ZoneAlarm firewall concern?

Discussion in 'Software' started by SpecialFNK, Jun 30, 2009.

  1. SpecialFNK

    SpecialFNK Private First Class

    i just wanted to see if i should be concerned with some activity in my ZoneAlarm firewall.
    today i was online around lunch until roughly 1:30 pm. during that time in the Alerts & Logs it showed activity blocked alerts. i then was online again at rougly 4:00 pm and from that time until roughly 6:30 pm in the Alerts & Logs there were no recent alerts from that entire time period. i dont usually check how often an alert is made, but should there not have been some type of an alert during that time period? i have a dial up connection and it was around that time of 6:30 pm when i was disconnected and connected online again, and since then i have had 2 regular type alerts.
    that was in the Alerts & Logs for the firewall section. i also checked the Alerts & Logs for the program area and theres something i dont know what it is.
    it says..
    Program- Program Files\Zone Labs\Zone Alarm\zclient.exe
    Direction- Outgoing (connect)
    Action Taken- Allowed (once) Auto
    Destination DNS- www.liutilities.com

    is that normal ?
    what is liutilities.com ?

    in the Programs area there is also another Outgoing blocked alert..
    Program- hprbUpfate.exe
    Direction- Outgoing (connect)
    Action Taken- Blocked
    Destination DNS- cache2.mtl1.rogerstelecom.net

    what is hprbUpdate.exe ?


    i sometimes in the firewall area also get Outgoing blocked alerts. should there be alerts Outgoing Blocked?
    they are..
    Protocol- UPD
    Program- svchost.exe
    Source IP-
    Destination IP-
    Direction- Outgoing
    Action Taken- Blocked
    Source DNS- USER-D720F8AB84
    Destination DNS- cache2.mtl1.rogerstelecom.net

    is that normal? or is that something i should be concerned with?

    thanx for any help
     
  2. hrlow2

    hrlow2 MajorGeek

    Do you have DriverScanner,DiskRescue,PowerSuite,SpeedUpMyPC,or RegistryBooster installed? All are from LiUtilities.
    The hprbUpdate appears to be an HP printer program.
     
  3. SpecialFNK

    SpecialFNK Private First Class

    none of these sound familiar.
    i used the Search , For Files or Folders, and nothing came up.
    i checked Add/Remove programs, and dont see any of those listed.

    since my last post have had another alert in the program area..
    Program- explorer.exe
    Direction- Outgoing
    Action Taken- Blocked
    Destination DNS- sa.windowsmedia.com.akadns.net

    i dont even use Internet Explorer as my browser but instead i use Firefox.
     
  4. hrlow2

    hrlow2 MajorGeek

    How long have you had this machine? Was it new or used?
    If used, may be remnants from previous owner.
    That robertstelecom may be an ISP type of thing.My Comodo flagged my cable connection until I listed it as a safe one.
     
  5. SpecialFNK

    SpecialFNK Private First Class

    ive had the computer for 2 years maybe. it was a refurbished computer.
    my ISP is from Rogers so i assume the rogerstelecom.net is from my ISP. i get a server assigned IP address everytime i log online with dialup and sometimes whatever is infront of rogerstelecom.net can change. it was cache2.mlt1.rogerstelecom.net but now in some of the Source DNS on Incoming blocks it has tor58-23b-95-54.dynamic.rogerstelecom.net
     
  6. hrlow2

    hrlow2 MajorGeek

    Is that Tor as in Tor Network?(a proxy server)
    Also, what type of machine is it we are discussing?
     
  7. SpecialFNK

    SpecialFNK Private First Class

    tor is out of Toronto. i live in near Hamilton. i think it goes through different servers.
    the machine i think is an old HP machine. the area where it had the HP was covered when it was refurbished.

    i just connected again, and in the Alerts & Logs for the firewall there were 3 alerts for Outgoing Blocked. it gives a Source IP and Destination IP, but google search for them doesnt give me much information.
    my server thing changed again, now to cache1.tor1.rogerstelecom.net
    i guess thats different every time i connect.

    when it gives an IP number like 000.000.000.00 and then has :## is that last ## a port number? i think i read somewhere about the port numbers or something. the :## always seems to be :53 if that means anything.
     
  8. plodr

    plodr MajorGeek Super Extraordinaire Moderator Staff Member

    This is the info I found on port 53 outbound
    So I don't think you should worry about the outbound. Your computer is trying to match a web url with a DNS number so you can see the site.
     

MajorGeeks.Com Menu

Downloads All In One Tweaks \ Android \ Anti-Malware \ Anti-Virus \ Appearance \ Backup \ Browsers \ CD\DVD\Blu-Ray \ Covert Ops \ Drive Utilities \ Drivers \ Graphics \ Internet Tools \ Multimedia \ Networking \ Office Tools \ PC Games \ System Tools \ Mac/Apple/Ipad Downloads

Other News: Top Downloads \ News (Tech) \ Off Base (Other Websites News) \ Way Off Base (Offbeat Stories and Pics)

Social: Facebook \ YouTube \ Twitter \ Tumblr \ Pintrest \ RSS Feeds