Re: New signatures, different error msg for same Firefox file
"Valerie Snyder \(valsnyde\) via clamav-users" <[email protected]> Fri, 3 Apr 2026 15:49:27 +0000
| Newsgroups | gmane.comp.security.virus.clamav.user |
|---|---|
| Message-ID | <SA1PR11MB57773A1804728D01AB4348E0DE5EA@SA1PR11MB5777.namprd11.prod.outlook.com> |
--===============0325456333518343182== Content-Language: en-US Content-Type: multipart/alternative; boundary="_000_SA1PR11MB57773A1804728D01AB4348E0DE5EASA1PR11MB5777namp_" --_000_SA1PR11MB57773A1804728D01AB4348E0DE5EASA1PR11MB5777namp_ Content-Type: text/plain; charset="iso-8859-1" Content-Transfer-Encoding: quoted-printable By default, ClamAV will stop at the first match. If you want it to keep goi= ng to search for addition detections, you can enable all-match mode (the `-= -allmatch` option for both clamscan and clamdscan). Respectfully, Val Valerie Snyder (she/they) ClamAV Development Talos Cisco Systems, Inc. ________________________________ From: Paul Kosinski <[email protected]> Sent: Thursday, April 2, 2026 11:19 PM To: Valerie Snyder (valsnyde) <[email protected]> Cc: [email protected] <[email protected]> Subject: Re: [clamav-users] New signatures, different error msg for same Fi= refox file Are you saying that ClamAV (clamd) stops scanning as soon as it finds the f= irst piece of malware, and thus never gets to the "excessively deep" recurs= ion? In any case, I re-scanned an older Firefox Setup file (115.15.0) in the sam= e major release and it too gave the Excessive Recursion error. The file had= previously been scanned and "passed" by my old 0.103.6 ClamAV. And, upon e= xamining the associated clamd.conf, I see that AlertExceedsMax was never ex= plicitly set, and thus defaulted to NO. This is probably due to the fact that that option didn't come into existenc= e until "recently" -- compared to when I started seriously using ClamAV (ba= ck around 0.94 in 2008). Perhaps the moral of this story is that with most = software, when new options are added, you can usually ignore them until you= need them. But with security software, you have to be more vigilant, becau= se a new option might have a default value that could hide a potential risk= to your entire system. =3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D= =3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D =3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D= =3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D On Tue, 31 Mar 2026 22:17:38 -0400 Paul Kosinski via clamav-users <[email protected]> wrote: > As I reported a couple of days ago, ClamAV 1.0.9 found what was almost ce= rtainly a false positive, since VirusTotal said file was AOK: > > =3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D > Firefox Setup 115.34.0esr.exe: Win.Trojan.Spora-7724442-0 FOUND > > ----------- SCAN SUMMARY ----------- > Infected files: 1 > Time: 36.458 sec (0 m 36 s) > Start Date: 2026:03:26 10:03:00 > End Date: 2026:03:26 10:03:37 > RC =3D 1 > =3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D > > Today, sending the same Firefox file to my local clamd (1.0.9) with lates= t freshclam update gave a different error: > > =3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D > Firefox Setup 115.34.0esr.exe: Heuristics.Limits.Exceeded.MaxRecursion FO= UND > > ----------- SCAN SUMMARY ----------- > Infected files: 1 > Time: 41.079 sec (0 m 41 s) > Start Date: 2026:03:31 19:19:38 > End Date: 2026:03:31 19:20:19 > RC =3D 1 > =3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D > > So I upped the recursion limits from 30 (max-dir-rec) and 32 (max-rec) to= 40 and 40 and got ... > > =3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D > Firefox Setup 115.34.0esr.exe: Heuristics.Limits.Exceeded.MaxRecursion FO= UND > > ----------- SCAN SUMMARY ----------- > Infected files: 1 > Time: 87.691 sec (1 m 27 s) > Start Date: 2026:03:31 21:14:31 > End Date: 2026:03:31 21:15:59 > RC =3D 1 > =3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D > > Next I upped the recursion limits from 40/40 to 60/60 and got much the sa= me: > > =3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D > Firefox Setup 115.34.0esr.exe: Heuristics.Limits.Exceeded.MaxRecursion FO= UND > > ----------- SCAN SUMMARY ----------- > Infected files: 1 > Time: 95.908 sec (1 m 35 s) > Start Date: 2026:03:31 21:23:08 > End Date: 2026:03:31 21:24:44 > RC =3D 1 > =3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D > > So, are the new signatures broken too, but in a different way? > > If so, since today's behavior is so different from a few days ago, I'm no= t sure if I should report a False Positive, something else, or both via cla= msubmit. > > P.S. I am now beginning to wonder about VirusTotal. Could they be running= a version and configuration of ClamAV that doesn't really examine the enti= re file? The file is about 57 MB, well within ClamAV's 2 GB limit, and even= less than the *default* size cutoff of 100 MB. --_000_SA1PR11MB57773A1804728D01AB4348E0DE5EASA1PR11MB5777namp_ Content-Type: text/html; charset="iso-8859-1" Content-Transfer-Encoding: quoted-printable <html> <head> <meta http-equiv=3D"Content-Type" content=3D"text/html; charset=3Diso-8859-= 1"> <style type=3D"text/css" style=3D"display:none;"> P {margin-top:0;margin-bo= ttom:0;} </style> </head> <body dir=3D"ltr"> <div class=3D"elementToProof" style=3D"font-family: Aptos, Aptos_EmbeddedFo= nt, Aptos_MSFontService, Calibri, Helvetica, sans-serif; font-size: 12pt; c= olor: rgb(0, 0, 0); --darkreader-inline-color: var(--darkreader-text--darkC= olor_rgb_0__0__0_, var(--darkreader-text-000000, #e8e6e3));" data-darkreade= r-inline-color=3D""> By default, ClamAV will stop at the first match. If you want it to keep goi= ng to search for addition detections, you can enable all-match mode (the `-= -allmatch` option for both clamscan and clamdscan).</div> <div id=3D"Signature" class=3D"elementToProof"> <div class=3D"elementToProof" style=3D"font-family: Aptos, Aptos_EmbeddedFo= nt, Aptos_MSFontService, Calibri, Helvetica, sans-serif; font-size: 12pt; c= olor: rgb(0, 0, 0); --darkreader-inline-color: var(--darkreader-text--darkC= olor_rgb_0__0__0_, var(--darkreader-text-000000, #e8e6e3));" data-darkreade= r-inline-color=3D""> <br> </div> <div class=3D"elementToProof" style=3D"font-family: Calibri, Arial, Helveti= ca, sans-serif; font-size: 12pt; color: rgb(0, 0, 0); --darkreader-inline-c= olor: var(--darkreader-text--darkColor_rgb_0__0__0_, var(--darkreader-text-= 000000, #e8e6e3));" data-darkreader-inline-color=3D""> Respectfully,</div> <div class=3D"elementToProof" style=3D"font-family: Calibri, Arial, Helveti= ca, sans-serif; font-size: 12pt; color: rgb(0, 0, 0); --darkreader-inline-c= olor: var(--darkreader-text--darkColor_rgb_0__0__0_, var(--darkreader-text-= 000000, #e8e6e3));" data-darkreader-inline-color=3D""> Val</div> <div class=3D"elementToProof" style=3D"font-family: Calibri, Arial, Helveti= ca, sans-serif; font-size: 12pt; color: rgb(0, 0, 0); --darkreader-inline-c= olor: var(--darkreader-text--darkColor_rgb_0__0__0_, var(--darkreader-text-= 000000, #e8e6e3));" data-darkreader-inline-color=3D""> <br> <span style=3D"font-family: Helvetica; font-size: 12px;">Valerie Snyder (sh= e/they)</span><br> <span style=3D"font-family: Helvetica; font-size: 12px;">ClamAV Development= </span><br> <span style=3D"font-family: Helvetica; font-size: 12px;">Talos</span><br> <span style=3D"font-family: Helvetica; font-size: 12px;">Cisco Systems, Inc= .</span><br> </div> </div> <div style=3D"font-family: Aptos, Aptos_EmbeddedFont, Aptos_MSFontService, = Calibri, Helvetica, sans-serif; font-size: 12pt; color: rgb(0, 0, 0); --dar= kreader-inline-color: var(--darkreader-text--darkColor_rgb_0__0__0_, var(--= darkreader-text-000000, #e8e6e3));" data-darkreader-inline-color=3D""> <br> </div> <hr style=3D"display: inline-block; width: 98%;"> <div id=3D"divRplyFwdMsg"> <div style=3D"direction: ltr; font-family: Calibri, sans-serif; font-size: = 11pt; color: rgb(0, 0, 0); --darkreader-inline-color: var(--darkreader-text= --darkColor_rgb_0__0__0_, var(--darkreader-text-000000, #e8e6e3));" data-da= rkreader-inline-color=3D""> <b>From:</b> Paul Kosinski <[email protected]><br> <b>Sent:</b> Thursday, April 2, 2026 11:19 PM<br> <b>To:</b> Valerie Snyder (valsnyde) <[email protected]><br> <b>Cc:</b> [email protected] <[email protected]= .net><br> <b>Subject:</b> Re: [clamav-users] New signatures, different error msg= for same Firefox file</div> <div style=3D"direction: ltr;"> </div> </div> <div style=3D"font-size: 11pt;">Are you saying that ClamAV (clamd) stops sc= anning as soon as it finds the first piece of malware, and thus never gets = to the "excessively deep" recursion?<br> <br> In any case, I re-scanned an older Firefox Setup file (115.15.0) in the sam= e major release and it too gave the Excessive Recursion error. The file had= previously been scanned and "passed" by my old 0.103.6 ClamAV. A= nd, upon examining the associated clamd.conf, I see that AlertExceedsMax was never explicitly set, and thus defaulted to= NO.<br> <br> This is probably due to the fact that that option didn't come into existenc= e until "recently" -- compared to when I started seriously using = ClamAV (back around 0.94 in 2008). Perhaps the moral of this story is that = with most software, when new options are added, you can usually ignore them until you need them. But with security softwar= e, you have to be more vigilant, because a new option might have a default = value that could hide a potential risk to your entire system.<br> <br> =3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D= =3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D<br= > =3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D= =3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D<br= > <br> On Tue, 31 Mar 2026 22:17:38 -0400<br> Paul Kosinski via clamav-users <[email protected]> wrote:= <br> <br> > As I reported a couple of days ago, ClamAV 1.0.9 found what was almost= certainly a false positive, since VirusTotal said file was AOK:<br> ><br> > =3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D<br> > Firefox Setup 115.34.0esr.exe: Win.Trojan.Spora-7724442-0 FOUND<br> ><br> > ----------- SCAN SUMMARY -----------<br> > Infected files: 1<br> > Time: 36.458 sec (0 m 36 s)<br> > Start Date: 2026:03:26 10:03:00<br> > End Date: 2026:03:26 10:03:37<br> > RC =3D 1<br> > =3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D<br> ><br> > Today, sending the same Firefox file to my local clamd (1.0.9) with la= test freshclam update gave a different error:<br> ><br> > =3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D<br> > Firefox Setup 115.34.0esr.exe: Heuristics.Limits.Exceeded.MaxRecursion= FOUND<br> ><br> > ----------- SCAN SUMMARY -----------<br> > Infected files: 1<br> > Time: 41.079 sec (0 m 41 s)<br> > Start Date: 2026:03:31 19:19:38<br> > End Date: 2026:03:31 19:20:19<br> > RC =3D 1<br> > =3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D<br> ><br> > So I upped the recursion limits from 30 (max-dir-rec) and 32 (max-rec)= to 40 and 40 and got ...<br> ><br> > =3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D<br> > Firefox Setup 115.34.0esr.exe: Heuristics.Limits.Exceeded.MaxRecursion= FOUND<br> ><br> > ----------- SCAN SUMMARY -----------<br> > Infected files: 1<br> > Time: 87.691 sec (1 m 27 s)<br> > Start Date: 2026:03:31 21:14:31<br> > End Date: 2026:03:31 21:15:59<br> > RC =3D 1<br> > =3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D<br> ><br> > Next I upped the recursion limits from 40/40 to 60/60 and got much the= same:<br> ><br> > =3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D<br> > Firefox Setup 115.34.0esr.exe: Heuristics.Limits.Exceeded.MaxRecursion= FOUND<br> ><br> > ----------- SCAN SUMMARY -----------<br> > Infected files: 1<br> > Time: 95.908 sec (1 m 35 s)<br> > Start Date: 2026:03:31 21:23:08<br> > End Date: 2026:03:31 21:24:44<br> > RC =3D 1<br> > =3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D<br> ><br> > So, are the new signatures broken too, but in a different way?<br> ><br> > If so, since today's behavior is so different from a few days ago, I'm= not sure if I should report a False Positive, something else, or both via = clamsubmit.<br> ><br> > P.S. I am now beginning to wonder about VirusTotal. Could they be runn= ing a version and configuration of ClamAV that doesn't really examine the e= ntire file? The file is about 57 MB, well within ClamAV's 2 GB limit, and e= ven less than the *default* size cutoff of 100 MB.</div> </body> </html> --_000_SA1PR11MB57773A1804728D01AB4348E0DE5EASA1PR11MB5777namp_-- --===============0325456333518343182== Content-Type: text/plain; charset="us-ascii" MIME-Version: 1.0 Content-Transfer-Encoding: 7bit Content-Disposition: inline _______________________________________________ Manage your clamav-users mailing list subscription / unsubscribe: https://lists.clamav.net/mailman/listinfo/clamav-users Help us build a comprehensive ClamAV guide: https://github.com/Cisco-Talos/clamav-documentation https://docs.clamav.net/#mailing-lists-and-chat --===============0325456333518343182==--