> I have not "activated" returncode 8 for F-prot in Declude yet > because I wasn't sure if we would get to many false > positives. Has anyone, or maybe f-prot themselves, any info > on that? Does returncode 8 generate false positives and if > so, how many?
Bonno, I don't know how much false positives it would produce but I haven't never heard some customer complaining about it. Until this morning there was not more then 2 or 3 "Unknown Virus" warnings per day with 13000 processed messages/day. But in this case - if I have understand it right - it was very usefull to have viruscode 8 enabled. I've seen the first "Unknown virus" message this morning at 09:30 AM. F-prot has had updates ready 3 hours later. In the meantime there was an average of 10 Bagle.AP infected messages per minute - catched only with viruscode 8. Until I've discovered what's going on here (the "unknown virus" story) and adapted the virus.cfg file with appropriate BANNAME's there was a large number of messages that would be delivered without this setting. Imagine that the breakout happened at 09:30 GMT+1 So I was already at work. People in american timezones was at work when AV-companies has had updates but Mailservers are delivering messages also overnight... Markus --- [This E-mail was scanned for viruses by Declude Virus (http://www.declude.com)] --- This E-mail came from the Declude.Virus mailing list. To unsubscribe, just send an E-mail to [EMAIL PROTECTED], and type "unsubscribe Declude.Virus". The archives can be found at http://www.mail-archive.com.