Clamav, handle with care

  • At first it took me a while until I got it running. Installing from the standard plugins went through without problems, but it wouldn't update (Saw that in the logs) and refused to start a scan (clamav Servname not supported for ai_socktype).
    Tried that twice again, same result. Then I thought it would be a good idea to install the openmediavault-omvextrasorg plugin, maybe there's another version, but it wasn't. Tried the installation once again and....oh, it runs. Looks like some needed parts will only be pulled and installed if the extrasorg-plugin is present.
    Would be a good idea to put that into a comment line with the clamav plugin, will save some time.


    And handle with care if you activate the PUA checkbox. Scanning for PUA (Probably Unwanted Application) is basically a good idea, but during the first scan on a download folder clamav moved about 535 exe-files to the quarantine. The reason for every move was that it found the PUA Win32.Packer, a kind of packaging program which is used for a lot of exe-files. At first I thought the whole download folder must be occupied by a million of viruses, but it only found this PUA. There are mostly original maker files like drivers, original Windows software like server resource kits and others. To my luck this is only a folder copied on a testing machine, if this has been running on the original folder I probably would have been jumped out of the window because years of collecting software were gone.


    So take care what you activate in the clamav config.

    Homebox: Bitfenix Prodigy Case, ASUS E45M1-I DELUXE ITX, 8GB RAM, 5x 4TB HGST Raid-5 Data, 1x 320GB 2,5" WD Bootdrive via eSATA from the backside
    Companybox 1: Standard Midi-Tower, Intel S3420 MoBo, Xeon 3450 CPU, 16GB RAM, 5x 2TB Seagate Data, 1x 80GB Samsung Bootdrive - testing for iSCSI to ESXi-Hosts
    Companybox 2: 19" Rackservercase 4HE, Intel S975XBX2 MoBo, C2D@2200MHz, 8GB RAM, HP P212 Raidcontroller, 4x 1TB WD Raid-0 Data, 80GB Samsung Bootdrive, Intel 1000Pro DualPort (Bonded in a VLAN) - Temp-NFS-storage for ESXi-Hosts

  • I've just started to scratch at the surface of clamav, but in the job definition you can only point it to shares on the machine, not to the system drive.
    To scan the system drive you have to compose a script executed by cron containing something like /usr/bin/clamscan -r --move=/home/USER/VIRUS /home/USER, more info @ http://askubuntu.com/questions…n-for-viruses-with-clamav or the ubuntu-wiki https://help.ubuntu.com/community/ClamAV


    And for the plugin dependencies, yes it looks like other plugins can be affected.

    Homebox: Bitfenix Prodigy Case, ASUS E45M1-I DELUXE ITX, 8GB RAM, 5x 4TB HGST Raid-5 Data, 1x 320GB 2,5" WD Bootdrive via eSATA from the backside
    Companybox 1: Standard Midi-Tower, Intel S3420 MoBo, Xeon 3450 CPU, 16GB RAM, 5x 2TB Seagate Data, 1x 80GB Samsung Bootdrive - testing for iSCSI to ESXi-Hosts
    Companybox 2: 19" Rackservercase 4HE, Intel S975XBX2 MoBo, C2D@2200MHz, 8GB RAM, HP P212 Raidcontroller, 4x 1TB WD Raid-0 Data, 80GB Samsung Bootdrive, Intel 1000Pro DualPort (Bonded in a VLAN) - Temp-NFS-storage for ESXi-Hosts

    Einmal editiert, zuletzt von datadigger ()

Jetzt mitmachen!

Sie haben noch kein Benutzerkonto auf unserer Seite? Registrieren Sie sich kostenlos und nehmen Sie an unserer Community teil!