ZoneAlarm Secure Wireless Router Z100G Discussion Forum

For other ZoneAlarm products click here

Our support personnel monitor this forum, however note this is not an official support channel - to contact support, click the button on the right.

Moderators: Ido, Marina, wendy
Go
New
Find
Notify
Tools
Reply
  
-star Rating Rate It!  Login/Join 
Junior Member
Posted
My Z100G Event log is showing a lot of outgoing phishing emails being blocked as suspicious activity. Although the ports and IP addresses vary the typical log entry is of the form:

Connection blocked by VStream Src:192.168.10.112 SPort:1035 Dst:72.14.217.93 DPort:80 IPP:6 Direction:Outbound DataDir:Inbound Filename:N/A Filetype:N/A VirusName:Email.Phishing.RB-1281

Full system scans by Norton/Symantec/ClamAV reveal nothing. Reinstalling the OS (without low level reformat) does nothing but generate even more suspect traffic.

Am I alone with this issue? Does anyone else have a simialr problem? Any ideas anyone?
 
Posts: 3 | Registered: June 12, 2007Reply With QuoteEdit or Delete MessageReport This Post
Junior Member
Posted Hide Post
I get the same logs; the destination address is always one registered to Google according to the ARIN WHOIS database.
 
Posts: 1 | Registered: July 21, 2007Reply With QuoteEdit or Delete MessageReport This Post
Member
Picture of NVC_Ryan
AIM: Online Status For oooorionoooo
Posted Hide Post
quote:

Connection blocked by VStream Src:192.168.10.112 SPort:1035 Dst:72.14.217.93 DPort:80 IPP:6 Direction:Outbound DataDir:Inbound Filename:N/A Filetype:N/A VirusName:Email.Phishing.RB-1281


DPort:80 is the key here I think. To me this reads as web traffic being misidentified as a phishing e-mail signature.
 
Posts: 67 | Location: Naples, FL | Registered: March 13, 2006Reply With QuoteEdit or Delete MessageReport This Post
  Powered by Eve Community  
 


© Copyright 2006 SofaWare Technologies Ltd.