Why does KlamAV keep marking an archive as infected with “Oversized.Zip” even though other virus scanners haven picked it up?
KlamAV marks a file with this infection, if the ArchiveMaxCompressionRatio limit is exceeded. This ratio can be increased in the Options dialog’s Archive Limits section, found from the Scan tab. An “Oversized.Zip” warning is an indicator that KlamAV has determined the compression ratio of the archive is higher than the pre-configured limit which could therefore be indicative of a potential logic bomb. This warning can also trigger on legitimate archives if the file(s) within them are objects which can be compressed significantly, such as BMP or plain text files.
Related Questions
- A client suspects their pet is infected with the 2009 H1N1 virus and wants to bring it in for examination and testing. What should we recommend?
- Why does KlamAV keep marking an archive as infected with "Oversized.Zip" even though other virus scanners haven picked it up?
- Are the Kennedys possibly infected with the Ebola virus?