Path: utzoo!utgpu!news-server.csri.toronto.edu!bonnie.concordia.ca!thunder.mcrcim.mcgill.edu!snorkelwacker.mit.edu!think.com!zaphod.mps.ohio-state.edu!swrinde!elroy.jpl.nasa.gov!ucla-cs!oahu.cs.ucla.edu!chao From: chao@oahu.cs.ucla.edu (Chia-Chi Chao) Newsgroups: comp.sys.ibm.pc.misc Subject: Re: Is there a virus in QEMM Ver. 5.1 ?? Keywords: virus,QEMM5.1 Message-ID: <1991Jan11.000614.1115@cs.ucla.edu> Date: 11 Jan 91 00:06:14 GMT References: <5955@rupert.misemi> Sender: news@cs.ucla.edu (Mr. News) Organization: UCLA Computer Science Department Lines: 28 Nntp-Posting-Host: oahu.cs.ucla.edu In article <5955@rupert.misemi> infotech@rupert.misemi ( infottech) writes: >A recent article found on comp.sys.ibm.pc.digest states (in part): > >>Date: Tue, 1 Jan 91 10:58:09 -0500 >>From: David Kirschbaum >>Subject: Reported QEMM virus >> >>I have found what appears to be a virus on the factory supplied disk >>from Quarterdeck on the QEMM386 V5.1 diskette in the Optimize.com amd >>install.exe programs. These 2 programs contain a HEX signature of >>EAF0FF00F0 which indicates the possible presence of the 648 virus. This >>virus is supposed to infect overlay programs, which I have had MAJOR >>problems with lately. >> > >I checked my copy of QEMM 5.1 and lo and behold the same Hex string >was in these programs... So, what's the scoop? Is it a virus? SCANV71 >didn't find anything out of the ordinary in these files. I have yet to >get through to Q-deck customer support... > >Anyone have any further info? No, it is _NOT_ a virus. I contacted the original poster, and I was told that the hex string turned out to be part of the warm boot instruction, which install.exe and optimize.com both use. -- Chia-Chi Chao chao@cs.ucla.edu ..!ucbvax!cs.ucla.edu!chao