I noticed a this a few days ago by accident and went searching. I found copies of IE in Windows\System 32\dllcache; Program Files\MS Works\Works, etc. I renamed them, opened my browser and saw there were still two copies running. I then deleted the copies that were found outisde of C:\Program Files, rebooted, opened my browser and they're still running.
I went to the ZA Application Control, saw two IE listed in Programs and killed the one showing outside of C:\Program Files. I opened my browser, 2 copies still running, looked at App Control again and the 4 red x's had turned back to green checks.
Incidently, I had to red check two of the columns on Generic Host Process to keep Port 135 closed and they keep reverting back to green. Am I infected? All help appreciated!!
ZoneAlarm version: 10.0.241.000
vsmon version: 10.0.241.000
Driver version: 10.0.241.000
Anti-virus engine version: 18.104.22.168
Anti-virus signature DAT file version: 1054487776
AntiSpam version: 22.214.171.12471
ZoneAlarm Browser Security: 1.5.311.0
ZoneAlarm ForceField Spyware Scanner: 126.96.36.199
ZoneAlarm ForceField Anti-Phishing Database: 188.8.131.52
ZoneAlarm ForceField Spyware Sites Database: 04.155