEHlprObj Class - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Adobe\Acrobat 6.0\Reader\ActiveX\AcroIEHelper.dll O2 - BHO: WormRadar.com IESiteBlocker.NavFilter - {3CA2F312-6F6E-4B53-A66E-4E65E497C8C0} - C:\Program Files\AVG\AVG8\avgssie.dll O2 - BHO: Spybot-S&D IE Protection - {53707962-6F74-2D53-2644-206D7942484F} - C:\PROGRA~1\SPYBOT~1\SDHelper.dll O2 - BHO: Google Toolbar Helper - {AA58ED58-01DD-4d91-8333-CF10577473F7} - c:\program files\google\googletoolbar1.dll O2 - BHO: ZoneAlarm Spy Blocker BHO - {F0D4B231-DA4B-4daf-81E4-DFEE4931A4AA} - C:\Program Files\ZoneAlarmSB\bar\1.bin\SPYBLOCK.DLL O3 - Toolbar: &Google - {2318C2B1-4965-11d4-9B18-009027A5CD4F} - c:\program files\google\googletoolbar1.dll O3 - Toolbar: ZoneAlarm Spy Blocker - {F0D4B239-DA4B-4daf-81E4-DFEE4931A4AA} - C:\Program Files\ZoneAlarmSB\bar\1.bin\SPYBLOCK.DLL O4 - HKLM\..\Run: [WD Button Manager] WDBtnMgr.exe O4 - HKLM\..\Run: [SynTPLpr] C:\Program Files\Synaptics\SynTP\SynTPLpr.exe O4 - HKLM\..\Run: [SynTPEnh] C:\Program Files\Synaptics\SynTP\SynTPEnh.exe O4 - HKLM\..\Run: [ATIPTA] C:\Program Files\ATI Technologies\ATI Control Panel\atiptaxx.exe O4 - HKLM\..\Run: [DAEMON Tools-1033] "C:\Program Files\D-Tools\daemon.exe" -lang 1033 O4 - HKLM\..\Run: [ioloDelayModule] C:\Program Files\iolo\System Mechanic 6\delay.exe O4 - HKLM\..\Run: [AVG8_TRAY] C:\PROGRA~1\AVG\AVG8\avgtray.exe O4 - HKLM\..\Run: [ZoneAlarm Client] "C:\Program Files\Zone Labs\ZoneAlarm\zlclient.exe" O4 - HKCU\..\Run: [SMSystemAnalyzer] "C:\Program Files\iolo\System Mechanic 6\SMSystemAnalyzer.exe" O4 - HKCU\..\Run: [SpybotSD TeaTimer] C:\Program Files\Spybot - Search & Destroy\TeaTimer.exe O4 - HKCU\..\Run: [ctfmon.exe] C:\WINDOWS\system32\ctfmon.exe O4 - HKCU\..\Run: [BitTorrent DNA] "C:\Program Files\DNA\btdna.exe" O4 - Global Startup: Hawking HWU54G Utility.lnk = C:\Program Files\Hawking Technologies\Hawking_HWU54G_Utility\HWU54G.exe O8 - Extra context menu item: E&xport to Microsoft Excel - res://C:\PROGRA~1\MICROS~4\Office12\EXCEL.EXE/3000 O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.5.0_02\bin\npjpi150_02.dll O9 - Extra 'Tools' menuitem: Sun Java Console - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.5.0_02\bin\npjpi150_02.dll O9 - Extra button: Research - {92780B25-18CC-41C8-B9BE-3C9C571A8263} - C:\PROGRA~1\MICROS~4\Office12\REFIEBAR.DLL O9 - Extra button: (no name) - {DFB852A3-47F8-48C4-A200-58CAB36FD2A2} - C:\PROGRA~1\SPYBOT~1\SDHelper.dll O9 - Extra 'Tools' menuitem: Spybot - Search & Destroy Configuration - {DFB852A3-47F8-48C4-A200-58CAB36FD2A2} - C:\PROGRA~1\SPYBOT~1\SDHelper.dll O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe O14 - IERESET.INF: START_PAGE_URL=http://ie.redirect.hp.com/svs/rdr?TYPE=3&tp=iehome&locale=EN_US&c=Q305&bd=presar io&pf=laptop O16 - DPF: {14C1B87C-3342-445F-9B5E-365FF330A3AC} (Hewlett-Packard Online Support Services) - http://h20278.www2.hp.com/HPISWeb/Cu...ataManager.CAB O16 - DPF: {4EC99A0B-E57C-4FBE-B9C4-8428424FBF88} (McciUtilsSpecialFolder Class) - http://supportcenter.verizon.net/euserv/jsp/VOLAWeb.cab O16 - DPF: {4F1E5B1A-2A80-42CA-8532-2D05CB959537} (MSN Photo Upload Tool) - http://by19fd.bay19.hotmail.msn.com/...s/MsnPUpld.cab O16 - DPF: {9600F64D-755F-11D4-A47F-0001023E6D5A} (Shutterfly Picture Upload Plugin) - http://web1.shutterfly.com/downloads/Uploader.cab O16 - DPF: {9A9307A0-7DA4-4DAF-B042-5009F29E09E1} (ActiveScan Installer Class) - http://acs.pandasoftware.com/actives...ree/asinst.cab O18 - Protocol: linkscanner - {F274614C-63F8-47D5-A4D1-FBDDE494F8D1} - C:\Program Files\AVG\AVG8\avgpp.dll O18 - Protocol: livecall - {828030A1-22C1-4009-854F-8E305202313F} - C:\PROGRA~1\MSNMES~1\MSGRAP~1.DLL O18 - Protocol: ms-help - {314111C7-A502-11D2-BBCA-00C04F8EC294} - C:\Program Files\Common Files\Microsoft Shared\Help\hxds.dll O18 - Protocol: msnim - {828030A1-22C1-4009-854F-8E305202313F} - C:\PROGRA~1\MSNMES~1\MSGRAP~1.DLL O18 - Filter hijack: text/xml - {807563E5-5146-11D5-A672-00B0D022E945} - C:\PROGRA~1\COMMON~1\MICROS~1\OFFICE12\MSOXMLMF.DL L O20 - AppInit_DLLs: avgrsstx.dll O20 - Winlogon Notify: WgaLogon - C:\WINDOWS\SYSTEM32\WgaLogon.dll O23 - Service: Ati HotKey Poller - ATI Technologies Inc. - C:\WINDOWS\system32\Ati2evxx.exe O23 - Service: AVG Free8 E-mail Scanner (avg8emc) - AVG Technologies CZ, s.r.o. - C:\PROGRA~1\AVG\AVG8\avgemc.exe O23 - Service: AVG Free8 WatchDog (avg8wd) - AVG Technologies CZ, s.r.o. - C:\PROGRA~1\AVG\AVG8\avgwdsvc.exe O23 - Service: Google Updater Service (gusvc) - Google - C:\Program Files\Google\Common\Google Updater\GoogleUpdaterService.exe O23 - Service: HP WMI Interface (hpqwmi) - Hewlett-Packard Development Company, L.P. - C:\Program Files\HPQ\SHARED\HPQWMI.exe O23 - Service: LightScribeService Direct Disc Labeling Service (LightScribeService) - Unknown owner - C:\Program Files\Common Files\LightScribe\LSSrvc.exe O23 - Service: Process Monitor (LVPrcSrv) - Logitech Inc. - c:\program files\common files\logitech\lvmvfm\LVPrcSrv.exe O23 - Service: LVSrvLauncher - Logitech Inc. - C:\Program Files\Common Files\Logitech\SrvLnch\SrvLnch.exe O23 - Service: Pml Driver HPZ12 - HP - C:\WINDOWS\system32\HPZipm12.exe O23 - Service: Intuit QuickBooks FCS (QBFCService) - Intuit Inc. - C:\Program Files\Common Files\Intuit\QuickBooks\FCS\Intuit.QuickBooks.FCS. exe O23 - Service: Retrospect Launcher (RetroLauncher) - Dantz Development Corporation - C:\Program Files\Dantz\Retrospect\retrorun.exe O23 - Service: Retrospect WD Service (RetroWDSvc) - Dantz Development Corporation - C:\PROGRA~1\Dantz\RETROS~1\wdsvc.exe O23 - Service: TrueVector Internet Monitor (vsmon) - Zone Labs, LLC - C:\WINDOWS\system32\ZoneLabs\vsmon.exe |
|
|
|
|
|
#4 |
|
Gold Member
![]() ![]() Join Date: May 2007
Location: Bath,South west UK
Posts: 229 PC Experience: Im learning more and more through PCHF!
|
Thanks for this promorobot, ill ask a tech to take a look.
Apologies about the delay
__________________
![]() > Did we help you? If we did,Say thanks by rating the posts or please consider A Donation
|
|
|
|
|
|
#5 |
|
Site Manager
![]() ![]() Join Date: Oct 2006
Location: South Wales
Posts: 8,984 PC Experience: ...
|
Hey Prom,
I'm just trying to find you a tech who has a little more experience with Zone Alarm. Not personally keen on it myself. However, can you tell us what the purpose would be of blocking an application you intend on using? I can think of a few very small reasons, but nothing that would explain the hasle of accepting each and every single e-mail that comes in and out? I would bug me! Also remember that Zone Alarm is capable of blocking ports as well as applications. Is port 25 or 110 listed there, and what settings do you have assigned to them? |
|
|
|
|
|
#6 |
|
Senior Security Analyst
![]() Join Date: Jun 2006
Location: Victoria, Australia
Posts: 6,867 PC Experience: Elite PC Guru
|
I dont see any sign of malware.It looks fine.
__________________
My real name is Eddy
|
|
|
|
|
|
#7 |
|
Bronze Member
![]() ![]() Join Date: Sep 2008
Posts: 5 PC Experience: Experienced
|
Originally Posted by madmonkey
Zone Alarm is a firewall that prevents any unauthorized access to or from the internet by a program that could be hijacked. So if you set a program to ask permission, a window will pop up asking you want Mozilla Thunderbird or Internet Explorer to have access to the internet at that moment. It's handy to know what programs are secretly "phoning home."
Ports are something I'm not too knowledgeable of. I don't really understand them, but I figured there must be something going on if my e-mail program can suddenly access the internet without asking for permission from Zone Alarm first. Someone just posted that nothing suspicious seems to be on my HJT log. Everything seems to work okay. This e-mail/firewall issue is not keeping me from working, but I'd just like to know what is going on. PR |
|
|
|
![]() |
| Bookmarks |
| Tags |
| alrm, control, email, firewall, involves, issue, program, zone |
| Thread Tools | |
| Display Modes | |
|
|










































Linear Mode

