Well, it parked itself in the system tray.
I googled a bit and checked c:\windows directory where I see new things from today 7:40pm, but nothing conclusive to understand really
- wiadebug.log
- wiaservc.log
I gather these are related to windows image acquisition - what it that??? I don't aquire any such thing.
then there is
- windowsupdate.log (yeah, I'll do it after I read if it'll break my system)
and
- Qfont.for
- QTfont.qfn
I ran Spybot - it's clean.
I will run a-square and ad-aware in safe mode later
I thought of running Trojan hunter but apparently my temp licence (from about a year ago) expired.
What's this all about?
Why would I get Apple computer program on WindowsXP home? How did it get in?
Edited upon further looking:
1. Bleeping computer startup list shows it as Apple program, no need to have it at startup
2. There's a CoolWebSearch, but my exe filename does not match
3. qttask.exe is in program files.
This is info from ZoneAlarm advice - copied and pasted
QUOTE
QuickTime is trying to open an existing process.
The current security setting for QuickTime does not permit this action, or ZoneAlarm Security Suite is asking you whether to allow this behavior. Your computer is safe.
Inside the OSFirewall alert
Alert property Alert property value Technical explanation
Program Name QuickTime A program running on your computer, which attempted an action that was detected by the OSFirewall.
Filename C:\PROGRAM FILES\QUICKTIME\qttask.exe The filename of the program that ZoneAlarm Security Suite found on your computer.
Program Size 77824 The size of the program executable file in bytes.
Program MD5 c9128ae6036cdf67873a516e1a00ed4b The MD5 hash, or number, that uniquely identifies the executable.
Smart Checksum e88d2e2d1b37a7175dbb80bfe299affe The SKIMP hash, or number, that uniquely identifies the executable.
Date Modified Dec-02-2003 07:05:00 PM The date when C:\PROGRAM FILES\QUICKTIME\qttask.exe was most recently modified.
Event Type Process The event involved starting or terminating a thread or process.
Sub Event Type OpenProcess QuickTime attempted to open another process.
Command Line "C:\WINDOWS\system32\ctfmon.exe" The command being used to open another process.
The current security setting for QuickTime does not permit this action, or ZoneAlarm Security Suite is asking you whether to allow this behavior. Your computer is safe.
Inside the OSFirewall alert
Alert property Alert property value Technical explanation
Program Name QuickTime A program running on your computer, which attempted an action that was detected by the OSFirewall.
Filename C:\PROGRAM FILES\QUICKTIME\qttask.exe The filename of the program that ZoneAlarm Security Suite found on your computer.
Program Size 77824 The size of the program executable file in bytes.
Program MD5 c9128ae6036cdf67873a516e1a00ed4b The MD5 hash, or number, that uniquely identifies the executable.
Smart Checksum e88d2e2d1b37a7175dbb80bfe299affe The SKIMP hash, or number, that uniquely identifies the executable.
Date Modified Dec-02-2003 07:05:00 PM The date when C:\PROGRAM FILES\QUICKTIME\qttask.exe was most recently modified.
Event Type Process The event involved starting or terminating a thread or process.
Sub Event Type OpenProcess QuickTime attempted to open another process.
Command Line "C:\WINDOWS\system32\ctfmon.exe" The command being used to open another process.
Edited some more:
I removed it from the system tray by doing Exit.
It stopped qttask running.
I don't know whether a service runs - names are not obvious to me.
Zone Alarm suite again says QuickTime wants to be at startup, and the alert displays an entry about attempt to Set Value in the registry: HKLM|Software|Microsoft\Windows\CurrentVersion\Run,
with a comma at the end. I suspect the entry is in there already, should I remove it?
The ZA alerts me every time I switch a page right here at BC, as well as on another site, and there are now over 100 entries in the alerts list related to QT.
