I know FAX...
However, in our specific case we know solved the issue, after we did some searching and went through our own logs...
Due to some other software the key HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Winlogon\Notify with everything attached to it was removed.
After we restored the registry Notify key and its sub-keys by hand, the ZA notification "Internet At Risk" has changed to "Internet Protected", ForceField.exe is again spawned as a process of IswSvc.exe, and under HELP> ABOUT all modules are now present, i.e.
ZoneAlarm Security Suite version: 10.0.250.000
vsmon version: 10.0.250.000
Driver version: 10.0.250.000
Anti-virus engine version: 18.104.22.168
Anti-virus signature DAT file version: 1059492832
AntiSpam version: 22.214.171.12471
ZoneAlarm Browser Security: 1.5.322.0
ZoneAlarm ForceField Spyware Scanner: 126.96.36.199
ZoneAlarm ForceField Anti-Phishing Database: 188.8.131.52
ZoneAlarm ForceField Spyware Sites Database: 04.155
Hence it looks like everything returned to normal.
My guess would be that, due to no HKEY\...\Notify registry keys, ZASS was not able to load/ log on properly. Hence no ForceField modules, thus a notification "Internet At Risk".
Since the problem originated at a non-existent registry key, the "Fix Now" did not work.