Possibly the site you are pointed to for the definition downloads is late in
getting the updates?  I point to ftp1.mirrors.frisk.is for updates and was
catching Netsky on the 18th.

Bill

-----Original Message-----
From: Mike VandeBerg [mailto:[EMAIL PROTECTED] 
Sent: Tuesday, February 24, 2004 7:43 AM
To: [EMAIL PROTECTED]
Subject: RE: [sniffer] F-Prot and netsky


Thanks for the replies folks, I think I may just stay with F-Prot. But one
thing is still confusing me.. Why did some people get a def file on the 18th
that caught netsky, but mine didn't. On the 20th, I even went so far as to
re-install f-prot which initially installs a July 02 def file, and ran the
updater just to make sure that I was getting the latest updated file as it
was being distributed by F-Prot, and I still got the 18th def file, which
according to Terry here, was catching it, but mine wasn't... Any ideas with
that glitch?  

>-----Original Message-----
>From: [EMAIL PROTECTED]
>[mailto:[EMAIL PROTECTED] On Behalf Of Smart 
>Business Support
>Sent: Tuesday, February 24, 2004 9:28 AM
>To: Mike VandeBerg
>Subject: Re: [sniffer] F-Prot and netsky
>
>Mike,
>
>Tuesday, February 24, 2004 you wrote:
>MV> I was wondering if anyone else is using F-prot for their virus
>MV> engine in declude, and what they now think about it. Netsky was 
>MV> discovered on the 18th, and F-Prot actually had it posted on their 
>MV> website as being discovered by them on the 19th. But they didn't 
>MV> update their definition files to actually catch it until 
>early this
>MV> morning. This meant that netsky ran rampant under F-Prots
>nose for 6
>MV> days. I feel this is completely unacceptable, and I am going to
>MV> change my virus engine this week unless someone can tell 
>me that there is a good reason why I shouldn't.
>
>  This is not our experience.  Here's an excerpt form our virus  
> reporter for the 18th.  Scanner 1 is Fprot.  Scanner 2 is NAI  
> (McAfee).  So on the 18th Fprot caught 39 it identified as Netsky.  
> However, some of these were corrupted.  All in all I'm happy with  
> F-prot but I see enough difference to run 2 and might add a 3rd:
>
>> From: 02/18/2004 00:00:30 Thru 02/18/2004 23:59:36 Log files:
>> vir0218.log
>> 
>> Scanner 1 Virus names
>>         VBS/Haptime.F  = 1
>>         W32/[EMAIL PROTECTED]  = 4
>>         W32/[EMAIL PROTECTED] (corrupted)  = 1
>>         W32/[EMAIL PROTECTED]  = 1
>>         W32/[EMAIL PROTECTED]  = 1
>>         W32/[EMAIL PROTECTED]  = 5
>>         W32/[EMAIL PROTECTED]  = 39
>> 
>> Scanner 1 Days
>>         02/18/2004 = 52
>> 
>> Scanner 2 Virus names
>>         VBS/[EMAIL PROTECTED] virus  = 1
>>         W32/[EMAIL PROTECTED] virus  = 4
>>         W32/Bugbear.b.dam virus  = 1
>>         W32/[EMAIL PROTECTED] virus  = 1
>>         W32/[EMAIL PROTECTED] virus  = 1
>>         W32/[EMAIL PROTECTED] virus  = 3
>>         W32/[EMAIL PROTECTED] virus  = 2
>>         W32/[EMAIL PROTECTED] virus  = 14
>>         W32/Sober!data trojan  = 3
>> 
>> Scanner 2 Days
>>         02/18/2004 = 30
>
> 
>
>
>
>
>Terry Fritts
>
>
>This E-Mail came from the Message Sniffer mailing list. For
>information and (un)subscription instructions go to 
>http://www.sortmonster.com/MessageSniffer/Help/Help.html
>---
>[This E-mail scanned for viruses by Declude Virus]
>
>

---
[This E-mail scanned for viruses by Declude Virus]


This E-Mail came from the Message Sniffer mailing list. For information and
(un)subscription instructions go to
http://www.sortmonster.com/MessageSniffer/Help/Help.html

-------------------------------------------------------------------------------
This message and any included attachments are from Siemens Medical Solutions 
USA, Inc. and are intended only for the addressee(s).  
The information contained herein may include trade secrets or privileged or 
otherwise confidential information.  Unauthorized review, forwarding, printing, 
copying, distributing, or using such information is strictly prohibited and may 
be unlawful.  If you received this message in error, or have reason to believe 
you are not authorized to receive it, please promptly delete this message and 
notify the sender by e-mail with a copy to [EMAIL PROTECTED] 

Thank you

This E-Mail came from the Message Sniffer mailing list. For information and 
(un)subscription instructions go to 
http://www.sortmonster.com/MessageSniffer/Help/Help.html

Reply via email to