Chapter 265: Disc Case, Paper Clip
The first version of the virus killing was written by Wu Yang, in order to be in a hurry, he did not disassemble the virus, but designed it according to the external characteristics of the virus and the extracted virus signature code, but this version failed.
In order to analyze the virus more accurately, Gu Wolf had to put down other work and devote himself to the analysis and research of the virus together with the employees of the technical department.
Still in a hurry, Gu Wolf instructed Wu Yang to bring two other employees, still according to the idea of the first version, to place the virus samples intercepted from the network into the virtual machine, further observe its characteristics, and improve the killing tool, while he took Liu Dong and several other employees to disassemble the virus, and then began to study the compilation source code of the virus.
According to general experience, when the computer virus is compiled, a large part of it will pack the virus protoplasma after the virus is compiled, increasing the difficulty of disassembly, but this virus, which was temporarily named CIH Network Enhanced Edition by Gu Wolf, did not pack its protoplasm, so the disassembly process was very smooth, which made Gu Wolf breathe a sigh of relief, because before he disassembled, he was still worried that the virus would be packed, and unwrapping the shell was sometimes more troublesome than disassembly, in that case, It will undoubtedly greatly increase the analysis time, and now for him, time is the most precious.
But this happiness only lasted for a short time, and then disappeared without a trace, because he soon found that the code he disassembled was a modified CIH virus, and there was no algorithm for virus mutation in the source code, and only according to the source code analysis obtained by his disassembly, the first version of the killing tool made by Wu Yang could completely kill it, and it should not fail, and the fact is that the first version of the killing tool failed, so this can only show a problem, the virus samples they obtained are not comprehensive, In other words, the source code they disassembled is incomplete, and the most important code of the virus is not disassembled.
The disassembly is not a complete code, indicating that the virogen they obtained may be incomplete, but this virion runs in a virtual machine environment and obviously has the ability to mutate automatically, so why is the mutation algorithm missing after disassembly now? This situation is not reasonable, but since unreasonable things have appeared, Gu Wolf can only find the reason from themselves.
At this time, Wu Yang's second version of the virus kill was made, but after the test, it still failed, but this failure, but it was not without gain, in order to thoroughly understand the working principle of the virus, he added a memory monitoring program to this killing, and when the test was carried out, a large amount of memory real-time data was captured when the virus was running.
And now in order to further understand the working principle of the virus, he began to analyze the real-time data of these captured memory, and soon, the data analysis results came out, and the results were consistent with his direct analysis of the virus characteristics, and the results obtained were the same, this result made him a little frustrated, and Gu Wolf's disassembly analysis of the virus protogen was also temporarily in trouble.
"Let's gather for a short meeting."
Seeing that the work of both sides was in a predicament, Gu Wolf immediately made a decision, suspended the virus analysis, and decided to gather the members of the two teams, and the two parties discussed together, maybe they would find a suitable solution.
So the special killing writing team led by Wu Yang and the virore analysis team led by Gu Wolf gathered together and held a short seminar.
"Tell me about the situation on our side, Liu Dong, you can talk about it." Gu Wolf spoke first and handed over the task of introducing the situation to Liu Dong.
"The protovirus was not packed, and the disassembly went smoothly, but the code we obtained did not have a virus mutation algorithm, so we re-collected the protovirus, but the results were still the same." Liu Dong said.
"And this virus progenitor that has not found a mutation algorithm, when running in a virtual machine, if you use the special killing tool designed by Wuyang to kill the virus, you can mutate yourself, avoid the special killing tool, and even identify the system immune patch generated by the special killing tool, and bypass the patch, and continue to destroy the computer, so it can be inferred that this virus has a certain intelligence, and uses a way that we don't know, its core function is hidden, Wuyang, tell me about your situation." After Gu Wolf added, he said.
"We have readjusted the code of the first version of the kill, made a new version, but this version is still invalid, I added a memory scraping code to the second version of the kill, caught some real-time memory data when the virus was running, but still no results have been analyzed, and now we are discussing, ready to capture a few more sets of data, for comparative analysis." Wu Yang said.
"Well, your idea is good, continue to follow this line of thought, wait a while to give me a copy of the captured data, I'll take a look, let's talk about your opinions, if you have any good ideas, just say it." Gu Wolf said.
Although Gu Wolf's original intention was good, but after some discussion, no one proposed any good way, so the seminar was over, Gu Wolf waited for Wuyang to grab a few memory data, took back his computer, opened a data analysis software, and analyzed and compared the data, the results were the same as the analysis results on Wuyang's side, even if the data was compared, there were still no clues.
"What am I overlooking?" Gu Wolf leaned back on the back of the seat, staring at the analysis results on the computer screen, his brows furrowed deeply.
After thinking for a while, he realized that his brain was at the tip of the bull's horn for a while, and he couldn't get out for a while, so he decided to go out, go to the network department to see the situation, change his brain, and come back in a few minutes.
When Gu Wolf walked into the network department, everyone was busy, and no one noticed his arrival, and he didn't alarm everyone, but directly found the manager of the network department and asked about the current situation in the outside world.
The situation in the outside world is becoming more and more severe, and the scope of virus transmission is getting bigger and bigger, because all network security companies and anti-virus software companies have not launched virus prevention and killing methods for a long time, so that public opinion is becoming more and more dissatisfied with all these companies, and the impact of virus infection on enterprises has begun to appear, and a large number of enterprises and units have suspended normal business and disconnected from the network. There is also a risk of infection, and for this reason, the company has disconnected all computers running Windows 9X from the network, and the computers that are still working on the network are running WindowsNT or Linux, which are not virus-infected operating systems.
With a large number of businesses shutting down computers, the virus has begun to have an impact on the daily lives of ordinary people......
After Zhang Shiqi finished his report, he walked out of the network department with a heavy expression, and this trip not only did not achieve the purpose of relaxation, but made him feel more and more heavy.
"What did you ignore that the mutation algorithm of the virus couldn't find?"
Gu Wolf thought as he walked, when he passed by the door of Tang Xinyu's office, Mei Li hurriedly walked out of it with a box in her arms, and suddenly collided with Gu Wolf.
"Ouch, I'm so sorry." Merry apologized as she crouched down and put the things on the ground into the box.
"It's okay, Xinyu is not in the office?" Gu Wolf smiled at Mei Li, squatted on the ground with her and picked up the scattered things into the box, and asked casually, but he was still thinking about the virus in his mind.
"Are you looking for him?" Merry said.
"No, I'll just ask." Gu Wolf said again.
Two boxes of discs that fell to the ground were scattered, he and Mei Li quickly put away these discs, put them into the disc box, and then put all the disc boxes into the box, and then the two began to pick up the paper clips on the ground, Gu Wolf picked some of them, and threw them into the box, some of which were scattered in the gap in the middle of the circular disc boxes neatly arranged in two rows.
Seeing this situation, Gu Wolf was stunned for a moment, suddenly his mind flashed, he thought of something, picked up a few paper clips from the ground and threw them into the gap between the disc boxes, he was stunned for a moment, stood up with a snort, and didn't say hello to Mei Li, and hurriedly ran away to the technical department.