Just for fun I ran tcpview yesterday and saw repeated attempts to connect to 220.127.116.11:80 and 18.104.22.168:80. WhoIs tells me these are in Amsterdam but not much else. So I ran Ethereal and captured some packets. Here's an interesting one:
HTTP/1.1..Host: pa2.zonelabs.com..Accept-Encoding: gzip..Accept: */*..Content-Type: text/plain..User-Agent: ZoneAlarm/6.1.737.000 (oem-1025; en-US) ZSP/2.1....
This was outbound from my PC to 22.214.171.124. So is this just ZAP trying to update itself? Or have I got something more serious going on?
Operating System:Windows XP Pro
Product Name:ZoneAlarm Pro