With the risk of repeating myself, have you tried to install our test pattern and downloading the eicar test virus?If the test rule functions, it's highly unlikely the other installed rules won't (the IRC rules from ET are also quite practical for testing purposes when there's IRC traffic).
Thanks. I'll check into these suggestions.Hopefully one day I see something that makes it all make sense
Can you post some of the alerts including details? (if you replace ip addresses, please replace them for something similar for external/internal ranges)