This is all about ZoneAlarm Suite v. 5.5.094.000 with all the bells and whistles. I apologize up front for the length of this message, but I feel it's needed to make a point or a better query. Thanks in advance for any help I can get.
Virus check log, for instance ZALog2005.06.14.txt, every time it runs it looks the same. I can't even tell if anything gets scanned other than a final report about no viruses. There are tons of entries about scan failed. For instance :
1. These are segments of a text file log:
Sorry for the look of it. I can't even tell where a sentence begins or ends.
2. In the Alerts and Logs pane, I see 100 of these lines. The ones about Spybot S&D are the only visible and all have Error E004000Fh at the end. I suspect all files get the error, it's just that I limit that pane to 100 entries. I googled and found 3 refs to this error apparently on ZA site. When I clicked on the links, the screen said "The Message you are trying to access has been deleted. Please update your bookmarks. " on all three. One of the titles indicates it's about Spybot. Interesting.
3. In the Windows\internet logs directory I see several files with names such as "vsmon_2nd_2005_06_09_20_39_06.dmp.zip". Each file is around 20 meg
They might be from the virus scan days, I think they're zipped Access files or something similar. I gotta get rid of them but can't if there might be valuable information.
4. In the same directory are, what looks like daily saves, roughly 60K each file, and the text, invariably looks like this:
I'm trying to make some sense out of this, especially the endless list of scan fails ... can anyone, please, tell me what am I looking at? I can barely manage this computer without help from this site or real system administrators at work, but they don't use ZA.
I do know some of the experts on BC aren't too keen on ZA. But I have it since before I joined BC and I do know several experts here know this sort of thing.
Virus check log, for instance ZALog2005.06.14.txt, every time it runs it looks the same. I can't even tell if anything gets scanned other than a final report about no viruses. There are tons of entries about scan failed. For instance :
1. These are segments of a text file log:
Quote
AV/treatment,2005/06/14,20:36:30 -4:00 GMT,,C:\Program Files\Lavasoft\Ad-Aware SE Personal\Skins\Ad-Aware SE default.ask>Ad-Aware SE Default.skn,Scan Failed,Auto
AV/treatment,2005/06/14,20:36:30 -4:00 GMT,,C:\Program Files\Lavasoft\Ad-Aware SE Personal\Skins\Ad-Aware SE default.ask>arrow1.bmp,Scan Failed,Auto
AV/treatment,2005/06/14,20:36:30 -4:00 GMT,,C:\Program Files\Lavasoft\Ad-Aware SE Personal\Skins\Ad-Aware SE default.ask>arrow2.bmp,Scan Failed,Auto
or
AV/treatment,2005/06/14,20:35:20 -4:00 GMT,,C:\Program Files\PestPatrol\Spyware.dat>r,Scan Failed,Auto
AV/treatment,2005/06/14,20:36:30 -4:00 GMT,,C:\Program
or
GMT,,C:\WINDOWS\$NtUninstallKB826939$\ole32.dll,Scan Failed,Auto
AV/treatment,2005/06/14,20:28:56 -4:00 GMT,,C:\WINDOWS\$NtUninstallKB826939$\osk.exe,Scan Failed,Auto
AV/treatment,2005/06/14,20:28:56 -4:00 GMT,,C:\WINDOWS\$NtUninstallKB826939$\pchshell.dll,Scan Failed,Auto
or
AV/treatment,2005/06/14,20:49:34 -4:00 GMT,,C:\Documents and Settings\All Users\Application Data\Spybot - Search & Destroy\Recovery\CDilla.zip>sbRecovery.reg,Scan Failed,Auto
AV/treatment,2005/06/14,20:49:34 -4:00 GMT,,C:\Documents and Settings\All Users\Application Data\Spybot - Search & Destroy\Recovery\CDilla.zip>sbRecovery.ini,Scan Failed,Auto
AV/treatment,2005/06/14,20:49:34 -4:00 GMT,,C:\Documents and Settings\All Users\Application Data\Spybot - Search & Destroy\Recovery\DSOExploit.zip>sbRecovery.reg,Scan Failed,Auto [/FONT]
AV/treatment,2005/06/14,20:36:30 -4:00 GMT,,C:\Program Files\Lavasoft\Ad-Aware SE Personal\Skins\Ad-Aware SE default.ask>arrow1.bmp,Scan Failed,Auto
AV/treatment,2005/06/14,20:36:30 -4:00 GMT,,C:\Program Files\Lavasoft\Ad-Aware SE Personal\Skins\Ad-Aware SE default.ask>arrow2.bmp,Scan Failed,Auto
or
AV/treatment,2005/06/14,20:35:20 -4:00 GMT,,C:\Program Files\PestPatrol\Spyware.dat>r,Scan Failed,Auto
AV/treatment,2005/06/14,20:36:30 -4:00 GMT,,C:\Program
or
GMT,,C:\WINDOWS\$NtUninstallKB826939$\ole32.dll,Scan Failed,Auto
AV/treatment,2005/06/14,20:28:56 -4:00 GMT,,C:\WINDOWS\$NtUninstallKB826939$\osk.exe,Scan Failed,Auto
AV/treatment,2005/06/14,20:28:56 -4:00 GMT,,C:\WINDOWS\$NtUninstallKB826939$\pchshell.dll,Scan Failed,Auto
or
AV/treatment,2005/06/14,20:49:34 -4:00 GMT,,C:\Documents and Settings\All Users\Application Data\Spybot - Search & Destroy\Recovery\CDilla.zip>sbRecovery.reg,Scan Failed,Auto
AV/treatment,2005/06/14,20:49:34 -4:00 GMT,,C:\Documents and Settings\All Users\Application Data\Spybot - Search & Destroy\Recovery\CDilla.zip>sbRecovery.ini,Scan Failed,Auto
AV/treatment,2005/06/14,20:49:34 -4:00 GMT,,C:\Documents and Settings\All Users\Application Data\Spybot - Search & Destroy\Recovery\DSOExploit.zip>sbRecovery.reg,Scan Failed,Auto [/FONT]
Sorry for the look of it. I can't even tell where a sentence begins or ends.
2. In the Alerts and Logs pane, I see 100 of these lines. The ones about Spybot S&D are the only visible and all have Error E004000Fh at the end. I suspect all files get the error, it's just that I limit that pane to 100 entries. I googled and found 3 refs to this error apparently on ZA site. When I clicked on the links, the screen said "The Message you are trying to access has been deleted. Please update your bookmarks. " on all three. One of the titles indicates it's about Spybot. Interesting.
3. In the Windows\internet logs directory I see several files with names such as "vsmon_2nd_2005_06_09_20_39_06.dmp.zip". Each file is around 20 meg
4. In the same directory are, what looks like daily saves, roughly 60K each file, and the text, invariably looks like this:
Quote
ZoneAlarm Logging Client v5.5.062.004
Windows XP-5.1.2600-Service Pack 2-SMP
type,date,time,source,destination,transport (security)
type,date,time,virus name,file name,mode,e-mail id (antivirus)
type,date,time,source,destination,action,service (IM security)
FWOUT,2005/01/20,22:12:36 -5:00 GMT,192.168.1.100:1186,151.197.0.38:53,UDP
AV/treatment,2005/01/21,19:53:38 -5:00 GMT,,d:\,Scan Failed,Auto
AV/treatment,2005/01/21,19:53:38 -5:00 GMT,,C:\hiberfil.sys,Scan Failed,Auto
AV/treatment,2005/01/21,19:53:40 -5:00 GMT,,C:\pagefile.sys,Scan Failed,Auto
AV/treatment,2005/01/21,19:55:08 -5:00 GMT,,C:\WORKSSETUP\MSWORKS\REDIST\IE6\TEMPFILE.CAB>msoe.chm,Scan Failed,Auto
AV/treatment,2005/01/21,19:55:08 -5:00 GMT,,C:\WORKSSETUP\MSWORKS\REDIST\IE6\TEMPFILE.CAB>msoe.hlp,Scan Failed,Auto
AV/treatment,2005/01/21,19:55:08 -5:00 GMT,,C:\WORKSSETUP\MSWORKS\REDIST\IE6\TEMPFILE.CAB>msoe50.inf,Scan Failed,Auto
AV/treatment,2005/01/21,19:55:08 -5:00 GMT,,C:\WORKSSETUP\MSWORKS\REDIST\IE6\TEMPFILE.CAB>msoe.txt,Scan Failed,Auto
AV/treatment,2005/01/21,19:55:08 -5:00 GMT,,C:\WORKSSETUP\MSWORKS\REDIST\IE6\TEMPFILE.CAB>aleabanr.gif,Scan Failed,Auto
AV/treatment,2005/01/21,19:55:08 -5:00
Windows XP-5.1.2600-Service Pack 2-SMP
type,date,time,source,destination,transport (security)
type,date,time,virus name,file name,mode,e-mail id (antivirus)
type,date,time,source,destination,action,service (IM security)
FWOUT,2005/01/20,22:12:36 -5:00 GMT,192.168.1.100:1186,151.197.0.38:53,UDP
AV/treatment,2005/01/21,19:53:38 -5:00 GMT,,d:\,Scan Failed,Auto
AV/treatment,2005/01/21,19:53:38 -5:00 GMT,,C:\hiberfil.sys,Scan Failed,Auto
AV/treatment,2005/01/21,19:53:40 -5:00 GMT,,C:\pagefile.sys,Scan Failed,Auto
AV/treatment,2005/01/21,19:55:08 -5:00 GMT,,C:\WORKSSETUP\MSWORKS\REDIST\IE6\TEMPFILE.CAB>msoe.chm,Scan Failed,Auto
AV/treatment,2005/01/21,19:55:08 -5:00 GMT,,C:\WORKSSETUP\MSWORKS\REDIST\IE6\TEMPFILE.CAB>msoe.hlp,Scan Failed,Auto
AV/treatment,2005/01/21,19:55:08 -5:00 GMT,,C:\WORKSSETUP\MSWORKS\REDIST\IE6\TEMPFILE.CAB>msoe50.inf,Scan Failed,Auto
AV/treatment,2005/01/21,19:55:08 -5:00 GMT,,C:\WORKSSETUP\MSWORKS\REDIST\IE6\TEMPFILE.CAB>msoe.txt,Scan Failed,Auto
AV/treatment,2005/01/21,19:55:08 -5:00 GMT,,C:\WORKSSETUP\MSWORKS\REDIST\IE6\TEMPFILE.CAB>aleabanr.gif,Scan Failed,Auto
AV/treatment,2005/01/21,19:55:08 -5:00
I'm trying to make some sense out of this, especially the endless list of scan fails ... can anyone, please, tell me what am I looking at? I can barely manage this computer without help from this site or real system administrators at work, but they don't use ZA.
I do know some of the experts on BC aren't too keen on ZA. But I have it since before I joined BC and I do know several experts here know this sort of thing.

Help
Welcome to BleepingComputer, a free community where people like yourself come together to discuss and learn how to use their computers. Using the site is easy and fun. As a guest, you can browse and view the various discussions in the forums, but can not create a new topic or reply to an existing one unless you are logged in. Other benefits of registering an account are subscribing to topics and forums, creating a blog, and having no ads shown anywhere on the site.


Back to top









