1. You are viewing our forum as a guest. For full access please Register. WindowsBBS.com is completely free, paid for by advertisers and donations.

zonealarm icon disappeared

Discussion in 'Security and Privacy' started by sarvesh63, 2008/03/06.

  1. 2008/03/06
    sarvesh63

    sarvesh63 Inactive Thread Starter

    Joined:
    2008/03/06
    Messages:
    8
    Likes Received:
    0
    Hi,

    I had installed zonealarm free version in my home computer a few months back. (win XP serv pack 2)
    I have recently noticed that the zonealarm icon in the task bar has disappeared.
    I tried reinstalling the zonealarm ver 7 installation file, but it says that the true vector service needs to be stopped for the installation. (was not able to proceed thereafter...)

    Based on some readings done on some help sites, i have checked the following:

    1.the start- program also does not show the zonealarm entry. (this would have allowed me to uninstall the program).
    2.the windows security center says that the zonealarm firewall is on.
    3.the windows task manager does not show vsmon.exe running.

    in the above circumstances, can anybody help me find out if the program is still installed and why it has become invisible?
    is there any way to reinstall the program?

    thanks in anticipation.
     
  2. 2008/03/06
    broni

    broni Moderator Malware Analyst

    Joined:
    2002/08/01
    Messages:
    21,701
    Likes Received:
    116
    Did you try to uninstall ZA, first, and then re-install?
     

  3. to hide this advert.

  4. 2008/03/07
    sarvesh63

    sarvesh63 Inactive Thread Starter

    Joined:
    2008/03/06
    Messages:
    8
    Likes Received:
    0
    i am unable to unistall as:

    1. the program is not listed in the start-> programs listing.
    2. it is also not showing up in the control panel->add delete programs list.

    from the above it would appear as if the program has been uninstalled. But the windows security center shows that "zonealarm firewall is running "

    is there any way to know if the program is still there ( and has become invisible due to some reason) or it has been uninstalled?

    regards
     
  5. 2008/03/07
    broni

    broni Moderator Malware Analyst

    Joined:
    2002/08/01
    Messages:
    21,701
    Likes Received:
    116
  6. 2008/03/07
    sarvesh63

    sarvesh63 Inactive Thread Starter

    Joined:
    2008/03/06
    Messages:
    8
    Likes Received:
    0
    dear broni,
    pl send yr email id to send the log file
    regds
     
  7. 2008/03/07
    broni

    broni Moderator Malware Analyst

    Joined:
    2002/08/01
    Messages:
    21,701
    Likes Received:
    116
    Post it right here. You can either paste, or attach it.
     
  8. 2008/03/07
    sarvesh63

    sarvesh63 Inactive Thread Starter

    Joined:
    2008/03/06
    Messages:
    8
    Likes Received:
    0
    pl see the log file below:

    Logfile of Trend Micro HijackThis v2.0.2
    Scan saved at 11:05:59 PM, on 3/7/2008
    Platform: Windows XP SP2 (WinNT 5.01.2600)
    MSIE: Internet Explorer v6.00 SP2 (6.00.2900.2180)
    Boot mode: Normal

    Running processes:
    C:\WINDOWS\System32\smss.exe
    C:\WINDOWS\system32\winlogon.exe
    C:\WINDOWS\system32\services.exe
    C:\WINDOWS\system32\lsass.exe
    C:\WINDOWS\system32\svchost.exe
    C:\WINDOWS\System32\svchost.exe
    E:\programs\ad aware\aawservice.exe
    C:\WINDOWS\system32\spoolsv.exe
    C:\Program Files\Common Files\Apple\Mobile Device Support\bin\AppleMobileDeviceService.exe
    C:\Program Files\Grisoft\AVG Anti-Spyware 7.5\guard.exe
    C:\PROGRA~1\Grisoft\AVG7\avgamsvr.exe
    C:\PROGRA~1\Grisoft\AVG7\avgupsvc.exe
    C:\Program Files\WIDCOMM\Bluetooth Software\bin\btwdins.exe
    C:\WINDOWS\system32\svchost.exe
    C:\Program Files\iolo\common\lib\ioloServiceManager.exe
    C:\WINDOWS\System32\svchost.exe
    C:\WINDOWS\Explorer.EXE
    C:\WINDOWS\System32\svchost.exe
    C:\Program Files\SiteAdvisor\6253\SAService.exe
    C:\WINDOWS\system32\svchost.exe
    E:\programs\K9\Blue Coat K9 Web Protection\k9filter.exe
    C:\WINDOWS\system32\VTTimer.exe
    C:\WINDOWS\SOUNDMAN.EXE
    C:\PROGRA~1\Grisoft\AVG7\avgcc.exe
    C:\Program Files\SiteAdvisor\6253\SiteAdv.exe
    E:\programs\System Mechanic 7\SMSystemAnalyzer.exe
    C:\Program Files\Common Files\Real\Update_OB\realsched.exe
    C:\Program Files\iTunes\iTunesHelper.exe
    C:\Program Files\Messenger\msmsgs.exe
    C:\Program Files\WIDCOMM\Bluetooth Software\BTTray.exe
    C:\Program Files\HP\Digital Imaging\bin\hpqtra08.exe
    C:\Program Files\PC Connectivity Solution\ServiceLayer.exe
    C:\PROGRA~1\WIDCOMM\BLUETO~1\BTSTAC~1.EXE
    C:\WINDOWS\System32\svchost.exe
    C:\Program Files\HP\Digital Imaging\bin\hpqSTE08.exe
    C:\Program Files\iPod\bin\iPodService.exe
    C:\Program Files\PC Connectivity Solution\NclBTHandler.exe
    E:\programs\System Mechanic 7\SMTrayNotify.exe
    E:\programs\System Mechanic 7\SMTrayNotify.exe
    C:\Program Files\Internet Explorer\IEXPLORE.EXE
    C:\Program Files\HP\Smart Web Printing\hpswp_clipbook.exe
    C:\Program Files\Trend Micro\HijackThis\HijackThis.exe

    R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://www.google.co.in/webhp
    R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Local Page =
    R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Local Page =
    O2 - BHO: HP Print Enhancer - {0347C33E-8762-4905-BF09-768834316C61} - C:\Program Files\HP\Smart Web Printing\hpswp_printenhancer.dll
    O2 - BHO: HP Print Clips - {053F9267-DC04-4294-A72C-58F732D338C0} - C:\Program Files\HP\Smart Web Printing\hpswp_framework.dll
    O2 - BHO: Adobe PDF Reader Link Helper - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Adobe\Acrobat 7.0\ActiveX\AcroIEHelper.dll
    O2 - BHO: (no name) - {089FD14D-132B-48FC-8861-0048AE113215} - C:\Program Files\SiteAdvisor\6253\SiteAdv.dll
    O3 - Toolbar: McAfee SiteAdvisor - {0BF43445-2F28-4351-9252-17FE6E806AA0} - C:\Program Files\SiteAdvisor\6253\SiteAdv.dll
    O4 - HKLM\..\Run: [VTTimer] VTTimer.exe
    O4 - HKLM\..\Run: [SoundMan] SOUNDMAN.EXE
    O4 - HKLM\..\Run: [AVG7_CC] C:\PROGRA~1\Grisoft\AVG7\avgcc.exe /STARTUP
    O4 - HKLM\..\Run: [SiteAdvisor] C:\Program Files\SiteAdvisor\6253\SiteAdv.exe
    O4 - HKLM\..\Run: [SMSystemAnalyzer] "E:\programs\System Mechanic 7\SMSystemAnalyzer.exe "
    O4 - HKLM\..\Run: [TkBellExe] "C:\Program Files\Common Files\Real\Update_OB\realsched.exe" -osboot
    O4 - HKLM\..\Run: [PCSuiteTrayApplication] E:\programs\nokia pc suite\Nokia PC Suite 6\LaunchApplication.exe -startup
    O4 - HKLM\..\Run: [iTunesHelper] "C:\Program Files\iTunes\iTunesHelper.exe "
    O4 - HKLM\..\Run: [QuickTime Task] "C:\Program Files\QuickTime\qttask.exe" -atboottime
    O4 - HKCU\..\Run: [MSMSGS] "C:\Program Files\Messenger\msmsgs.exe" /background
    O4 - HKUS\S-1-5-19\..\Run: [AVG7_Run] C:\PROGRA~1\Grisoft\AVG7\avgw.exe /RUNONCE (User 'LOCAL SERVICE')
    O4 - HKUS\S-1-5-20\..\Run: [AVG7_Run] C:\PROGRA~1\Grisoft\AVG7\avgw.exe /RUNONCE (User 'NETWORK SERVICE')
    O4 - HKUS\S-1-5-18\..\Run: [AVG7_Run] C:\PROGRA~1\Grisoft\AVG7\avgw.exe /RUNONCE (User 'SYSTEM')
    O4 - HKUS\.DEFAULT\..\Run: [AVG7_Run] C:\PROGRA~1\Grisoft\AVG7\avgw.exe /RUNONCE (User 'Default user')
    O4 - Global Startup: Bluetooth.lnk = ?
    O4 - Global Startup: HP Digital Imaging Monitor.lnk = C:\Program Files\HP\Digital Imaging\bin\hpqtra08.exe
    O8 - Extra context menu item: E&xport to Microsoft Excel - res://C:\PROGRA~1\MICROS~2\Office10\EXCEL.EXE/3000
    O8 - Extra context menu item: Send to &Bluetooth Device... - C:\Program Files\WIDCOMM\Bluetooth Software\btsendto_ie_ctx.htm
    O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\j2re1.4.2_09\bin\npjpi142_09.dll
    O9 - Extra 'Tools' menuitem: Sun Java Console - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\j2re1.4.2_09\bin\npjpi142_09.dll
    O9 - Extra button: HP Clipbook - {58ECB495-38F0-49cb-A538-10282ABF65E7} - C:\Program Files\HP\Smart Web Printing\hpswp_extensions.dll
    O9 - Extra button: HP Smart Select - {700259D7-1666-479a-93B1-3250410481E8} - C:\Program Files\HP\Smart Web Printing\hpswp_extensions.dll
    O9 - Extra button: @btrez.dll,-4015 - {CCA281CA-C863-46ef-9331-5C8D4460577F} - C:\Program Files\WIDCOMM\Bluetooth Software\btsendto_ie.htm
    O9 - Extra 'Tools' menuitem: @btrez.dll,-12650 - {CCA281CA-C863-46ef-9331-5C8D4460577F} - C:\Program Files\WIDCOMM\Bluetooth Software\btsendto_ie.htm
    O16 - DPF: {B8BE5E93-A60C-4D26-A2DC-220313175592} (MSN Games - Installer) - http://cdn2.zone.msn.com/binFramework/v10/ZIntro.cab56649.cab
    O16 - DPF: {D27CDB6E-AE6D-11CF-96B8-444553540000} (Shockwave Flash Object) - https://download.macromedia.com/pub/shockwave/cabs/flash/swflash.cab
    O16 - DPF: {E008A543-CEFB-4559-912F-C27C2B89F13B} (Domino Web Access 7 Control) - https://notesmail2.sjsu.edu/dwa7W.cab
    O17 - HKLM\System\CCS\Services\Tcpip\..\{F3DDB287-7589-4533-A74D-4B4FF50C4D7C}: NameServer = 59.144.127.16,59.144.127.17
    O23 - Service: Ad-Aware 2007 Service (aawservice) - Lavasoft - E:\programs\ad aware\aawservice.exe
    O23 - Service: Apple Mobile Device - Apple, Inc. - C:\Program Files\Common Files\Apple\Mobile Device Support\bin\AppleMobileDeviceService.exe
    O23 - Service: AVG Anti-Spyware Guard - GRISOFT s.r.o. - C:\Program Files\Grisoft\AVG Anti-Spyware 7.5\guard.exe
    O23 - Service: AVG7 Alert Manager Server (Avg7Alrt) - GRISOFT, s.r.o. - C:\PROGRA~1\Grisoft\AVG7\avgamsvr.exe
    O23 - Service: AVG7 Update Service (Avg7UpdSvc) - GRISOFT, s.r.o. - C:\PROGRA~1\Grisoft\AVG7\avgupsvc.exe
    O23 - Service: Bluetooth Service (btwdins) - Broadcom Corporation. - C:\Program Files\WIDCOMM\Bluetooth Software\bin\btwdins.exe
    O23 - Service: InstallDriver Table Manager (IDriverT) - Macrovision Corporation - C:\Program Files\Common Files\InstallShield\Driver\11\Intel 32\IDriverT.exe
    O23 - Service: iolo FileInfoList Service (ioloFileInfoList) - Unknown owner - C:\Program Files\iolo\common\lib\ioloServiceManager.exe
    O23 - Service: iolo System Service (ioloSystemService) - Unknown owner - C:\Program Files\iolo\common\lib\ioloServiceManager.exe
    O23 - Service: iPod Service - Apple Inc. - C:\Program Files\iPod\bin\iPodService.exe
    O23 - Service: ServiceLayer - Nokia. - C:\Program Files\PC Connectivity Solution\ServiceLayer.exe
    O23 - Service: SiteAdvisor Service - Unknown owner - C:\Program Files\SiteAdvisor\6253\SAService.exe
    O23 - Service: TrueVector Internet Monitor (vsmon) - Zone Labs, LLC - C:\WINDOWS\system32\ZoneLabs\vsmon.exe
    O23 - Service: Blue Coat K9 Web Protection (WebFilter) - Unknown owner - E:\programs\K9\Blue Coat K9 Web Protection\k9filter.exe

    --
    End of file - 7605 bytes
     
  9. 2008/03/07
    noahdfear

    noahdfear Inactive

    Joined:
    2003/04/06
    Messages:
    12,178
    Likes Received:
    15
    Hi sarvesh63,

    Please navigate to C:\Program Files\Zone Labs\ZoneAlarm (or E:\programs\Zone labs\ZoneAlarm if you altered the default installation path) and look for, then double click on the file zauninst.exe if present, to start the Zone Alarm uninstaller.
     
  10. 2008/03/11
    sarvesh63

    sarvesh63 Inactive Thread Starter

    Joined:
    2008/03/06
    Messages:
    8
    Likes Received:
    0
    both the locations do not have the zauninst.exe !
     
  11. 2008/03/11
    broni

    broni Moderator Malware Analyst

    Joined:
    2002/08/01
    Messages:
    21,701
    Likes Received:
    116
  12. 2008/03/13
    sarvesh63

    sarvesh63 Inactive Thread Starter

    Joined:
    2008/03/06
    Messages:
    8
    Likes Received:
    0
    thanks. i have installed the revounistaller.
    the revounistaller does not list zonealarm as a installed program.
    the windows security center still shows that zonealarm firewall is running.
     
  13. 2008/03/13
    sarvesh63

    sarvesh63 Inactive Thread Starter

    Joined:
    2008/03/06
    Messages:
    8
    Likes Received:
    0
    can i go ahead and install another firewall ?
     
  14. 2008/03/13
    broni

    broni Moderator Malware Analyst

    Joined:
    2002/08/01
    Messages:
    21,701
    Likes Received:
    116
    It's not a good idea, yet, since you have some ZA leftovers.
    Go Start>Run, type in:
    services.msc
    Click OK.
    Services window will open.
    Scroll down to find TrueVector Internet Monitor service.
    Right click on it, and click Stop. Allow stopping service.
    Now, try to reinstall ZA.
     
  15. 2008/03/14
    Evan Omo

    Evan Omo Computer Support Technician Staff

    Joined:
    2006/09/10
    Messages:
    7,901
    Likes Received:
    510
    Hi Sarvesh63. If you have already tried removing Zone Alarm and you still have it showing up in the Windows Security Center then try this:

    1. Click Start> Administrative Tools> Services
    2 Stop the WMI Service
    3. Delete the "repository" folder in C:\windows\system32\wbem
    4. Start the WMI Service. Starting the service rebuilds the deleted folder and the database.
    5. Restart the computer for the changes to take effect.
     
  16. 2008/03/15
    sarvesh63

    sarvesh63 Inactive Thread Starter

    Joined:
    2008/03/06
    Messages:
    8
    Likes Received:
    0
    thanks.

    will do as suggested and revert.

    meanwhile, just one query - will reinstalling windows XP get rid of the ZA leftovers?

    regds
     
  17. 2008/03/15
    Evan Omo

    Evan Omo Computer Support Technician Staff

    Joined:
    2006/09/10
    Messages:
    7,901
    Likes Received:
    510
    Sarvesh63, If you reinstall Windows XP it all depends which route you take. If you do a repair install then no, Zonealarm will remain on your system because the Windows XP setup will replace Windows System Files only. If you do a clean Windows XP install then yes, zonealarm will be gone from your computer since your harddrive is being formatted during the installation of Windows XP. :)
     
  18. 2008/03/15
    noahdfear

    noahdfear Inactive

    Joined:
    2003/04/06
    Messages:
    12,178
    Likes Received:
    15
    Hi sarvesh63,

    I wouldn't expect a clean installation of Windows to be necessary. Lets see where Zone Alarm is loading from and attempt to disable it (it can't be done from the services console, as it's well protected). Once the service is stopped you will be able to re-install ZA. Please download and run serviceinfo.exe then post the contents of the log it creates.
     

Share This Page

  1. This site uses cookies to help personalise content, tailor your experience and to keep you logged in if you register.
    By continuing to use this site, you are consenting to our use of cookies.