Well, vsmon.exe connects every so often to:

hs2.zonelabs.com at 208.185.174.66

and to

pa2.zonelabs.com at 209.249.114.20 which also resolves to 209.249.114.20.akamai.com

The nature of the traffic appears to be similar. So Akamai is probably hosting some Zonelabs mirror for regional service/load balancing. Outbound traffic appears to be some sort of get command. Inbound traffic appears to be some sort of content code with an expirery date.

What it all means I know not. Nothing sinister? But then there are the perennial questions that flood net forums every so often:

"What exactly is vsmon.exe doing?"

"Is ZoneAlarm spyware?"