but doesn't a firewall block the ability of spyware/adware to connect back to their servers? if I understand my zone alarm correctly, every connecting application is being blocked for authorisation. since firewalls work at the network layer, these spyware/adware shouldn't be able to establish a TCP session without the firewalls knowing right? unless they go and mess with the firewall settings.