Zone Alarm Configuration

Discussion in 'Malware Help - MG (A Specialist Will Reply)' started by TheOldThug, Jan 28, 2005.

  1. TheOldThug

    TheOldThug First Sergeant

    I have installed Zone Alarm and have a few questions on configurations. First of all is there a thread on it specifically. I already noticed that svchost.exe is trying to connect to the internet - Generic Host Process for Win32 Services. I believe that is normal with Win XP. Believe it is coming from windows\system32\svchost.exe Should I allow it and say don't ask again? Should I check "Protect the ZoneAlarm Client"? Does anyone know some generic answrs for what to allow and disallow with this program?
     
  2. Journeyer

    Journeyer Private E-2

    I don't see a specific Zone Alarm forum right here ... but you can probably find some help here ...http://forums.zonelabs.com/zonelabs

    Yes. Checking allow and don't ask again would be correct. However, Generic Host Process does not need to have Act as Server allowed. Here is a link with some information on Local Host ... http://support.microsoft.com/?kbid=314056

    I use Sygate Personal Firewall rather than Zone Alarm so I'm not sure about "Protect the ZoneAlarm Client" setting. My assumption would be to say "Yes" and I'd find out pretty quickly whether or not that is the correct answer. ;)
     
  3. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    Here is a link you may find useful: http://www.markusjansson.net/eza.html

    svchost.exe does not need Internet Access.

    Here is what ZoneLabs says about Protecting the Client:
    Prevents Trojan horses from sending Keyboard and Mouse requests to Zone Labs security software.
    Note: To ensure maximum security, only disable this feature if you are having problems with your keyboard or mouse while using remote access programs.

    If you have a problem keeping the item selected, your database has most likely been corrupted. To correct this, delete the contents of C\Windows\Internet Logs. Now a new log will begin from this point in time.

    See this link too: http://www.zonelabs.com/store/content/support/techNote_10.jsp?lid=tn_recent

    By the way this verges on the edge of belonging in the Software Forum but since firewalls are such an important part of malware protection, let's keep it here.
     
    Last edited: Jan 29, 2005
  4. TheOldThug

    TheOldThug First Sergeant

    Chaslang

    I find that I can not connect on internet thru Mozilla if I do not allow svchost.exe to connect.
     
  5. Night

    Night Private First Class

    I also use Sygates Free Firewall,Zone Alarm made my system run slow for some reason.
     
  6. TheOldThug

    TheOldThug First Sergeant

    So does any1 have opinion which they like better, Sygate or Zone Alarm
     
  7. Journeyer

    Journeyer Private E-2

    With indulgence of chaslang, perhaps we can extend this a bit longer. The Sygate or Zone Alarm question is discussed in number of forums and it typically comes out about even. Both do an excellent job and it generally comes down to personal choice.

    After several years using Zone Alarm, I recently switched to Sygate. I felt Zone Alarm was becoming a bit bloated and the interface more confusing. After several weeks, I think Sygate is a bit less cumbersome. It's truly a matter of choice.

    If you decide to try Sygate, note this mid January comment from Trinh, the Sygate Super Moderator on the Sygate Forum.

    ---------------
    Version 5.6 build 2808 has reported bugs and has been fixed.
    The fix will not be available until the next release.
    Currently we are in beta of the is release.

    You can revert back to Version 5.5 build 2710 at the following link.
    http://207.33.111.31/spf/spf5.5b2710.exe
    ---------------

    I suggest taking this advice rather than downloading the current Version 5.6 build ... then upgrade when the new (currently in beta) Version 5.6 build is released.
     
  8. Journeyer

    Journeyer Private E-2

    Thanks for allowing us to hang in with this thread. It might be of interest to have a forum dedicated specifically to malware prevention programs like firewalls and antivirus. It has become such a critical issue ... and it might prevent a few folks from winding up in your Spyware Specific forum. The Software Forum seems to be a bit too general for these focused tools. Just a thought.
     
  9. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    This forum covers all of it. Even though it is titled the Spyware Specific Forum, you do see that we handle all forms of malware here and not just spyware. Prevention is also discussed.
     
  10. Journeyer

    Journeyer Private E-2

    Agreed. Spyware Specific does a great job covering the full issue. You had just mentioned that this discussion might be borderline. If prevention fits just a well as trying to get fixed ... that's great. I see it as a good spot to discuss your sticky "How to Protect yourself from malware!" information.

    Thanks again for your support.
     
  11. scorcer

    scorcer ajMro keGe

    I've been using ZoneAlarm Free for almost a year.
    I've had no problems since, the only trick was getting used to it asking what to allow,I was always wondering, like you, should I allow this, or what is that for??.
    I dont know if I was right, but I went off the perception that if it was in my puter and wanted out it was ok.
    Try this, if something asks to get out allow it once before checking "do not ask again". if all goes fine next time You can check the box and allow.
    Its important to security check your system after these trials,, good luck
    Also, I'm running Windows ME so I dont know any specifics when it comes to XP :)
     
  12. nbalive

    nbalive Private E-2

    Hey Thug, which version of ZoneAlarm do you have? Is it the free one? If so, where do you go to check "Protect the ZoneAlarm Client"?
     
  13. nbalive

    nbalive Private E-2

    Oh, never mind. I just found it....sweeeeeeet
     
  14. TheOldThug

    TheOldThug First Sergeant

    You might want to look at #3 in this thread for configuration help.
     
  15. PhilliePhan

    PhilliePhan Guest

    This isn't entirely wise . . . . Could be a Trojan or other malware "phoning home" for reinforcements.
    Kinda defeats the purpose of the firewall if you blindly allow everything to connect at will ;)

    PP :)
     
  16. Journeyer

    Journeyer Private E-2

    Agreed. If you're not sure, it would seem better to deny access and see if it breaks something.
     
  17. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    That is the safest course of action! Most programs really do not need to have access to the internet to work even when the look for it. They cannot assume that people are always connected. You can always give them access later if you find it necessary (like for a software update to work). If you see a message popup and you do not know what the program is, find it on you hard disk and look at its Properties, Version tab and see who it belongs too. If there is no Version tab. Deny it access to anything, even the local network. Otherwise after finding out who the program belongs to, you still should decide if you want to grant them external access. As I said above, in most cases they really do not need it.
     
  18. TheOldThug

    TheOldThug First Sergeant

    I am constanly seeing pinging to this address about every 1-7 minutes:

    incoming 192.168.0.1 to 192.168.0.100
    or svchost.exe from 192.168.0.100 to 192.168.0.1:53

    I know that this address 192.168.1.0 is what I type in my browser when I need to make changes in my D-link router.

    Is this just normal communications between my computers and my router. Should I keep blocking it or just allow it.
     
  19. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    You need to add your local network stuff to the Trusted Zone in your firewall.

    You should be defining your DNS Server as an IP Address and put it in the Trusted Zone.
    Also for your network you should define the below Entry Types
    - Network Trusted and it should define your network and submask. Probably should be 192.168.0.0/255.255.255.0
    - IP Range Trusted and it should define the range of address allow for equipment in your network (like 192.168.0.0 - 192.168.0.100) That would allow 101 devices on your network.
     
    Last edited: Feb 1, 2005
  20. dumbluck

    dumbluck Private E-2

    oh. >blush< I've got the same thing happening to me. Heck, it may explain why I can't get the other computer to connect to the network..... >blush<

    Um.... would you mind translating your instructions into newbie-speak, so that I can follow along?
     
  21. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    Sorry! No time for that in here! We are too busy with malware issues. Most firewall documentation (especially ZoneAlarms I have seen) cover this. You could ask for help on this in the Networking Forum.
     

MajorGeeks.Com Menu

Downloads All In One Tweaks \ Android \ Anti-Malware \ Anti-Virus \ Appearance \ Backup \ Browsers \ CD\DVD\Blu-Ray \ Covert Ops \ Drive Utilities \ Drivers \ Graphics \ Internet Tools \ Multimedia \ Networking \ Office Tools \ PC Games \ System Tools \ Mac/Apple/Ipad Downloads

Other News: Top Downloads \ News (Tech) \ Off Base (Other Websites News) \ Way Off Base (Offbeat Stories and Pics)

Social: Facebook \ YouTube \ Twitter \ Tumblr \ Pintrest \ RSS Feeds