Virus check log, for instance ZALog2005.06.14.txt, every time it runs it looks the same. I can't even tell if anything gets scanned other than a final report about no viruses. There are tons of entries about scan failed. For instance :
1. These are segments of a text file log:
Quote
AV/treatment,2005/06/14,20:36:30 -4:00 GMT,,C:\Program Files\Lavasoft\Ad-Aware SE Personal\Skins\Ad-Aware SE default.ask>Ad-Aware SE Default.skn,Scan Failed,Auto
AV/treatment,2005/06/14,20:36:30 -4:00 GMT,,C:\Program Files\Lavasoft\Ad-Aware SE Personal\Skins\Ad-Aware SE default.ask>arrow1.bmp,Scan Failed,Auto
AV/treatment,2005/06/14,20:36:30 -4:00 GMT,,C:\Program Files\Lavasoft\Ad-Aware SE Personal\Skins\Ad-Aware SE default.ask>arrow2.bmp,Scan Failed,Auto
or
AV/treatment,2005/06/14,20:35:20 -4:00 GMT,,C:\Program Files\PestPatrol\Spyware.dat>r,Scan Failed,Auto
AV/treatment,2005/06/14,20:36:30 -4:00 GMT,,C:\Program
or
GMT,,C:\WINDOWS\$NtUninstallKB826939$\ole32.dll,Scan Failed,Auto
AV/treatment,2005/06/14,20:28:56 -4:00 GMT,,C:\WINDOWS\$NtUninstallKB826939$\osk.exe,Scan Failed,Auto
AV/treatment,2005/06/14,20:28:56 -4:00 GMT,,C:\WINDOWS\$NtUninstallKB826939$\pchshell.dll,Scan Failed,Auto
or
AV/treatment,2005/06/14,20:49:34 -4:00 GMT,,C:\Documents and Settings\All Users\Application Data\Spybot - Search & Destroy\Recovery\CDilla.zip>sbRecovery.reg,Scan Failed,Auto
AV/treatment,2005/06/14,20:49:34 -4:00 GMT,,C:\Documents and Settings\All Users\Application Data\Spybot - Search & Destroy\Recovery\CDilla.zip>sbRecovery.ini,Scan Failed,Auto
AV/treatment,2005/06/14,20:49:34 -4:00 GMT,,C:\Documents and Settings\All Users\Application Data\Spybot - Search & Destroy\Recovery\DSOExploit.zip>sbRecovery.reg,Scan Failed,Auto [/FONT]
AV/treatment,2005/06/14,20:36:30 -4:00 GMT,,C:\Program Files\Lavasoft\Ad-Aware SE Personal\Skins\Ad-Aware SE default.ask>arrow1.bmp,Scan Failed,Auto
AV/treatment,2005/06/14,20:36:30 -4:00 GMT,,C:\Program Files\Lavasoft\Ad-Aware SE Personal\Skins\Ad-Aware SE default.ask>arrow2.bmp,Scan Failed,Auto
or
AV/treatment,2005/06/14,20:35:20 -4:00 GMT,,C:\Program Files\PestPatrol\Spyware.dat>r,Scan Failed,Auto
AV/treatment,2005/06/14,20:36:30 -4:00 GMT,,C:\Program
or
GMT,,C:\WINDOWS\$NtUninstallKB826939$\ole32.dll,Scan Failed,Auto
AV/treatment,2005/06/14,20:28:56 -4:00 GMT,,C:\WINDOWS\$NtUninstallKB826939$\osk.exe,Scan Failed,Auto
AV/treatment,2005/06/14,20:28:56 -4:00 GMT,,C:\WINDOWS\$NtUninstallKB826939$\pchshell.dll,Scan Failed,Auto
or
AV/treatment,2005/06/14,20:49:34 -4:00 GMT,,C:\Documents and Settings\All Users\Application Data\Spybot - Search & Destroy\Recovery\CDilla.zip>sbRecovery.reg,Scan Failed,Auto
AV/treatment,2005/06/14,20:49:34 -4:00 GMT,,C:\Documents and Settings\All Users\Application Data\Spybot - Search & Destroy\Recovery\CDilla.zip>sbRecovery.ini,Scan Failed,Auto
AV/treatment,2005/06/14,20:49:34 -4:00 GMT,,C:\Documents and Settings\All Users\Application Data\Spybot - Search & Destroy\Recovery\DSOExploit.zip>sbRecovery.reg,Scan Failed,Auto [/FONT]
Sorry for the look of it. I can't even tell where a sentence begins or ends.
2. In the Alerts and Logs pane, I see 100 of these lines. The ones about Spybot S&D are the only visible and all have Error E004000Fh at the end. I suspect all files get the error, it's just that I limit that pane to 100 entries. I googled and found 3 refs to this error apparently on ZA site. When I clicked on the links, the screen said "The Message you are trying to access has been deleted. Please update your bookmarks. " on all three. One of the titles indicates it's about Spybot. Interesting.
3. In the Windows\internet logs directory I see several files with names such as "vsmon_2nd_2005_06_09_20_39_06.dmp.zip". Each file is around 20 meg
4. In the same directory are, what looks like daily saves, roughly 60K each file, and the text, invariably looks like this:
Quote
ZoneAlarm Logging Client v5.5.062.004
Windows XP-5.1.2600-Service Pack 2-SMP
type,date,time,source,destination,transport (security)
type,date,time,virus name,file name,mode,e-mail id (antivirus)
type,date,time,source,destination,action,service (IM security)
FWOUT,2005/01/20,22:12:36 -5:00 GMT,192.168.1.100:1186,151.197.0.38:53,UDP
AV/treatment,2005/01/21,19:53:38 -5:00 GMT,,d:\,Scan Failed,Auto
AV/treatment,2005/01/21,19:53:38 -5:00 GMT,,C:\hiberfil.sys,Scan Failed,Auto
AV/treatment,2005/01/21,19:53:40 -5:00 GMT,,C:\pagefile.sys,Scan Failed,Auto
AV/treatment,2005/01/21,19:55:08 -5:00 GMT,,C:\WORKSSETUP\MSWORKS\REDIST\IE6\TEMPFILE.CAB>msoe.chm,Scan Failed,Auto
AV/treatment,2005/01/21,19:55:08 -5:00 GMT,,C:\WORKSSETUP\MSWORKS\REDIST\IE6\TEMPFILE.CAB>msoe.hlp,Scan Failed,Auto
AV/treatment,2005/01/21,19:55:08 -5:00 GMT,,C:\WORKSSETUP\MSWORKS\REDIST\IE6\TEMPFILE.CAB>msoe50.inf,Scan Failed,Auto
AV/treatment,2005/01/21,19:55:08 -5:00 GMT,,C:\WORKSSETUP\MSWORKS\REDIST\IE6\TEMPFILE.CAB>msoe.txt,Scan Failed,Auto
AV/treatment,2005/01/21,19:55:08 -5:00 GMT,,C:\WORKSSETUP\MSWORKS\REDIST\IE6\TEMPFILE.CAB>aleabanr.gif,Scan Failed,Auto
AV/treatment,2005/01/21,19:55:08 -5:00
Windows XP-5.1.2600-Service Pack 2-SMP
type,date,time,source,destination,transport (security)
type,date,time,virus name,file name,mode,e-mail id (antivirus)
type,date,time,source,destination,action,service (IM security)
FWOUT,2005/01/20,22:12:36 -5:00 GMT,192.168.1.100:1186,151.197.0.38:53,UDP
AV/treatment,2005/01/21,19:53:38 -5:00 GMT,,d:\,Scan Failed,Auto
AV/treatment,2005/01/21,19:53:38 -5:00 GMT,,C:\hiberfil.sys,Scan Failed,Auto
AV/treatment,2005/01/21,19:53:40 -5:00 GMT,,C:\pagefile.sys,Scan Failed,Auto
AV/treatment,2005/01/21,19:55:08 -5:00 GMT,,C:\WORKSSETUP\MSWORKS\REDIST\IE6\TEMPFILE.CAB>msoe.chm,Scan Failed,Auto
AV/treatment,2005/01/21,19:55:08 -5:00 GMT,,C:\WORKSSETUP\MSWORKS\REDIST\IE6\TEMPFILE.CAB>msoe.hlp,Scan Failed,Auto
AV/treatment,2005/01/21,19:55:08 -5:00 GMT,,C:\WORKSSETUP\MSWORKS\REDIST\IE6\TEMPFILE.CAB>msoe50.inf,Scan Failed,Auto
AV/treatment,2005/01/21,19:55:08 -5:00 GMT,,C:\WORKSSETUP\MSWORKS\REDIST\IE6\TEMPFILE.CAB>msoe.txt,Scan Failed,Auto
AV/treatment,2005/01/21,19:55:08 -5:00 GMT,,C:\WORKSSETUP\MSWORKS\REDIST\IE6\TEMPFILE.CAB>aleabanr.gif,Scan Failed,Auto
AV/treatment,2005/01/21,19:55:08 -5:00
I'm trying to make some sense out of this, especially the endless list of scan fails ... can anyone, please, tell me what am I looking at? I can barely manage this computer without help from this site or real system administrators at work, but they don't use ZA.
I do know some of the experts on BC aren't too keen on ZA. But I have it since before I joined BC and I do know several experts here know this sort of thing.

Help


Back to top









