Tom's Guide | Tom's Hardware | Tom's Games
![]() |
![]() |
![]() |
Hi,
I have an ADSL connection and have always wondered why there is traffic activity even when I am not using any internet related programs. I always notice the dial-up networking icon (the two green computer icons in the system tray) flashing after I connect to suggest there is activity - but I have not internet programs running. This got me a little concerned, so I installed Zone Alarm to see what was going on.
As soon as it was installed it (about five minutes ago), I have received hundreds of alerts at the steady rate of about 3 per second. I clicked on "more info" on the alert box which took me to the Zone Alarm site. This reported that the related port is commonly used with edonkey, so it is probably ok. But as I dont have edonkey open at the moment, I am wondering why I am getting all these alerts.
Any help on this would be much appreciated as I would like to protect my pc at all times if possible.
Thanks,
DG

Don't know the answer to your question but if Zone Alarm is fending them off then your pc is protected.
I realise that this maybe an extreme case (hence your interest) but in general I tend to not worry too much about what a firewall is preventing. To do so is rather like having a dog and barking yourself, if you see what I mean.
Hope you find the reason just the same.
Derek

Go toStart/Run and type msconfig.
Check the Startup tab for any suspicious programs. Reference the following sites for help in identification:Startup programs list
http://www.pacs-portal.co.uk/startup_pages/startup_full.htm
http://www2.whidbey.net/djdenham/Running_items.htm
http://www.pacs-portal.co.uk/startup_content.htm#Select
http://www.3feetunder.com/krick/startlist.htmKeep ZoneAlarm running!

I've used Zone Alarm for a while. He's correct you can turn off the messages and still have it block the intrusions.
Have uninstalled Zone Alarm and am using another freeware forewall called agnitu,m which seems to do the trick. Apparently comsidered by some to be better than the free ZA.

Thanks for the replies guys. I have since disconected and re-connected and have found that there are now only about 4 alerts per minute. I know most people are just happy leaving Zone Alarm on in the backround, but I would like to know a little more about what it is actually doing. As I currently know nothing about internet security, I dont know if Zone Alarm is actually protecting me, so I am hoping someone here can help me out a little.
Firstly, how can you determine whether or not you are being targeted by a hacker?
Secondly, I have instructed zone alarm to allow connections to programs such as kazzaa, edonkey, internet explorer and outlook, so I presume this will leave many ports open. Doesnt this mean that hackers will be able to use them now?
I have now left zone alarm running in the backround (alerts off), yet I dont feel at all safe as I have little understanding of how it works. So any advice or extra info would be much appreciated.
Thanks,
DG

In the normal way, leaving Zone Alarm at it's original settings means you can pretty well sit back and be sure you are protected - no log or alerts really necessary.
It is obviously safe to allow such things as IE & OE outgoing plus any legitimate updates to programs (both ways), such as AV, Ad-Aware and so on.
I know little about edonkey but it certainly seems (from what I've read here) that Kazza is spyware ridden - not the sort of thing that I would personally wish to allow.
I also read that KazzaLite is safer.It's some time since I used ZA but perhaps it can be run where things like Kazza are only allowed on a dynamic Permit/Deny basis (as required), rather than invoking continuous permission.
Derek

kazaa is full of spyware, possibly edonkey
also. This spyware will be calling out to the Internet to report that you are connected, to bring you adverts, pop-ups and other crap. It will also slow down your PC.
There was a Trojan that was installed with some of these file share type programs
(someting like... 'didler.dll'??).Zonealarm works great, but I would want the spyware crap off of my PC.
Install and run the free program Spybot from....
http://security.kolla.de/
This will list the bugs on your system and allow you to delete them. Kazaa (and a few other progs including Adobe Acrobat Reader )will not run without the spyware installed.I would delete the spyware, uninstall Kazaa & Edonkey and only when I was 100% sure this rubbish is gone would I install KazaaLite from....
http://www.k-lite.tk
It's the same program execpt the spyware has been removed. Another P2P program that works great but does not have spyware is Winmx from
www.winmx.comTo test if you have Zonealarm properly installed and set up for blocking potential hackers, go to...
www.grc.com and run thier security tests (Shields-up). This tests for open ports etc
I have ZoneAlarm, KazaaLite & Winmx and my ports are in STEALTH MODE meaning hackers can't see them. A determined hacker will get into anything but if you are a home PC user this is unlikely to happen.One last point, always virus check anything you download from these programs. There is the option in KazaaLite to filter out files that can potentially carry a virus - TOOLS - OPTIONS. Documents can also carry a virus but these are not filtered, so always virus check.
Another last point, if you don't have a good Anti-virus program, you can get the free AVG from...
www.grisoft.com
version 6 is free but 7 is a paid for version.That's it, for now. I think ??????

Thanks again for the help guys. I have been using ad-aware for a while now, but have just downloaded the latest version (v6) which has acutally found a few hundred spyware files that the older version kept missing. I also use Norton AntiVirus and scan all .exe, .zip, etc. files before opening, whilst also doing virus scans once a week, so I should have viruses and spyware covered. Oh, and I used to use Kazza but switched to Lite due to it's lack of spyware.
Regarding Zone Alarm, I switched it on and went over to that site michael2 recommended (www.grc.com) to run the tests. With Zone Alarm on, the tests were all passed perfectly stating that my ports were in stealth mode. I then ran the tests without Zone Alarm on, and they all failed. I ran them a last time with Zone Alarm on and Edonkey on as well, and they still passed.
These tests have given me some reassurance that I am a whole lot safer than I was before, so thanks michael2 for suggesting it, and thanks to everyone else for your feedback.
DG

Glad to hear of the improvement.
Yes Ad-Aware stopped updating their previous version without notification - the new one gets updated fine. Can't complain I suppose because it's free.
Derek

![]() |
memory has changed at sta...
|
getting into dos
|

This post is quite old and has been locked from receiving new replies. Please create a new posting instead.
| Ads by Google |