Re: Why are recent Firefox (for Windows) downloads ALL being found to contain ransomware?

Newcomer01 via clamav-users <[email protected]> Fri, 27 Mar 2026 04:12:23 +0000
Newsgroups gmane.comp.security.virus.clamav.user
Message-ID <[email protected]>
This is a multi-part message in MIME format.
--===============7960958475269875511==
Content-Type: multipart/alternative;
 boundary="------------MCpUEhukQjJ280YkFCFhpehn"
Content-Language: en-US, de-DE

This is a multi-part message in MIME format.
--------------MCpUEhukQjJ280YkFCFhpehn
Content-Type: text/plain; charset=UTF-8
Content-Transfer-Encoding: 8bit

LTS means Long Term Support and the current suggested release is 1.0.9 or better 1.4.3 that's fact. 
You want to have a hard cut? So if your install is out of maintenance, then all is dead? Have a look in your
freshclam.log, here you can find the information, that your Version is eol and don't get any updates afterwards, right? ...

Von / From: 	Paul Kosinski via clamav-users <mailto:[email protected]>
An / To: 	Newcomer01 <mailto:[email protected]>
CC / CC: 	Paul Kosinski <mailto:[email protected]>
Gesendet / Sent: 	Freitag, März 27, 2026 um 00:09 (at 12:09 AM) +0100
Betreff / Subject: 	Re: [clamav-users] Why are recent Firefox (for Windows) downloads ALL being found to contain
ransomware?

> I only have 1.0.9 installed, so I don't currently have a way to test it with either 1.5.x or 1.4.x. 
>
> So I submitted the "Firefox Setup 115.34.0esr.exe" file to VirusTotal, and none of their scanners found a virus.
> I then asked VirusTotal (now owned by Google) what version of ClamAV they run, but they haven't replied as of a few minutes ago.
>
> I realize that ClamAV 1.0.9 is "EOL", but one can still obtain "official" signature files for another year beyond that.
>
> Disturbingly, the Version Support Matrix says that, for 1.0 LTS, signatures are NOT tested for false positives (FP) after 1.1 was released. In this case that's about 2.5 years BEFORE 1.0.9 EOL.
>
> So WHAT EXACTLY DOES LTS MEAN?? For 1.0 LTS, it seems that no 1.0.x can be FULLY trusted after 1.1 was released. This is not what I would characterize as LTS.
>
> Furthermore, since the DB files can still be downloaded one year after nominal EOL (much less End Of Trust), why doesn't freshclam at least issue a warning among its large number of messages that EOL is past?
>
> Finally, I intend to (try to) install 1.4 LTS in the near future. But will this help? According to the Version Support Matrix, FP testing will not be done for 1.4 LTS after 1.5 is released. Oops: that was last October (2025)!
>
> ---------------------
>
> On Thu, 26 Mar 2026 18:17:38 +0000 (GMT)
> Andrew C Aitchison via clamav-users <[email protected]> wrote:
>
>> On Thu, 26 Mar 2026, Paul Kosinski via clamav-users wrote:
>>
>>> For example:
>>>
>>> Firefox Setup 140.9.0esr.exe  --> Win.Trojan.Spora-7724442-0 FOUND
>>> Firefox Setup 115.34.0esr.exe --> Win.Trojan.Spora-7724442-0 FOUND
>>> Firefox Setup 115.34.0esr.msi --> Win.Trojan.Spora-7724442-0 FOUND
>>>
>>>
>>> These are from ClamAV 1.0.9 clamd on Linux receiving file to be scanned over TCP.  
>> https://docs.clamav.net/faq/faq-eol.html#version-support-matrix
>> suggests that 1.0.9 went end-of-life Nov-28 2025
>> Version 1.3 is also EOL.
>>
>> Can you verify the problem with version 1.4.3 or 1.5.1 ?
>>
> _______________________________________________
>
> Manage your clamav-users mailing list subscription / unsubscribe:
> https://lists.clamav.net/mailman/listinfo/clamav-users
>
>
> Help us build a comprehensive ClamAV guide:
> https://github.com/Cisco-Talos/clamav-documentation
>
> https://docs.clamav.net/#mailing-lists-and-chat

--------------MCpUEhukQjJ280YkFCFhpehn
Content-Type: text/html; charset=UTF-8
Content-Transfer-Encoding: 8bit

<!DOCTYPE html>
<html>
  <head>
    <meta http-equiv="Content-Type" content="text/html; charset=UTF-8">
  </head>
  <body text="#000000" bgcolor="#ffffff" smarttemplateinserted="true">
    <div id="smartTemplate4-template" data-smarttemplate-hash="47148ae4">LTS
      means Long Term Support and the current suggested release is 1.0.9
      or better 1.4.3 that's fact. <br>
      You want to have a hard cut? So if your install is out of
      maintenance, then all is dead? Have a look in your freshclam.log,
      here you can find the information, that your Version is eol and
      don't get any updates afterwards, right? ...</div>
    <div id="smartTemplate4-quoteHeader"><br>
      <table
style="border-collapse: collapse; width: 100%; border-top: 2px solid #808080; font-family: Verdana, Arial, sans-serif; color: #000000; font-size: 13px; background-color: #eeeeee;">
        <tbody>
          <tr style="vertical-align: top;">
            <td style="width: 120px; vertical-align: middle;"><span
                style="color: #cc0000;">Von / From:</span></td>
            <td style="vertical-align: middle;"><a
                style="text-decoration: none;"
                href="mailto:[email protected]">Paul
                Kosinski via clamav-users</a></td>
          </tr>
          <tr style="vertical-align: top;">
            <td style="width: 120px; vertical-align: middle;"><span
                style="color:#cc0000;">An / To:</span></td>
            <td style="vertical-align: middle;"><a
                style="text-decoration: none;"
                href="mailto:[email protected]">Newcomer01</a></td>
          </tr>
          <tr style="vertical-align: top;">
            <td style="width: 120px; vertical-align: middle;"><span
                style="color: #cc0000;">CC / CC:</span></td>
            <td style="vertical-align: middle;"><a
                style="text-decoration: none;"
                href="mailto:[email protected]">Paul Kosinski</a></td>
          </tr>
          <tr style="vertical-align: top;">
            <td style="width: 120px; vertical-align: middle;"><span
                style="color: #cc0000;">Gesendet / Sent:</span></td>
            <td style="vertical-align: middle;"> Freitag, März 27, 2026
              um 00:09 (at 12:09 AM) +0100</td>
          </tr>
          <tr style="vertical-align: top;">
            <td style="width: 120px; vertical-align: middle;"><span
                style="color: #cc0000;">Betreff / Subject:</span></td>
            <td style="vertical-align: middle;">Re: [clamav-users] Why
              are recent Firefox (for Windows) downloads ALL being found
              to contain ransomware?</td>
          </tr>
        </tbody>
      </table>
    </div>
    <blockquote type="cite"
      cite="mid:[email protected]">
      <pre wrap="" class="moz-quote-pre">I only have 1.0.9 installed, so I don't currently have a way to test it with either 1.5.x or 1.4.x. 

So I submitted the "Firefox Setup 115.34.0esr.exe" file to VirusTotal, and none of their scanners found a virus.
I then asked VirusTotal (now owned by Google) what version of ClamAV they run, but they haven't replied as of a few minutes ago.

I realize that ClamAV 1.0.9 is "EOL", but one can still obtain "official" signature files for another year beyond that.

Disturbingly, the Version Support Matrix says that, for 1.0 LTS, signatures are NOT tested for false positives (FP) after 1.1 was released. In this case that's about 2.5 years BEFORE 1.0.9 EOL.

So WHAT EXACTLY DOES LTS MEAN?? For 1.0 LTS, it seems that no 1.0.x can be FULLY trusted after 1.1 was released. This is not what I would characterize as LTS.

Furthermore, since the DB files can still be downloaded one year after nominal EOL (much less End Of Trust), why doesn't freshclam at least issue a warning among its large number of messages that EOL is past?

Finally, I intend to (try to) install 1.4 LTS in the near future. But will this help? According to the Version Support Matrix, FP testing will not be done for 1.4 LTS after 1.5 is released. Oops: that was last October (2025)!

---------------------

On Thu, 26 Mar 2026 18:17:38 +0000 (GMT)
Andrew C Aitchison via clamav-users <a class="moz-txt-link-rfc2396E" href="mailto:[email protected]">&lt;[email protected]&gt;</a> wrote:

</pre>
      <blockquote type="cite">
        <pre wrap="" class="moz-quote-pre">On Thu, 26 Mar 2026, Paul Kosinski via clamav-users wrote:

</pre>
        <blockquote type="cite">
          <pre wrap="" class="moz-quote-pre">For example:

Firefox Setup 140.9.0esr.exe  --&gt; Win.Trojan.Spora-7724442-0 FOUND
Firefox Setup 115.34.0esr.exe --&gt; Win.Trojan.Spora-7724442-0 FOUND
Firefox Setup 115.34.0esr.msi --&gt; Win.Trojan.Spora-7724442-0 FOUND


These are from ClamAV 1.0.9 clamd on Linux receiving file to be scanned over TCP.  
</pre>
        </blockquote>
        <pre wrap="" class="moz-quote-pre">
<a class="moz-txt-link-freetext" href="https://docs.clamav.net/faq/faq-eol.html#version-support-matrix">https://docs.clamav.net/faq/faq-eol.html#version-support-matrix</a>
suggests that 1.0.9 went end-of-life Nov-28 2025
Version 1.3 is also EOL.

Can you verify the problem with version 1.4.3 or 1.5.1 ?

</pre>
      </blockquote>
      <pre wrap="" class="moz-quote-pre">_______________________________________________

Manage your clamav-users mailing list subscription / unsubscribe:
<a class="moz-txt-link-freetext" href="https://lists.clamav.net/mailman/listinfo/clamav-users">https://lists.clamav.net/mailman/listinfo/clamav-users</a>


Help us build a comprehensive ClamAV guide:
<a class="moz-txt-link-freetext" href="https://github.com/Cisco-Talos/clamav-documentation">https://github.com/Cisco-Talos/clamav-documentation</a>

<a class="moz-txt-link-freetext" href="https://docs.clamav.net/#mailing-lists-and-chat">https://docs.clamav.net/#mailing-lists-and-chat</a>
</pre>
    </blockquote>
    <br>
  </body>
</html>

--------------MCpUEhukQjJ280YkFCFhpehn--

--===============7960958475269875511==
Content-Type: text/plain; charset="us-ascii"
MIME-Version: 1.0
Content-Transfer-Encoding: 7bit
Content-Disposition: inline

_______________________________________________

Manage your clamav-users mailing list subscription / unsubscribe:
https://lists.clamav.net/mailman/listinfo/clamav-users


Help us build a comprehensive ClamAV guide:
https://github.com/Cisco-Talos/clamav-documentation

https://docs.clamav.net/#mailing-lists-and-chat

--===============7960958475269875511==--