Re: New signatures, different error msg for same Firefox file
Paul Kosinski via clamav-users <[email protected]> Thu, 2 Apr 2026 23:19:33 -0400
| Newsgroups | gmane.comp.security.virus.clamav.user |
|---|---|
| Organization | InterMedia Enterprises |
| Message-ID | <[email protected]> |
Are you saying that ClamAV (clamd) stops scanning as soon as it finds the first piece of malware, and thus never gets to the "excessively deep" recursion? In any case, I re-scanned an older Firefox Setup file (115.15.0) in the same major release and it too gave the Excessive Recursion error. The file had previously been scanned and "passed" by my old 0.103.6 ClamAV. And, upon examining the associated clamd.conf, I see that AlertExceedsMax was never explicitly set, and thus defaulted to NO. This is probably due to the fact that that option didn't come into existence until "recently" -- compared to when I started seriously using ClamAV (back around 0.94 in 2008). Perhaps the moral of this story is that with most software, when new options are added, you can usually ignore them until you need them. But with security software, you have to be more vigilant, because a new option might have a default value that could hide a potential risk to your entire system. ================================================= ================================================= On Tue, 31 Mar 2026 22:17:38 -0400 Paul Kosinski via clamav-users <[email protected]> wrote: > As I reported a couple of days ago, ClamAV 1.0.9 found what was almost certainly a false positive, since VirusTotal said file was AOK: > > ==================== > Firefox Setup 115.34.0esr.exe: Win.Trojan.Spora-7724442-0 FOUND > > ----------- SCAN SUMMARY ----------- > Infected files: 1 > Time: 36.458 sec (0 m 36 s) > Start Date: 2026:03:26 10:03:00 > End Date: 2026:03:26 10:03:37 > RC = 1 > ==================== > > Today, sending the same Firefox file to my local clamd (1.0.9) with latest freshclam update gave a different error: > > ==================== > Firefox Setup 115.34.0esr.exe: Heuristics.Limits.Exceeded.MaxRecursion FOUND > > ----------- SCAN SUMMARY ----------- > Infected files: 1 > Time: 41.079 sec (0 m 41 s) > Start Date: 2026:03:31 19:19:38 > End Date: 2026:03:31 19:20:19 > RC = 1 > ==================== > > So I upped the recursion limits from 30 (max-dir-rec) and 32 (max-rec) to 40 and 40 and got ... > > ==================== > Firefox Setup 115.34.0esr.exe: Heuristics.Limits.Exceeded.MaxRecursion FOUND > > ----------- SCAN SUMMARY ----------- > Infected files: 1 > Time: 87.691 sec (1 m 27 s) > Start Date: 2026:03:31 21:14:31 > End Date: 2026:03:31 21:15:59 > RC = 1 > ==================== > > Next I upped the recursion limits from 40/40 to 60/60 and got much the same: > > ==================== > Firefox Setup 115.34.0esr.exe: Heuristics.Limits.Exceeded.MaxRecursion FOUND > > ----------- SCAN SUMMARY ----------- > Infected files: 1 > Time: 95.908 sec (1 m 35 s) > Start Date: 2026:03:31 21:23:08 > End Date: 2026:03:31 21:24:44 > RC = 1 > ==================== > > So, are the new signatures broken too, but in a different way? > > If so, since today's behavior is so different from a few days ago, I'm not sure if I should report a False Positive, something else, or both via clamsubmit. > > P.S. I am now beginning to wonder about VirusTotal. Could they be running a version and configuration of ClamAV that doesn't really examine the entire file? The file is about 57 MB, well within ClamAV's 2 GB limit, and even less than the *default* size cutoff of 100 MB. _______________________________________________ Manage your clamav-users mailing list subscription / unsubscribe: https://lists.clamav.net/mailman/listinfo/clamav-users Help us build a comprehensive ClamAV guide: https://github.com/Cisco-Talos/clamav-documentation https://docs.clamav.net/#mailing-lists-and-chat