|
thank you
I put in the detailed tests as
below.
When the nonsero single test runs I get items trapped
with a score of 7 by sniffer however when I turn it off and activate4 the
detailed once I do not get a hit at all on the detailed tests even though it is
the exact same item. What did I miss here?
change from:
#SNIFFER external nonzero
"D:\IMail\Declude\sniffer\xxxxxx.exe xxxxxx persistent" 7 0
to: #SNIFFER-TRAVEL
external 047 "D:\IMail\Declude\sniffer\xxxxxx.exe xxxxxx
persistent" 10
0
#SNIFFER-INSURANCE external 048 "D:\IMail\Declude\sniffer\xxxxxx.exe xxxxxx persistent" 10 0 #SNIFFER-AV-PUSH external 049 "D:\IMail\Declude\sniffer\xxxxxx.exe xxxxxx persistent" 10 0 #SNIFFER-WAREZ external 050 "D:\IMail\Declude\sniffer\xxxxxx.exe xxxxxx persistent" 15 0 #SNIFFER-SPAMWARE external 051 "D:\IMail\Declude\sniffer\xxxxxx.exe xxxxxx persistent" 19 0 #SNIFFER-SNAKEOIL external 052 "D:\IMail\Declude\sniffer\xxxxxx.exe xxxxxx persistent" 19 0 #SNIFFER-SCAMS external 053 "D:\IMail\Declude\sniffer\xxxxxx.exe xxxxxx persistent" 19 0 #SNIFFER-PORN external 054 "D:\IMail\Declude\sniffer\xxxxxx.exe xxxxxx persistent" 19 0 #SNIFFER-MALWARE external 055 "D:\IMail\Declude\sniffer\xxxxxx.exe xxxxxx persistent" 20 0 #SNIFFER-INKPRINTING external 056 "D:\IMail\Declude\sniffer\xxxxxx.exe xxxxxx persistent" 10 0 #SNIFFER-SCHEMES external 057 "D:\IMail\Declude\sniffer\xxxxxx.exe xxxxxx persistent" 15 0 #SNIFFER-CREDIT external 058 "D:\IMail\Declude\sniffer\xxxxxx.exe xxxxxx persistent" 15 0 #SNIFFER-GAMBLING external 059 "D:\IMail\Declude\sniffer\xxxxxx.exe xxxxxx persistent" 15 0 #SNIFFER-EXP-IP external 063 "D:\IMail\Declude\sniffer\xxxxxx.exe xxxxxx persistent" 10 0 #SNIFFER-OBFUSCATION external 062 "D:\IMail\Declude\sniffer\xxxxxx.exe xxxxxx persistent" 15 0 #SNIFFER-EXP-ABST external 061 "D:\IMail\Declude\sniffer\xxxxxx.exe xxxxxx persistent" 10 0 #SNIFFER-GENERAL external 060 "D:\IMail\Declude\sniffer\xxxxxx.exe xxxxxx persistent" 12 0 Harry Vanderzand
|
- [sniffer] declude tests Harry Vanderzand
- Re: [sniffer] declude tests Scott Fisher
- RE: [sniffer] declude tests Harry Vanderzand
- Re[2]: [sniffer] declude tests Pete McNeil
- Re: [sniffer] declude tests Pete McNeil
- RE: [sniffer] declude tests Harry Vanderzand
- Re[2]: [sniffer] declude tests Pete McNeil
- RE: Re[2]: [sniffer] declude tests Harry Vanderzand
