I'll have to let others comment on the ZoneAlarm config - but my basic recommendation for anyone with a high-speed line (either DSL or Cable modem or other high speed connectivity) is to buy a hardware device and use it!
Personally I feel that Zone Alarm or similar programs sit too close to the data to be effective at stopping problems. A hardware device, be it a well-configured filtering router or a simple firewall, prevents most malware from even getting to the PC. Logically speaking, by the time something bad gets intercepted by Zone Alarm, it's already standing in the doorway. I'd rather keep the front door shut.
Basic hardware firewalls from NetGear or Linksys can be had for $50 or $60 bucks, require little configuration out of the box, and require much less tinkering than a software-based 'firewall.' After that is in place, you can work to complete the defense-in-depth with regular Windows Update visits, an active and religiously updated Anti-Virus program set to scan everything, and possibly a decent spam killer. After that, and depending on how far you want to go, you can then look at something like Zone Alarm.
0.02, won't buy much gas......
--Micah
--Micah O'C
'17 M2 6MT, Mineral Grey
'04 330i ZHP
'88 M5 2791445
'92 M5T BL01001
formerly '90 535iM, '92 525iT