> I expect that we will change the code to treat these as > forging, so SKIPIFFORGING would catch 'em. We could also add > a separate SKIPIF... > option just to detect these, just to be safe.
I believe it would be usefull for all users of F-Prot with returncode 8 enabled to avoid future uneccessary warnings send out if f-prot is fast catching but not exact naming new virus variants. Now after renaming all .offline files back to .eml there are again some NDR's. As Franco allready reported it seems that F-Prot up to now is not catching 100% of Bagle.AP. So I've not removed the BANNAME's from my config file and keept .offline the bannotify.eml file. Comparing scan results in the vir logfile I can see that F-Prot up to now is catching only around 50% of what is catching Mcafee regarding Bagle.AP (or in Mcafee terms Bagle.bb) I'm not sure if Mcafee is catching all Bagle.bb's Markus --- [This E-mail was scanned for viruses by Declude Virus (http://www.declude.com)] --- This E-mail came from the Declude.Virus mailing list. To unsubscribe, just send an E-mail to [EMAIL PROTECTED], and type "unsubscribe Declude.Virus". The archives can be found at http://www.mail-archive.com.
