Benny Pedersen | 24 Mar 2013 15:22
Picon

http://blog.clamav.net/2013/02/resolving-issues-with-freshclam.html

daily.cvd is still here on 63 after doing this "fix"

note that the url says 73, so is it fixed now ?
_______________________________________________
Help us build a comprehensive ClamAV guide: visit http://wiki.clamav.net
http://www.clamav.net/support/ml

Jerry | 24 Mar 2013 12:15
Face

SubmitDetectionStats error message after update

Ever since I updated "clamav" the other day, the "freshclam.log" has
been filling up with the following.

Sun Mar 24 06:43:43 2013 -> Received signal: wake up
Sun Mar 24 06:43:43 2013 -> ClamAV update process started at Sun Mar 24 06:43:43 2013
Sun Mar 24 06:43:43 2013 -> main.cld is up to date (version: 54, sigs: 1044387, f-level: 60, builder: sven)
Sun Mar 24 06:43:43 2013 -> daily.cld is up to date (version: 16892, sigs: 981794, f-level: 63, builder: neo)
Sun Mar 24 06:43:43 2013 -> bytecode.cld is up to date (version: 214, sigs: 41, f-level: 63, builder: neo)
Sun Mar 24 06:44:32 2013 -> nonblock_recv: recv timing out (30 secs)
Sun Mar 24 06:44:32 2013 -> ERROR: SubmitDetectionStats: Can't read from socket

The actual setting is:

SubmitDetectionStats /usr/local/etc/clamd.conf

Everything was working fine until the update. Nothing was modified and
I have tried to do a hard reboot to see if it made any difference, but
it didn't.

I welcome any suggestions.

--

-- 
Jerry ♔

Disclaimer: off-list followups get on-list replies or get ignored.
Please do not ignore the Reply-To header.
__________________________________________________________________

_______________________________________________
Help us build a comprehensive ClamAV guide: visit http://wiki.clamav.net
(Continue reading)

Ben Stuyts | 22 Mar 2013 18:11
Picon
Favicon

Client disconnected while scanjob was active

Hi,

I was using clamscan for daily scanning of our user's home directories, but it was getting too slow with scan
times of up to 6 hours. Therefor I'm testing clamdscan and using multiple threads to scan. (cmd line is
/usr/local/bin/clamdscan -m --fdpass /home)

I am getting the following error messages from clamd while scanning, and it's missing a lot of files. If put
the Eicar test file at various spots and it's being missed by the scan.

Thu Mar 21 22:00:01 2013 -> SelfCheck: Database status OK.
Thu Mar 21 22:10:01 2013 -> SelfCheck: Database status OK.
Thu Mar 21 22:13:48 2013 -> Client disconnected while scanjob was active
Thu Mar 21 22:13:48 2013 -> Client disconnected while scanjob was active
(repeat...)
Thu Mar 21 22:14:06 2013 -> Client disconnected while scanjob was active
Thu Mar 21 22:17:29 2013 -> Reading databases from /var/db/clamav
Thu Mar 21 22:17:36 2013 -> Database correctly reloaded (2019434 signatures)

Output from clamdscan, no errors:

----------- SCAN SUMMARY -----------
Infected files: 0
Time: 3846.032 sec (64 m 6 s)

This is on FreeBSD 7.4-stable, clamav-0.97.7 (clamav-0.97.6 had the same problem). The home directories
are all zfs based. clamd runs as user clamav, clamdscan as user root.

What could be causing this?

Kind regards,
(Continue reading)

Christian Salway | 22 Mar 2013 17:40
Gravatar

Memory level

In your new version, can you please consider how to run it on low memory
systems (<512MB) for spamassassin other than direct from the command line
which takes time to load each time it's called.

Our basic internet servers we roll out to dedicated clients run on the
Amazon EC2 micro servers and consist of mysql, postfix, dovecot, apache,
spamassassin and clamd (disabled).  Disabled because it consumes too much
RAM and deemed the least required because antivirus is readily available on
desktops, tablets and phones and most clients would prefer to deal with one
or two virus' messages than 100's of spam messages.

At the moment, on the Amazon EC2 micro servers, there is 512Mb RAM
available, of which, clamd consumes 30% if enabled, taking the RAM load from
165/512MB to 337/512MB, and that's before the server has started processing
anything.

Kind regards,
Christian

_______________________________________________
Help us build a comprehensive ClamAV guide: visit http://wiki.clamav.net
http://www.clamav.net/support/ml

Rick Macdougall | 22 Mar 2013 14:56

Strange error with freshclam

Hi,

Re-post since I didn't see it hit the list.

For some reason one of our mail servers is being denied access to 
download the latest cvd file because it is too out of date.  Current 
version is the latest 97.7 and before that it was 97.6.

Current working dir is /usr/local/share/clamav
Max retries == 3
ClamAV update process started at Thu Mar 21 12:02:36 2013
Using IPv6 aware code
Querying current.cvd.clamav.net
TTL: 900
Software version from DNS: 0.97.7
main.cvd version from DNS: 54
main.cld is up to date (version: 54, sigs: 1044387, f-level: 60, 
builder: sven)
daily.cvd version from DNS: 16879
Retrieving http://database.clamav.net/daily-16682.cdiff
Ignoring mirror 208.70.244.158 (has connected too many times with an 
outdated version)
Ignoring mirror 24.215.0.24 (has connected too many times with an 
outdated version)
Ignoring mirror 200.236.31.1 (has connected too many times with an 
outdated version)
Ignoring mirror 128.177.8.248 (has connected too many times with an 
outdated version)
Ignoring mirror 208.70.244.158 (has connected too many times with an 
outdated version)
(Continue reading)

Paul Whelan | 22 Mar 2013 13:00
Picon

PUA types

What PUA category does "PUA.OLE.EmbeddedPDF" come under? (Triggered by a Word 
document).

paul

_______________________________________________
Help us build a comprehensive ClamAV guide: visit http://wiki.clamav.net
http://www.clamav.net/support/ml

Rick Macdougall | 21 Mar 2013 17:05

Strange error with freshclam

Hi,

For some reason one of our mail servers is being denied access to 
download the latest cvd file because it is too out of date.  Current 
version is the latest 97.7 and before that it was 97.6.

Current working dir is /usr/local/share/clamav
Max retries == 3
ClamAV update process started at Thu Mar 21 12:02:36 2013
Using IPv6 aware code
Querying current.cvd.clamav.net
TTL: 900
Software version from DNS: 0.97.7
main.cvd version from DNS: 54
main.cld is up to date (version: 54, sigs: 1044387, f-level: 60, 
builder: sven)
daily.cvd version from DNS: 16879
Retrieving http://database.clamav.net/daily-16682.cdiff
Ignoring mirror 208.70.244.158 (has connected too many times with an 
outdated version)
Ignoring mirror 24.215.0.24 (has connected too many times with an 
outdated version)
Ignoring mirror 200.236.31.1 (has connected too many times with an 
outdated version)
Ignoring mirror 128.177.8.248 (has connected too many times with an 
outdated version)
Ignoring mirror 208.70.244.158 (has connected too many times with an 
outdated version)
...

(Continue reading)

Paul Wise | 26 Nov 2012 04:19
Picon
Favicon
Gravatar

looking for Bill Landry <bill <at> inetmsg.com>

Hi all,

Bill Landry is the developer of clamav-unofficial-sigs and since I'm the
Debian maintainer of that, I need to discuss some things with him but
his domain inetmsg.com doesn't respond to HTTP or SMTP connections. Does
anyone know what happened to him or if he moved to a different domain?

PS: whats the status of clamav support for third-party signatures?

--

-- 
bye,
pabs

http://wiki.debian.org/PaulWise
_______________________________________________
Help us build a comprehensive ClamAV guide: visit http://wiki.clamav.net
http://www.clamav.net/support/ml
Konrad | 17 Mar 2013 10:57
Picon
Picon

clamd (0.97.7) stops working after the first call

Hi All,

I'm new to this forum and I know that this is a UNIX only mailing list. 
My problem is related to a Win XP installation but I was hoping that you 
can at least give me some hints on how to debug clamd or increase the 
log level so that I will see what is going on! The Windows mailing list 
seems to be "dead" so I guess that I will not get any help from there. 
If you are not willing to answer Windows related questions, just let me 
know...

My problem:

I'm using ClamAV together with my mail server (Mercury) on a Windows XP 
box and v 0.95 works great so far. Now I wanted to upgrade to 0.97.7 but 
I can't get it working. If I start clamd manually in a shell, I can see 
that it is coming up "normal" and the process is visible in the task 
manager. The first mail is scanned OK and if it contains a virus 
attachment, clamd detects it. So far, so good. But from that moment on, 
it stops working and every next call is not processed anymore. No idea 
what is going on... I tried to activate logs but the log does not say 
much. Is there is way to increase the log level to get more information?

I tried something else:

I started clamd in one shell window and opened another shell to connect 
with telnet and 127.0.0.1 3310 and it gets connected. Pressing any key, 
I get UNKNOWN COMMAND and telnet exits. If I repeat this test, I can key 
in as much as I like, the UNKNOWN COMMAND error message does not appear 
anymore and telnet keeps running. If I do this with the OK working 0.95 
installation, I get UNKNOWN COMMAND every time and telnet always exits 
(Continue reading)

Christian Salway | 16 Mar 2013 18:44
Gravatar

duplicate clamd processes

At the moment when I start clamd, it spawns two processes with different
PID's, the problem is I don't have enough memory to run two so I have been
trying to figure out how to spawn only one.

I've searched the internet, I've also asked around on forums and looked in
the manuals, but no one seems to know how to limit it.  Can anyone help?

You can see an image of the problem here
http://unix.stackexchange.com/questions/68155/limit-clamav-to-one-thread

Hope someone can help

Kind regards,

Christian

_______________________________________________
Help us build a comprehensive ClamAV guide: visit http://wiki.clamav.net
http://www.clamav.net/support/ml

Eray Aslan | 15 Mar 2013 12:44
Picon

llvm library

I see that clamav is bundling llvm library along with its code.

* What does llvm buy me exactly for clamav?  In other words, why do I
want to turn it on?  Or do I even want to turn it on?
* I dont think bundling a library is such a great idea.  Fortunately,
there is a --with-system-llvm switch in the configure script.  I believe
clamav is shipping llvm-2.8.  Upstream seems to be at llvm-3.2.  Are
there any compatibility tests being made?  Does clamav have a version
restriction regarding the llvm library it uses?

Thanks.
--

-- 
Eray Aslan
_______________________________________________
Help us build a comprehensive ClamAV guide: visit http://wiki.clamav.net
http://www.clamav.net/support/ml


Gmane