Re: Why are recent Firefox (for Windows) downloads ALL being found to contain ransomware?
"Valerie Snyder \(valsnyde\) via clamav-users" <[email protected]> Mon, 30 Mar 2026 22:03:23 +0000
| Newsgroups | gmane.comp.security.virus.clamav.user |
|---|---|
| Message-ID | <SA1PR11MB57776D4578F2BF830831F116DE52A@SA1PR11MB5777.namprd11.prod.outlook.com> |
--===============7680777652448866159== Content-Language: en-US Content-Type: multipart/alternative; boundary="_000_SA1PR11MB57776D4578F2BF830831F116DE52ASA1PR11MB5777namp_" --_000_SA1PR11MB57776D4578F2BF830831F116DE52ASA1PR11MB5777namp_ Content-Type: text/plain; charset="us-ascii" Content-Transfer-Encoding: quoted-printable When you have "AlertExceedsMax yes" in your config, then exceeding scan lim= its are treated as alerts / infected regardless of if it finds any signatur= e matches. Respectfully, Val Valerie Snyder (she/they) ClamAV Development Talos Cisco Systems, Inc. ________________________________ From: clamav-users <[email protected]> on behalf of Pau= l Kosinski via clamav-users <[email protected]> Sent: Saturday, March 28, 2026 10:43 AM To: Andrew C Aitchison <[email protected]> Cc: Paul Kosinski <[email protected]>; [email protected] <= [email protected]> Subject: Re: [clamav-users] Why are recent Firefox (for Windows) downloads = ALL being found to contain ransomware? On Fri, 27 Mar 2026 12:23:35 +0000 (GMT) Andrew Aitchison via clamav-users <[email protected]> wrote: > I note that the scan takes around two minutes > which may be enough for a timeout such as ReadTimeout to kick in. ------------------------------------ ------------------------------------ If I reduce the max scan time limit for clamd to 30 secs, I get the followi= ng: =3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D Firefox Setup 115.34.0esr.exe: Heuristics.Limits.Exceeded.MaxScanTime FOUND ----------- SCAN SUMMARY ----------- Infected files: 1 Time: 30.619 sec (0 m 30 s) Start Date: 2026:03:27 22:29:05 End Date: 2026:03:27 22:29:36 RC =3D 1 =3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D which is quite different from: =3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D Firefox Setup 115.34.0esr.exe: Win.Trojan.Spora-7724442-0 FOUND ----------- SCAN SUMMARY ----------- Infected files: 1 Time: 87.618 sec (1 m 27 s) Start Date: 2026:03:27 22:41:03 End Date: 2026:03:27 22:42:31 RC =3D 1 =3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D P.S. In both cases I have used the verbose reporting option. It's interesti= ng that the first case also shows 1 infected file -- perhaps it found the T= rojan before it timed out? _______________________________________________ Manage your clamav-users mailing list subscription / unsubscribe: https://lists.clamav.net/mailman/listinfo/clamav-users Help us build a comprehensive ClamAV guide: https://github.com/Cisco-Talos/clamav-documentation https://docs.clamav.net/#mailing-lists-and-chat --_000_SA1PR11MB57776D4578F2BF830831F116DE52ASA1PR11MB5777namp_ Content-Type: text/html; charset="us-ascii" Content-Transfer-Encoding: quoted-printable <html> <head> <meta http-equiv=3D"Content-Type" content=3D"text/html; charset=3Dus-ascii"= > <style type=3D"text/css" style=3D"display:none;"> P {margin-top:0;margin-bo= ttom:0;} </style> </head> <body dir=3D"ltr"> <div class=3D"elementToProof" style=3D"font-family: Aptos, Aptos_EmbeddedFo= nt, Aptos_MSFontService, Calibri, Helvetica, sans-serif; font-size: 12pt; c= olor: rgb(0, 0, 0); --darkreader-inline-color: var(--darkreader-text--darkC= olor_rgb_0__0__0_, var(--darkreader-text-000000, #e8e6e3));" data-darkreade= r-inline-color=3D""> When you have "AlertExceedsMax yes" in your config, then exceedin= g scan limits are treated as alerts / infected regardless of if it finds an= y signature matches. </div> <div id=3D"Signature" class=3D"elementToProof"> <div class=3D"elementToProof" style=3D"font-family: Aptos, Aptos_EmbeddedFo= nt, Aptos_MSFontService, Calibri, Helvetica, sans-serif; font-size: 12pt; c= olor: rgb(0, 0, 0); --darkreader-inline-color: var(--darkreader-text--darkC= olor_rgb_0__0__0_, var(--darkreader-text-000000, #e8e6e3));" data-darkreade= r-inline-color=3D""> <br> </div> <div class=3D"elementToProof" style=3D"font-family: Calibri, Arial, Helveti= ca, sans-serif; font-size: 12pt; color: rgb(0, 0, 0); --darkreader-inline-c= olor: var(--darkreader-text--darkColor_rgb_0__0__0_, var(--darkreader-text-= 000000, #e8e6e3));" data-darkreader-inline-color=3D""> Respectfully,</div> <div class=3D"elementToProof" style=3D"font-family: Calibri, Arial, Helveti= ca, sans-serif; font-size: 12pt; color: rgb(0, 0, 0); --darkreader-inline-c= olor: var(--darkreader-text--darkColor_rgb_0__0__0_, var(--darkreader-text-= 000000, #e8e6e3));" data-darkreader-inline-color=3D""> Val</div> <div class=3D"elementToProof" style=3D"font-family: Calibri, Arial, Helveti= ca, sans-serif; font-size: 12pt; color: rgb(0, 0, 0); --darkreader-inline-c= olor: var(--darkreader-text--darkColor_rgb_0__0__0_, var(--darkreader-text-= 000000, #e8e6e3));" data-darkreader-inline-color=3D""> <br> <span style=3D"font-family: Helvetica; font-size: 12px;">Valerie Snyder (sh= e/they)</span><br> <span style=3D"font-family: Helvetica; font-size: 12px;">ClamAV Development= </span><br> <span style=3D"font-family: Helvetica; font-size: 12px;">Talos</span><br> <span style=3D"font-family: Helvetica; font-size: 12px;">Cisco Systems, Inc= .</span><br> </div> </div> <div id=3D"appendonsend"></div> <hr style=3D"display:inline-block;width:98%" tabindex=3D"-1"> <div id=3D"divRplyFwdMsg" dir=3D"ltr"><font face=3D"Calibri, sans-serif" st= yle=3D"font-size:11pt" color=3D"#000000"><b>From:</b> clamav-users <clam= [email protected]> on behalf of Paul Kosinski via clamav= -users <[email protected]><br> <b>Sent:</b> Saturday, March 28, 2026 10:43 AM<br> <b>To:</b> Andrew C Aitchison <[email protected]><br> <b>Cc:</b> Paul Kosinski <[email protected]>; clamav-users@lists= .clamav.net <[email protected]><br> <b>Subject:</b> Re: [clamav-users] Why are recent Firefox (for Windows) dow= nloads ALL being found to contain ransomware?</font> <div> </div> </div> <div class=3D"BodyFragment"><font size=3D"2"><span style=3D"font-size:11pt;= "> <div class=3D"PlainText">On Fri, 27 Mar 2026 12:23:35 +0000 (GMT)<br> Andrew Aitchison via clamav-users <[email protected]> wro= te:<br> <br> > I note that the scan takes around two minutes<br> > which may be enough for a timeout such as ReadTimeout to kick in.<br> <br> ------------------------------------<br> ------------------------------------<br> <br> If I reduce the max scan time limit for clamd to 30 secs, I get the followi= ng:<br> <br> =3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D<br> Firefox Setup 115.34.0esr.exe: Heuristics.Limits.Exceeded.MaxScanTime FOUND= <br> <br> ----------- SCAN SUMMARY -----------<br> Infected files: 1<br> Time: 30.619 sec (0 m 30 s)<br> Start Date: 2026:03:27 22:29:05<br> End Date: 2026:03:27 22:29:36<br> RC =3D 1<br> =3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D<br> <br> which is quite different from:<br> <br> =3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D<br> Firefox Setup 115.34.0esr.exe: Win.Trojan.Spora-7724442-0 FOUND<br> <br> ----------- SCAN SUMMARY -----------<br> Infected files: 1<br> Time: 87.618 sec (1 m 27 s)<br> Start Date: 2026:03:27 22:41:03<br> End Date: 2026:03:27 22:42:31<br> RC =3D 1<br> =3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D<br> <br> P.S. In both cases I have used the verbose reporting option. It's interesti= ng that the first case also shows 1 infected file -- perhaps it found the T= rojan before it timed out?<br> _______________________________________________<br> <br> Manage your clamav-users mailing list subscription / unsubscribe:<br> <a href=3D"https://lists.clamav.net/mailman/listinfo/clamav-users">https://= lists.clamav.net/mailman/listinfo/clamav-users</a><br> <br> <br> Help us build a comprehensive ClamAV guide:<br> <a href=3D"https://github.com/Cisco-Talos/clamav-documentation">https://git= hub.com/Cisco-Talos/clamav-documentation</a><br> <br> <a href=3D"https://docs.clamav.net/#mailing-lists-and-chat">https://docs.cl= amav.net/#mailing-lists-and-chat</a><br> </div> </span></font></div> </body> </html> --_000_SA1PR11MB57776D4578F2BF830831F116DE52ASA1PR11MB5777namp_-- --===============7680777652448866159== Content-Type: text/plain; charset="us-ascii" MIME-Version: 1.0 Content-Transfer-Encoding: 7bit Content-Disposition: inline _______________________________________________ Manage your clamav-users mailing list subscription / unsubscribe: https://lists.clamav.net/mailman/listinfo/clamav-users Help us build a comprehensive ClamAV guide: https://github.com/Cisco-Talos/clamav-documentation https://docs.clamav.net/#mailing-lists-and-chat --===============7680777652448866159==--