Re: New signatures, different error msg for same Firefox file

"Valerie Snyder \(valsnyde\) via clamav-users" <[email protected]> Wed, 1 Apr 2026 17:26:54 +0000
Newsgroups gmane.comp.security.virus.clamav.user
Message-ID <SA1PR11MB57779975879B0C78E0BF284FDE50A@SA1PR11MB5777.namprd11.prod.outlook.com>
--===============4051111155757626481==
Content-Language: en-US
Content-Type: multipart/alternative;
	boundary="_000_SA1PR11MB57779975879B0C78E0BF284FDE50ASA1PR11MB5777namp_"

--_000_SA1PR11MB57779975879B0C78E0BF284FDE50ASA1PR11MB5777namp_
Content-Type: text/plain; charset="iso-8859-1"
Content-Transfer-Encoding: quoted-printable

I shared your report about an FP with our threat research malware team and =
they dropped the Win.Trojan.Spora-7724442-0 signature at 2026-03-28T06:24:3=
2Z, so it would have been removed in the subsequent daily database update.

With the signature removed, it now scans further into the file before hitti=
ng the recursion limit.

Respectfully,
Val

Valerie Snyder (she/they)
ClamAV Development
Talos
Cisco Systems, Inc.

________________________________
From: clamav-users <[email protected]> on behalf of Pau=
l Kosinski via clamav-users <[email protected]>
Sent: Tuesday, March 31, 2026 10:17 PM
To: [email protected] <[email protected]>
Cc: Paul Kosinski <[email protected]>
Subject: [clamav-users] New signatures, different error msg for same Firefo=
x file

As I reported a couple of days ago, ClamAV 1.0.9 found what was almost cert=
ainly a false positive, since VirusTotal said file was AOK:

=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D
Firefox Setup 115.34.0esr.exe: Win.Trojan.Spora-7724442-0 FOUND

----------- SCAN SUMMARY -----------
Infected files: 1
Time: 36.458 sec (0 m 36 s)
Start Date: 2026:03:26 10:03:00
End Date:   2026:03:26 10:03:37
RC =3D 1
=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D

Today, sending the same Firefox file to my local clamd (1.0.9) with latest =
freshclam update gave a different error:

=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D
Firefox Setup 115.34.0esr.exe: Heuristics.Limits.Exceeded.MaxRecursion FOUN=
D

----------- SCAN SUMMARY -----------
Infected files: 1
Time: 41.079 sec (0 m 41 s)
Start Date: 2026:03:31 19:19:38
End Date:   2026:03:31 19:20:19
RC =3D 1
=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D

So I upped the recursion limits from 30 (max-dir-rec) and 32 (max-rec) to 4=
0 and 40 and got ...

=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D
Firefox Setup 115.34.0esr.exe: Heuristics.Limits.Exceeded.MaxRecursion FOUN=
D

----------- SCAN SUMMARY -----------
Infected files: 1
Time: 87.691 sec (1 m 27 s)
Start Date: 2026:03:31 21:14:31
End Date:   2026:03:31 21:15:59
RC =3D 1
=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D

Next I upped the recursion limits from 40/40 to 60/60 and got much the same=
:

=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D
Firefox Setup 115.34.0esr.exe: Heuristics.Limits.Exceeded.MaxRecursion FOUN=
D

----------- SCAN SUMMARY -----------
Infected files: 1
Time: 95.908 sec (1 m 35 s)
Start Date: 2026:03:31 21:23:08
End Date:   2026:03:31 21:24:44
RC =3D 1
=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D

So, are the new signatures broken too, but in a different way?

If so, since today's behavior is so different from a few days ago, I'm not =
sure if I should report a False Positive, something else, or both via clams=
ubmit.

P.S. I am now beginning to wonder about VirusTotal. Could they be running a=
 version and configuration of ClamAV that doesn't really examine the entire=
 file? The file is about 57 MB, well within ClamAV's 2 GB limit, and even l=
ess than the *default* size cutoff of 100 MB.






_______________________________________________

Manage your clamav-users mailing list subscription / unsubscribe:
https://lists.clamav.net/mailman/listinfo/clamav-users


Help us build a comprehensive ClamAV guide:
https://github.com/Cisco-Talos/clamav-documentation

https://docs.clamav.net/#mailing-lists-and-chat

--_000_SA1PR11MB57779975879B0C78E0BF284FDE50ASA1PR11MB5777namp_
Content-Type: text/html; charset="iso-8859-1"
Content-Transfer-Encoding: quoted-printable

<html>
<head>
<meta http-equiv=3D"Content-Type" content=3D"text/html; charset=3Diso-8859-=
1">
<style type=3D"text/css" style=3D"display:none;"> P {margin-top:0;margin-bo=
ttom:0;} </style>
</head>
<body dir=3D"ltr">
<div class=3D"elementToProof" style=3D"font-family: Aptos, Aptos_EmbeddedFo=
nt, Aptos_MSFontService, Calibri, Helvetica, sans-serif; font-size: 12pt; c=
olor: rgb(0, 0, 0); --darkreader-inline-color: var(--darkreader-text--darkC=
olor_rgb_0__0__0_, var(--darkreader-text-000000, #e8e6e3));" data-darkreade=
r-inline-color=3D"">
I shared your report about an FP with our threat research malware team and =
they dropped the Win.Trojan.Spora-7724442-0 signature at 2026-03-28T06:24:3=
2Z, so it would have been removed in the subsequent daily database update.<=
/div>
<div class=3D"elementToProof" style=3D"font-family: Aptos, Aptos_EmbeddedFo=
nt, Aptos_MSFontService, Calibri, Helvetica, sans-serif; font-size: 12pt; c=
olor: rgb(0, 0, 0); --darkreader-inline-color: var(--darkreader-text--darkC=
olor_rgb_0__0__0_, var(--darkreader-text-000000, #e8e6e3));" data-darkreade=
r-inline-color=3D"">
<br>
</div>
<div class=3D"elementToProof" style=3D"font-family: Aptos, Aptos_EmbeddedFo=
nt, Aptos_MSFontService, Calibri, Helvetica, sans-serif; font-size: 12pt; c=
olor: rgb(0, 0, 0); --darkreader-inline-color: var(--darkreader-text--darkC=
olor_rgb_0__0__0_, var(--darkreader-text-000000, #e8e6e3));" data-darkreade=
r-inline-color=3D"">
With the signature removed, it now scans further into the file before hitti=
ng the recursion limit.</div>
<div id=3D"Signature" class=3D"elementToProof">
<div class=3D"elementToProof" style=3D"font-family: Aptos, Aptos_EmbeddedFo=
nt, Aptos_MSFontService, Calibri, Helvetica, sans-serif; font-size: 12pt; c=
olor: rgb(0, 0, 0); --darkreader-inline-color: var(--darkreader-text--darkC=
olor_rgb_0__0__0_, var(--darkreader-text-000000, #e8e6e3));" data-darkreade=
r-inline-color=3D"">
<br>
</div>
<div class=3D"elementToProof" style=3D"font-family: Calibri, Arial, Helveti=
ca, sans-serif; font-size: 12pt; color: rgb(0, 0, 0); --darkreader-inline-c=
olor: var(--darkreader-text--darkColor_rgb_0__0__0_, var(--darkreader-text-=
000000, #e8e6e3));" data-darkreader-inline-color=3D"">
Respectfully,</div>
<div class=3D"elementToProof" style=3D"font-family: Calibri, Arial, Helveti=
ca, sans-serif; font-size: 12pt; color: rgb(0, 0, 0); --darkreader-inline-c=
olor: var(--darkreader-text--darkColor_rgb_0__0__0_, var(--darkreader-text-=
000000, #e8e6e3));" data-darkreader-inline-color=3D"">
Val</div>
<div class=3D"elementToProof" style=3D"font-family: Calibri, Arial, Helveti=
ca, sans-serif; font-size: 12pt; color: rgb(0, 0, 0); --darkreader-inline-c=
olor: var(--darkreader-text--darkColor_rgb_0__0__0_, var(--darkreader-text-=
000000, #e8e6e3));" data-darkreader-inline-color=3D"">
<br>
<span style=3D"font-family: Helvetica; font-size: 12px;">Valerie Snyder (sh=
e/they)</span><br>
<span style=3D"font-family: Helvetica; font-size: 12px;">ClamAV Development=
</span><br>
<span style=3D"font-family: Helvetica; font-size: 12px;">Talos</span><br>
<span style=3D"font-family: Helvetica; font-size: 12px;">Cisco Systems, Inc=
.</span><br>
</div>
</div>
<div id=3D"appendonsend"></div>
<div style=3D"font-family: Aptos, Aptos_EmbeddedFont, Aptos_MSFontService, =
Calibri, Helvetica, sans-serif; font-size: 12pt; color: rgb(0, 0, 0); --dar=
kreader-inline-color: var(--darkreader-text--darkColor_rgb_0__0__0_, var(--=
darkreader-text-000000, #e8e6e3));" data-darkreader-inline-color=3D"">
<br>
</div>
<hr style=3D"display: inline-block; width: 98%;">
<div id=3D"divRplyFwdMsg">
<div style=3D"direction: ltr; font-family: Calibri, sans-serif; font-size: =
11pt; color: rgb(0, 0, 0); --darkreader-inline-color: var(--darkreader-text=
--darkColor_rgb_0__0__0_, var(--darkreader-text-000000, #e8e6e3));" data-da=
rkreader-inline-color=3D"">
<b>From:</b>&nbsp;clamav-users &lt;[email protected]&gt=
; on behalf of Paul Kosinski via clamav-users &lt;[email protected]=
.net&gt;<br>
<b>Sent:</b>&nbsp;Tuesday, March 31, 2026 10:17 PM<br>
<b>To:</b>&nbsp;[email protected] &lt;[email protected]=
.net&gt;<br>
<b>Cc:</b>&nbsp;Paul Kosinski &lt;[email protected]&gt;<br>
<b>Subject:</b>&nbsp;[clamav-users] New signatures, different error msg for=
 same Firefox file</div>
<div style=3D"direction: ltr;">&nbsp;</div>
</div>
<div style=3D"font-size: 11pt;">As I reported a couple of days ago, ClamAV =
1.0.9 found what was almost certainly a false positive, since VirusTotal sa=
id file was AOK:<br>
<br>
=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D<br>
Firefox Setup 115.34.0esr.exe: Win.Trojan.Spora-7724442-0&nbsp;FOUND<br>
<br>
----------- SCAN SUMMARY -----------<br>
Infected files: 1<br>
Time: 36.458 sec (0 m 36 s)<br>
Start Date: 2026:03:26 10:03:00<br>
End Date:&nbsp;&nbsp; 2026:03:26 10:03:37<br>
RC =3D 1<br>
=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D<br>
<br>
Today, sending the same Firefox file to my local clamd (1.0.9) with latest =
freshclam update gave a different error:<br>
<br>
=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D<br>
Firefox Setup 115.34.0esr.exe: Heuristics.Limits.Exceeded.MaxRecursion FOUN=
D<br>
<br>
----------- SCAN SUMMARY -----------<br>
Infected files: 1<br>
Time: 41.079 sec (0 m 41 s)<br>
Start Date: 2026:03:31 19:19:38<br>
End Date:&nbsp;&nbsp; 2026:03:31 19:20:19<br>
RC =3D 1<br>
=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D<br>
<br>
So I upped the recursion limits from 30 (max-dir-rec) and 32 (max-rec) to 4=
0 and 40 and got ...<br>
<br>
=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D<br>
Firefox Setup 115.34.0esr.exe: Heuristics.Limits.Exceeded.MaxRecursion FOUN=
D<br>
<br>
----------- SCAN SUMMARY -----------<br>
Infected files: 1<br>
Time: 87.691 sec (1 m 27 s)<br>
Start Date: 2026:03:31 21:14:31<br>
End Date:&nbsp;&nbsp; 2026:03:31 21:15:59<br>
RC =3D 1<br>
=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D<br>
<br>
Next I upped the recursion limits from 40/40 to 60/60 and got much the same=
:<br>
<br>
=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D<br>
Firefox Setup 115.34.0esr.exe: Heuristics.Limits.Exceeded.MaxRecursion FOUN=
D<br>
<br>
----------- SCAN SUMMARY -----------<br>
Infected files: 1<br>
Time: 95.908 sec (1 m 35 s)<br>
Start Date: 2026:03:31 21:23:08<br>
End Date:&nbsp;&nbsp; 2026:03:31 21:24:44<br>
RC =3D 1<br>
=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D<br>
<br>
So, are the new signatures broken too, but in a different way?<br>
<br>
If so, since today's behavior is so different from a few days ago, I'm not =
sure if I should report a False Positive, something else, or both via clams=
ubmit.<br>
<br>
P.S. I am now beginning to wonder about VirusTotal. Could they be running a=
 version and configuration of ClamAV that doesn't really examine the entire=
 file? The file is about 57 MB, well within ClamAV's 2 GB limit, and even l=
ess than the *default* size cutoff
 of 100 MB.<br>
<br>
<br>
<br>
<br>
<br>
<br>
_______________________________________________<br>
<br>
Manage your clamav-users mailing list subscription / unsubscribe:<br>
<a href=3D"https://lists.clamav.net/mailman/listinfo/clamav-users" id=3D"OW=
A0215d87a-c07e-5a20-8c15-e008da76f2b1" class=3D"OWAAutoLink" data-auth=3D"N=
otApplicable">https://lists.clamav.net/mailman/listinfo/clamav-users</a><br=
>
<br>
<br>
Help us build a comprehensive ClamAV guide:<br>
<a href=3D"https://github.com/Cisco-Talos/clamav-documentation" id=3D"OWA68=
ca09dd-d7b9-dd31-d0be-e9160ad15774" class=3D"OWAAutoLink" data-auth=3D"NotA=
pplicable">https://github.com/Cisco-Talos/clamav-documentation</a><br>
<br>
<a href=3D"https://docs.clamav.net/#mailing-lists-and-chat" id=3D"OWAcc6b8a=
8c-960f-b867-1487-a89638580396" class=3D"OWAAutoLink" data-auth=3D"NotAppli=
cable">https://docs.clamav.net/#mailing-lists-and-chat</a></div>
</body>
</html>

--_000_SA1PR11MB57779975879B0C78E0BF284FDE50ASA1PR11MB5777namp_--

--===============4051111155757626481==
Content-Type: text/plain; charset="us-ascii"
MIME-Version: 1.0
Content-Transfer-Encoding: 7bit
Content-Disposition: inline

_______________________________________________

Manage your clamav-users mailing list subscription / unsubscribe:
https://lists.clamav.net/mailman/listinfo/clamav-users


Help us build a comprehensive ClamAV guide:
https://github.com/Cisco-Talos/clamav-documentation

https://docs.clamav.net/#mailing-lists-and-chat

--===============4051111155757626481==--