Koozali.org: home of the SME Server

clamav false positives with zip files, someone else is noticing the same?

Offline albatroz

  • *****
  • 159
  • +0/-0
I have noticed that the clamav installation inside SME server is giving me
some false positives. For instance when someone sends me several files inside
a zip file it is detected as a virus infected file.

Is someone else suffering the same issue?

Thanks in advance

Offline albatroz

  • *****
  • 159
  • +0/-0
Re: clamav false positives with zip files, someone else is noticing the same?
« Reply #1 on: September 05, 2007, 06:03:30 PM »
Just adding more info about this issue:

the sender received when the email bounced
190.41.24.200 failed after I sent the message.
Remote host said: 552 Virus Found: Oversized.Zip

We are using SME 7.2

Offline Stefano

  • *
  • 10,894
  • +3/-0
Re: clamav false positives with zip files, someone else is noticing the same?
« Reply #2 on: September 05, 2007, 06:25:35 PM »
from a quick googling I've found:

Quote
Whenever a file exceeds ArchiveMaxCompressionRatio (see clamd.conf man page), it's considered a logic bomb and marked as Oversized.zip . Try increasing your ArchiveMaxCompressionRatio setting.

look for ArchiveMaxCompressionRatio, ArchiveMaxFileSize, ArchiveMaxFiles, ArchiveMaxRecursion in /etc/clamd.conf

and, of course, man clamd.conf ;-)

HTH

Ciao

Stefano

Offline albatroz

  • *****
  • 159
  • +0/-0
Re: clamav false positives with zip files, someone else is noticing the same?
« Reply #3 on: September 05, 2007, 06:26:21 PM »
Are those files templated?

Offline Stefano

  • *
  • 10,894
  • +3/-0
Re: clamav false positives with zip files, someone else is noticing the same?
« Reply #4 on: September 05, 2007, 06:29:06 PM »
Are those files templated?

it's only one file: /etc/clamd.conf

yes, it's templated..

Ciao

Stefano

Offline Normando

  • *
  • 841
  • +2/-1
    • Unixlan
Re: clamav false positives with zip files, someone else is noticing the same?
« Reply #5 on: September 06, 2007, 12:31:44 AM »
Are those files templated?
Please, see
http://wiki.contribs.org/DB_Variables_Configuration#Clam_AntiVirus_.28clamav.29

Also check if you have select some files under Ativirus - server-manager. Please, not check the last two zip files.