البرنامج قوي وهو مجاني وهذا وصف مختصر للفئات المكونة للبرنامج والمكتوب بلغة السي ++
CVirusCleaner
VirusCleaner.h
VirusCleaner.cpp
The workhorse of the virus scanner. Given a starting root directory it creates a thread that recurses through all directories and scans files for virus signatures. When a signature is found within a file that could possibly be infected this class passes the file onto the custom virus killer class that deals with it (scan, clean or delete). This class also holds the scan statistics of the scan.
VirusKiller
VirusCleaner.h
VirusCleaner.cpp
This class is (basically) an abstract class that defines the interface for a virus killer. A virus killer holds the virus definition (name, signature, etc) and has the code to handle an infected file, (in-depth scan, clean or delete). Creating a new virus killer would entail subclassing this class and providing the virus name, associated extensions (or all), signature (if any), and a 'virtual SCANRESULT Clean()' method to handle an infected file. The Clean() function should return whether it only scanned, cleaned or deleted the file.
w32_nimda_a, w32_nimda_b, w32_nimda_c
w32_nimda.h
w32_nimda.cpp
These three files make up the total definition for the nimbda virus. Version 'a' cleans 'exe' and 'dll' files, version 'b' cleans 'htm', 'html', and 'asp' files, and finally version 'c' simply deletes all '*.eml' and '*.nws' files.
CNimdaDlg
NimbdaDlg.h
NimbdaDlg.cpp
Dialog (visual interface) for the anti-nimda virus killer. Starts the CVirusKiller thread and creates a windows timer to update statistics from the CVirusKiller object. Very simple interface.
CServiceThread
ServiceThread.h
ServiceThread.cpp
impliments threading for general servicing type threads. A class I generally use when creating worker threads. All that is needed is to override 'virtual void run()' and the Start(), Stop() Pause() and Continue() are already implimented.
CProperty
Property.h
Property.cpp
Used in CServiceThread as a way for a worker thread to recieve input/start parameters.
CNimdaFilter
NimdaFilter.h
NimdaFilter.cpp
Contains the IIS filter for nimda filter. The most relevant code (i.e. not produced by the ISAPI Extension Wizard) is contained in 'CNimdaFilter::OnUrlMap'. This method is called when IIS is mapping a URL passed by a browser to a filename on the local machine. If the file part of the url contains the percent (%) character, constituting a malformed URL, an error is returned and the client is disconnected. An entry to the nimda filter log is made logging the clients IP address, time of attack and the malformed part of the URL.
الموضوع مهم وفيه تحدي لمن يستطيع تطوير البرنامج او برمجة الافضل