I want to know some detail about 4 differnt ZA Alerts.
1. SUSPECIOUS BEHAVIOUR
Services and Controller app is trying to load the driver :Registry\Machine\system\CurrentControlSet\
Application : SERVICES.EXE
2. SUSPECIOUS BEHAVIOUR
Spooler Subsystem App is trying to access the internet
Identification : Unknown
Application : spoolsv.exe
Destination IP : 0.0.0.0.DNS
3. SUSPECIOUS BEHAVIOUR
LSA Executive and Sever DLL (Export Version) is trying to communicate with C:\WINNT\System32\svchost.exe - kwugroup by opening its processes
Application : LSASS.EXE
4. SUSPECIOUS BEHAVIOUR
Task Scheduler Engine is trying to act as a server
Identification : None
Application : mstask.exe
Destination IP : 0.0.0.0.Port1025
These alerts are shown mainly at the system starting and sometimes two or three, sometimes all one after one.
Each alert are with allow or deny options at the bottom and in all the cases no smart defense advice is available. I have no idea about what to do with these alerts, what it results if allow or deny, or are these dangerous to the system or not. As a result I cannot do allow or deny with 'remember this setting' checked.
THANKS to ALL.
Operating System:Windows 2000 Pro
Product Name:ZoneAlarm Pro