Questions tagged [clamav]

Antivirus for UNIX-like systems primarily for mailserver integration.

Clam AntiVirus is an open source (GPL) anti-virus toolkit for UNIX, designed especially for e-mail scanning on mail gateways. It provides a number of utilities including a flexible and scalable multi-threaded daemon, a command line scanner and advanced tool for automatic database updates. The core of the package is an anti-virus engine available in a form of shared library.

  • command-line scanner
  • fast, multi-threaded daemon with support for on-access scanning
  • milter interface for sendmail
  • advanced database updater with support for scripted updates and digital signatures
  • virus scanner C library
  • on-access scanning (Linux® and FreeBSD®)
  • virus database updated multiple times per day (see home page for total number of signatures)
  • built-in support for various archive formats, including Zip, RAR, Tar, Gzip, Bzip2, OLE2, Cabinet, CHM, BinHex, SIS and others
  • built-in support for almost all mail file formats
  • built-in support for ELF executables and Portable Executable files compressed with UPX, FSG, Petite, NsPack, wwpack32, MEW, Upack and obfuscated with SUE, Y0da Cryptor and others

Official site: www.clamav.net

158 questions
5
votes
1 answer

Squid + ClamAV + i-cap: Scanning proxy for uploaded files?

I'm trying to configure a virus scanning proxy server specifically to scan files being uploaded. Scanning flies being downloaded seems to be the common use case, and seems to be well documented. Not being a squid or i-cap expert, I'm using…
5
votes
1 answer

clamav-daemon start condition failed, /var/lib/clamav/daily.{c[vl]d,inc} was not met

After installing Modoboa(Open Source Mail Hosting), I Tried to start clamav-daemon, but i faced start condition failed. systemctl status clamav-daemon.service clamav-daemon.service - Clam AntiVirus userspace daemon Loaded: loaded…
Omid Estaji
  • 213
  • 1
  • 3
  • 11
5
votes
2 answers

avoid redundant writing of virus scan signatures in VMs on same disk

I have two VMs on the same disk that each have clamav installed. Both regularly run updates for the same virus scan signatures simultaneously which results in an unnecessary strain on the performance of the disk every time. Since those are the same…
schf1919
  • 59
  • 2
4
votes
2 answers

Scan the full filesystem in parallel with clamscan

I run a clamav scan weekly on my servers. There is one server with a raid6 cluster of 30TB of disk space where the scan take more than 24h to run. So I wonder how can I run clamscan on the whole filesystem, taking advantage of the several cores the…
azmeuk
  • 195
  • 1
  • 2
  • 16
4
votes
1 answer

correct order for Postfix milters

I use the following milters with Postfix: ClamAV, OpenDKIM, OpenDMARC, Rspamd This is also the order they are being called via smtpd_milters. What would be the best order for them regarding performance, resources and spam protection?
basbebe
  • 313
  • 2
  • 16
4
votes
3 answers

Disable ClamAV for Amavis

I have a Postfix mail server, using Amavis and Spamassassin to check for unwanted e-mails. I have removed ClamAV because it'd basically freeze the whole server every time someone received an e-mail, and server-side virus-scanning does not seem to…
RobinJ
  • 187
  • 1
  • 3
  • 14
4
votes
3 answers

Where is ClamAV quarantine folder?

I want to restore some files from quarantine after I have executed clamscan some times. But I cannot find the quarantine folder in the configuration. How should I find the address of the quarantined file?
smhnaji
  • 619
  • 2
  • 11
  • 24
4
votes
3 answers

How to scan only last 24 hours files with clamav

I've create a bash script to scan whole server for virus via clamav. The script has been running via cron every night. Because of this I want to scan only the files that has been added last 24 hours. For now I am using this command in my…
Ehsan
  • 247
  • 2
  • 5
4
votes
1 answer

How do I configure MailScanner to use a remote clamd?

I decided to decrease the workload on my mail gateway by moving anti-virus processing to a separate server. I created the server, installed clamav-daemon on it, and tested it by running clamdscan from the mail gateway. Satisfied, I then changed…
Daniel C. Sobral
  • 5,713
  • 6
  • 34
  • 48
4
votes
2 answers

Exim4 won't send message

My exim4 don't send any message. The logs says 2011-03-09 15:59:57 1PxKrl-00038i-BT malware acl condition: clamd: ClamAV returned /var/spool/exim4/scan/1PxKrl-00038i-BT: lstat() failed: Permission denied. ERROR I supose that clamav (running clamd)…
PeterMmm
  • 895
  • 16
  • 28
4
votes
1 answer

How are systemd/system overrides supposed to work?

I'm messing around with some timeout settings, and am trying to figure out the correct way to set things for systemd/system daemons. Specifically, this is an underpowered server, and I keep timing out on starting clamd, so I'm trying to figure out…
philolegein
  • 409
  • 4
  • 12
3
votes
1 answer

ClamAV signature to ban office documents with macros

We are using custom signatures for ClamAV database to ban some types of files when they're attached to one email. This it's done using clamd and clamassassin with procmail. We're looking to add a rule in our custom rules for ClamAV to ban emails…
NetVicious
  • 462
  • 5
  • 17
3
votes
1 answer

System-wide virus scans in Ubuntu?

I installed ClamAV (clamav-daemon and clamav-freshclam) in order to set up a policy of regularly scanning my LTSP thin client setup for Windows viruses. Currently, we have a variety of users, each with their own group. All files in their home…
lfaraone
  • 1,611
  • 3
  • 18
  • 23
3
votes
2 answers

Process 'clamd' "not monitored"

the output of monit summary says clamav is not monitored. The configuration says: check process clamd with pidfile /var/run/clamav/clamd.pid start program = "/etc/init.d/clamav-daemon start" stop program = "/etc/init.d/clamav-daemon stop" if…
Adripants
  • 347
  • 2
  • 5
  • 16
3
votes
3 answers

Scan whole system or just user dirs with clamav

I'm in doubt about how to scan my Linux system with Clamav: do I just scan the places where users can upload files (homedirs, their webroots) or do I scan the whole system? The various sites I've read vary in opinion, some say you needn't scan the…
datadevil
  • 535
  • 1
  • 7
  • 22
1
2
3
10 11