Re: New signatures, different error msg for same Firefox file

"Valerie Snyder \(valsnyde\) via clamav-users" <[email protected]> Fri, 3 Apr 2026 15:49:27 +0000
Newsgroups gmane.comp.security.virus.clamav.user
Message-ID <SA1PR11MB57773A1804728D01AB4348E0DE5EA@SA1PR11MB5777.namprd11.prod.outlook.com>
--===============0325456333518343182==
Content-Language: en-US
Content-Type: multipart/alternative;
	boundary="_000_SA1PR11MB57773A1804728D01AB4348E0DE5EASA1PR11MB5777namp_"

--_000_SA1PR11MB57773A1804728D01AB4348E0DE5EASA1PR11MB5777namp_
Content-Type: text/plain; charset="iso-8859-1"
Content-Transfer-Encoding: quoted-printable

By default, ClamAV will stop at the first match. If you want it to keep goi=
ng to search for addition detections, you can enable all-match mode (the `-=
-allmatch` option for both clamscan and clamdscan).

Respectfully,
Val

Valerie Snyder (she/they)
ClamAV Development
Talos
Cisco Systems, Inc.

________________________________
From: Paul Kosinski <[email protected]>
Sent: Thursday, April 2, 2026 11:19 PM
To: Valerie Snyder (valsnyde) <[email protected]>
Cc: [email protected] <[email protected]>
Subject: Re: [clamav-users] New signatures, different error msg for same Fi=
refox file

Are you saying that ClamAV (clamd) stops scanning as soon as it finds the f=
irst piece of malware, and thus never gets to the "excessively deep" recurs=
ion?

In any case, I re-scanned an older Firefox Setup file (115.15.0) in the sam=
e major release and it too gave the Excessive Recursion error. The file had=
 previously been scanned and "passed" by my old 0.103.6 ClamAV. And, upon e=
xamining the associated clamd.conf, I see that AlertExceedsMax was never ex=
plicitly set, and thus defaulted to NO.

This is probably due to the fact that that option didn't come into existenc=
e until "recently" -- compared to when I started seriously using ClamAV (ba=
ck around 0.94 in 2008). Perhaps the moral of this story is that with most =
software, when new options are added, you can usually ignore them until you=
 need them. But with security software, you have to be more vigilant, becau=
se a new option might have a default value that could hide a potential risk=
 to your entire system.

=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=
=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D
=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=
=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D

On Tue, 31 Mar 2026 22:17:38 -0400
Paul Kosinski via clamav-users <[email protected]> wrote:

> As I reported a couple of days ago, ClamAV 1.0.9 found what was almost ce=
rtainly a false positive, since VirusTotal said file was AOK:
>
> =3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D
> Firefox Setup 115.34.0esr.exe: Win.Trojan.Spora-7724442-0 FOUND
>
> ----------- SCAN SUMMARY -----------
> Infected files: 1
> Time: 36.458 sec (0 m 36 s)
> Start Date: 2026:03:26 10:03:00
> End Date:   2026:03:26 10:03:37
> RC =3D 1
> =3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D
>
> Today, sending the same Firefox file to my local clamd (1.0.9) with lates=
t freshclam update gave a different error:
>
> =3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D
> Firefox Setup 115.34.0esr.exe: Heuristics.Limits.Exceeded.MaxRecursion FO=
UND
>
> ----------- SCAN SUMMARY -----------
> Infected files: 1
> Time: 41.079 sec (0 m 41 s)
> Start Date: 2026:03:31 19:19:38
> End Date:   2026:03:31 19:20:19
> RC =3D 1
> =3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D
>
> So I upped the recursion limits from 30 (max-dir-rec) and 32 (max-rec) to=
 40 and 40 and got ...
>
> =3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D
> Firefox Setup 115.34.0esr.exe: Heuristics.Limits.Exceeded.MaxRecursion FO=
UND
>
> ----------- SCAN SUMMARY -----------
> Infected files: 1
> Time: 87.691 sec (1 m 27 s)
> Start Date: 2026:03:31 21:14:31
> End Date:   2026:03:31 21:15:59
> RC =3D 1
> =3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D
>
> Next I upped the recursion limits from 40/40 to 60/60 and got much the sa=
me:
>
> =3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D
> Firefox Setup 115.34.0esr.exe: Heuristics.Limits.Exceeded.MaxRecursion FO=
UND
>
> ----------- SCAN SUMMARY -----------
> Infected files: 1
> Time: 95.908 sec (1 m 35 s)
> Start Date: 2026:03:31 21:23:08
> End Date:   2026:03:31 21:24:44
> RC =3D 1
> =3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D
>
> So, are the new signatures broken too, but in a different way?
>
> If so, since today's behavior is so different from a few days ago, I'm no=
t sure if I should report a False Positive, something else, or both via cla=
msubmit.
>
> P.S. I am now beginning to wonder about VirusTotal. Could they be running=
 a version and configuration of ClamAV that doesn't really examine the enti=
re file? The file is about 57 MB, well within ClamAV's 2 GB limit, and even=
 less than the *default* size cutoff of 100 MB.

--_000_SA1PR11MB57773A1804728D01AB4348E0DE5EASA1PR11MB5777namp_
Content-Type: text/html; charset="iso-8859-1"
Content-Transfer-Encoding: quoted-printable

<html>
<head>
<meta http-equiv=3D"Content-Type" content=3D"text/html; charset=3Diso-8859-=
1">
<style type=3D"text/css" style=3D"display:none;"> P {margin-top:0;margin-bo=
ttom:0;} </style>
</head>
<body dir=3D"ltr">
<div class=3D"elementToProof" style=3D"font-family: Aptos, Aptos_EmbeddedFo=
nt, Aptos_MSFontService, Calibri, Helvetica, sans-serif; font-size: 12pt; c=
olor: rgb(0, 0, 0); --darkreader-inline-color: var(--darkreader-text--darkC=
olor_rgb_0__0__0_, var(--darkreader-text-000000, #e8e6e3));" data-darkreade=
r-inline-color=3D"">
By default, ClamAV will stop at the first match. If you want it to keep goi=
ng to search for addition detections, you can enable all-match mode (the `-=
-allmatch` option for both clamscan and clamdscan).</div>
<div id=3D"Signature" class=3D"elementToProof">
<div class=3D"elementToProof" style=3D"font-family: Aptos, Aptos_EmbeddedFo=
nt, Aptos_MSFontService, Calibri, Helvetica, sans-serif; font-size: 12pt; c=
olor: rgb(0, 0, 0); --darkreader-inline-color: var(--darkreader-text--darkC=
olor_rgb_0__0__0_, var(--darkreader-text-000000, #e8e6e3));" data-darkreade=
r-inline-color=3D"">
<br>
</div>
<div class=3D"elementToProof" style=3D"font-family: Calibri, Arial, Helveti=
ca, sans-serif; font-size: 12pt; color: rgb(0, 0, 0); --darkreader-inline-c=
olor: var(--darkreader-text--darkColor_rgb_0__0__0_, var(--darkreader-text-=
000000, #e8e6e3));" data-darkreader-inline-color=3D"">
Respectfully,</div>
<div class=3D"elementToProof" style=3D"font-family: Calibri, Arial, Helveti=
ca, sans-serif; font-size: 12pt; color: rgb(0, 0, 0); --darkreader-inline-c=
olor: var(--darkreader-text--darkColor_rgb_0__0__0_, var(--darkreader-text-=
000000, #e8e6e3));" data-darkreader-inline-color=3D"">
Val</div>
<div class=3D"elementToProof" style=3D"font-family: Calibri, Arial, Helveti=
ca, sans-serif; font-size: 12pt; color: rgb(0, 0, 0); --darkreader-inline-c=
olor: var(--darkreader-text--darkColor_rgb_0__0__0_, var(--darkreader-text-=
000000, #e8e6e3));" data-darkreader-inline-color=3D"">
<br>
<span style=3D"font-family: Helvetica; font-size: 12px;">Valerie Snyder (sh=
e/they)</span><br>
<span style=3D"font-family: Helvetica; font-size: 12px;">ClamAV Development=
</span><br>
<span style=3D"font-family: Helvetica; font-size: 12px;">Talos</span><br>
<span style=3D"font-family: Helvetica; font-size: 12px;">Cisco Systems, Inc=
.</span><br>
</div>
</div>
<div style=3D"font-family: Aptos, Aptos_EmbeddedFont, Aptos_MSFontService, =
Calibri, Helvetica, sans-serif; font-size: 12pt; color: rgb(0, 0, 0); --dar=
kreader-inline-color: var(--darkreader-text--darkColor_rgb_0__0__0_, var(--=
darkreader-text-000000, #e8e6e3));" data-darkreader-inline-color=3D"">
<br>
</div>
<hr style=3D"display: inline-block; width: 98%;">
<div id=3D"divRplyFwdMsg">
<div style=3D"direction: ltr; font-family: Calibri, sans-serif; font-size: =
11pt; color: rgb(0, 0, 0); --darkreader-inline-color: var(--darkreader-text=
--darkColor_rgb_0__0__0_, var(--darkreader-text-000000, #e8e6e3));" data-da=
rkreader-inline-color=3D"">
<b>From:</b>&nbsp;Paul Kosinski &lt;[email protected]&gt;<br>
<b>Sent:</b>&nbsp;Thursday, April 2, 2026 11:19 PM<br>
<b>To:</b>&nbsp;Valerie Snyder (valsnyde) &lt;[email protected]&gt;<br>
<b>Cc:</b>&nbsp;[email protected] &lt;[email protected]=
.net&gt;<br>
<b>Subject:</b>&nbsp;Re: [clamav-users] New signatures, different error msg=
 for same Firefox file</div>
<div style=3D"direction: ltr;">&nbsp;</div>
</div>
<div style=3D"font-size: 11pt;">Are you saying that ClamAV (clamd) stops sc=
anning as soon as it finds the first piece of malware, and thus never gets =
to the &quot;excessively deep&quot; recursion?<br>
<br>
In any case, I re-scanned an older Firefox Setup file (115.15.0) in the sam=
e major release and it too gave the Excessive Recursion error. The file had=
 previously been scanned and &quot;passed&quot; by my old 0.103.6 ClamAV. A=
nd, upon examining the associated clamd.conf,
 I see that AlertExceedsMax was never explicitly set, and thus defaulted to=
 NO.<br>
<br>
This is probably due to the fact that that option didn't come into existenc=
e until &quot;recently&quot; -- compared to when I started seriously using =
ClamAV (back around 0.94 in 2008). Perhaps the moral of this story is that =
with most software, when new options are added,
 you can usually ignore them until you need them. But with security softwar=
e, you have to be more vigilant, because a new option might have a default =
value that could hide a potential risk to your entire system.<br>
<br>
=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=
=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D<br=
>
=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=
=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D<br=
>
<br>
On Tue, 31 Mar 2026 22:17:38 -0400<br>
Paul Kosinski via clamav-users &lt;[email protected]&gt; wrote:=
<br>
<br>
&gt; As I reported a couple of days ago, ClamAV 1.0.9 found what was almost=
 certainly a false positive, since VirusTotal said file was AOK:<br>
&gt;<br>
&gt; =3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D<br>
&gt; Firefox Setup 115.34.0esr.exe: Win.Trojan.Spora-7724442-0 FOUND<br>
&gt;<br>
&gt; ----------- SCAN SUMMARY -----------<br>
&gt; Infected files: 1<br>
&gt; Time: 36.458 sec (0 m 36 s)<br>
&gt; Start Date: 2026:03:26 10:03:00<br>
&gt; End Date:&nbsp;&nbsp; 2026:03:26 10:03:37<br>
&gt; RC =3D 1<br>
&gt; =3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D<br>
&gt;<br>
&gt; Today, sending the same Firefox file to my local clamd (1.0.9) with la=
test freshclam update gave a different error:<br>
&gt;<br>
&gt; =3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D<br>
&gt; Firefox Setup 115.34.0esr.exe: Heuristics.Limits.Exceeded.MaxRecursion=
 FOUND<br>
&gt;<br>
&gt; ----------- SCAN SUMMARY -----------<br>
&gt; Infected files: 1<br>
&gt; Time: 41.079 sec (0 m 41 s)<br>
&gt; Start Date: 2026:03:31 19:19:38<br>
&gt; End Date:&nbsp;&nbsp; 2026:03:31 19:20:19<br>
&gt; RC =3D 1<br>
&gt; =3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D<br>
&gt;<br>
&gt; So I upped the recursion limits from 30 (max-dir-rec) and 32 (max-rec)=
 to 40 and 40 and got ...<br>
&gt;<br>
&gt; =3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D<br>
&gt; Firefox Setup 115.34.0esr.exe: Heuristics.Limits.Exceeded.MaxRecursion=
 FOUND<br>
&gt;<br>
&gt; ----------- SCAN SUMMARY -----------<br>
&gt; Infected files: 1<br>
&gt; Time: 87.691 sec (1 m 27 s)<br>
&gt; Start Date: 2026:03:31 21:14:31<br>
&gt; End Date:&nbsp;&nbsp; 2026:03:31 21:15:59<br>
&gt; RC =3D 1<br>
&gt; =3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D<br>
&gt;<br>
&gt; Next I upped the recursion limits from 40/40 to 60/60 and got much the=
 same:<br>
&gt;<br>
&gt; =3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D<br>
&gt; Firefox Setup 115.34.0esr.exe: Heuristics.Limits.Exceeded.MaxRecursion=
 FOUND<br>
&gt;<br>
&gt; ----------- SCAN SUMMARY -----------<br>
&gt; Infected files: 1<br>
&gt; Time: 95.908 sec (1 m 35 s)<br>
&gt; Start Date: 2026:03:31 21:23:08<br>
&gt; End Date:&nbsp;&nbsp; 2026:03:31 21:24:44<br>
&gt; RC =3D 1<br>
&gt; =3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D<br>
&gt;<br>
&gt; So, are the new signatures broken too, but in a different way?<br>
&gt;<br>
&gt; If so, since today's behavior is so different from a few days ago, I'm=
 not sure if I should report a False Positive, something else, or both via =
clamsubmit.<br>
&gt;<br>
&gt; P.S. I am now beginning to wonder about VirusTotal. Could they be runn=
ing a version and configuration of ClamAV that doesn't really examine the e=
ntire file? The file is about 57 MB, well within ClamAV's 2 GB limit, and e=
ven less than the *default* size cutoff
 of 100 MB.</div>
</body>
</html>

--_000_SA1PR11MB57773A1804728D01AB4348E0DE5EASA1PR11MB5777namp_--

--===============0325456333518343182==
Content-Type: text/plain; charset="us-ascii"
MIME-Version: 1.0
Content-Transfer-Encoding: 7bit
Content-Disposition: inline

_______________________________________________

Manage your clamav-users mailing list subscription / unsubscribe:
https://lists.clamav.net/mailman/listinfo/clamav-users


Help us build a comprehensive ClamAV guide:
https://github.com/Cisco-Talos/clamav-documentation

https://docs.clamav.net/#mailing-lists-and-chat

--===============0325456333518343182==--