> I have not "activated" returncode 8 for F-prot in Declude yet 
> because I wasn't sure if we would get to many false 
> positives. Has anyone, or maybe f-prot themselves, any info 
> on that? Does returncode 8 generate false positives and if 
> so, how many?

Bonno,

I don't know how much false positives it would produce but I haven't never
heard some customer complaining about it. Until this morning there was not
more then 2 or 3 "Unknown Virus" warnings per day with 13000 processed
messages/day.

But in this case - if I have understand it right - it was very usefull to
have viruscode 8 enabled.
I've seen the first "Unknown virus" message this morning at 09:30 AM. F-prot
has had updates ready 3 hours later. In the meantime there was an average of
10 Bagle.AP infected messages per minute - catched only with viruscode 8.

Until I've discovered what's going on here (the "unknown virus" story) and
adapted the virus.cfg file with appropriate BANNAME's there was a large
number of messages that would be delivered without this setting.

Imagine that the breakout happened at 09:30 GMT+1
So I was already at work. People in american timezones was at work when
AV-companies has had updates but Mailservers are delivering messages also
overnight...

Markus



---
[This E-mail was scanned for viruses by Declude Virus (http://www.declude.com)]

---
This E-mail came from the Declude.Virus mailing list.  To
unsubscribe, just send an E-mail to [EMAIL PROTECTED], and
type "unsubscribe Declude.Virus".    The archives can be found
at http://www.mail-archive.com.

Reply via email to