[clamav-users] Samba vfs_virusfilter and clamd

2021-04-27 Thread Matthias Leopold via clamav-users
Hi, do I get it right that clamd has to run as root to work with vfs_virusfilter in Samba 4.13? I really thought I ran it as non-root the last time I tested it, but now I can't reproduce it and this confuses me. thanks Matthias PS I also posted this to Samba mailing list __

Re: [clamav-users] Problema antivirus su Nas QNAP

2021-04-27 Thread Matus UHLAR - fantomas
On 26.04.21 22:49, Federico Dal Zotto via clamav-users wrote: possiedo un Nas QNAP TS-231 According to https://www.qnap.com/en/product/ts-231/specs/hardware the TS-231 only has 512MB of RAM, while clamav needs >1GB. AFAIk TS-231 can't be expanded with more RAM. I'm afraid that ClamAV on your

Re: [clamav-users] Odd behavior when scanning eicar test files

2021-04-27 Thread Haukur Valgeirsson via clamav-users
Hi again. Now I am getting really confused. I repeated the tests but now scanning the eicar files in different directories in the same scan. I compiled the file list into a file that I read into an array in bash and pass to clamscan. The results differ between directories, even if the files in

[clamav-users] CLAMAD - Connecting to socket failed

2021-04-27 Thread Zami3l via clamav-users
Hello everyone, I have installed clamav for use with samba vfs virus filter. I want to be able to scan files as soon as they are opened. Operating System: CentOS Linux release 7.9.2009 (Core) The clamd@scan and smb services have no errors at boot time. As soon as a file is opened, an error appe

Re: [clamav-users] CLAMAD - Connecting to socket failed

2021-04-27 Thread Eero Volotinen
is the clamdscan working correctly? what is selinux status? is it running on permissive mode? Eero On Tue 27. Apr 2021 at 13.19, Zami3l via clamav-users < clamav-users@lists.clamav.net> wrote: > Hello everyone, > > I have installed clamav for use with samba vfs virus filter. > I want to be able

Re: [clamav-users] Odd behavior when scanning eicar test files

2021-04-27 Thread Haukur Valgeirsson via clamav-users
Now the plot thickens. Sorry for the "spam", but I am just trying to convey useful information. I tested a bunch of quarantined php injections. Whitelisting each of these worked exactly as expected, only the whitelisted file was "clean" (md5 checksum whitelisting). Then I used one of these fil

Re: [clamav-users] CLAMAD - Connecting to socket failed

2021-04-27 Thread Zami3l via clamav-users
Selinux is disabled. No problem with clamdscan when I run a scan. I performed further testing and noticed that: If I restart clamdscan and then smb everything seems to work. For example, if I try to open eicar.com (test virus), it detects malware and removes it. I can then easily open xls, doc,

Re: [clamav-users] CLAMAD - Connecting to socket failed

2021-04-27 Thread Eero Volotinen
Is there enough memory on server? check out the clamd* logs. Eero On Tue, Apr 27, 2021 at 4:47 PM Zami3l via clamav-users < clamav-users@lists.clamav.net> wrote: > Selinux is disabled. > > No problem with clamdscan when I run a scan. > > I performed further testing and noticed that: > > If I re

Re: [clamav-users] CLAMAD - Connecting to socket failed

2021-04-27 Thread Zami3l via clamav-users
Yes, I think so RAM 2Go and Swap 4Go There are only interesting things in the smb logs.Nothing special in those of clamd :( Thank you for answer. Best Regards, Zami3l April 27, 2021 3:56:21 PM CEST Eero Volotinen wrote: Is there enough memory on server? check out the clamd* logs. Eero On

Re: [clamav-users] CLAMAD - Connecting to socket failed

2021-04-27 Thread Eero Volotinen
Sorry to say, but 2G is too low memory for clamav. I think it crashes for out of memory reason. Upgrade server memory at least to 8G. Memory chips are so cheap.. Eero On Tue, Apr 27, 2021 at 5:38 PM Zami3l via clamav-users < clamav-users@lists.clamav.net> wrote: > Yes, I think so > RAM 2Go and

Re: [clamav-users] How to scan a single partition

2021-04-27 Thread G.W. Haywood via clamav-users
Hi there, On Mon, 26 Apr 2021, Christian wrote: ... Alas I couldn't gel hold of a ClamAV manual. Try typing "ClamAV manual" into any search engine. I'm not sure about the *syntax* though. Should I use / or /dev/sdc1 as a starting point: Unless you really know what you're doing, you will n

[clamav-users] automate clamav on windows and user manual popup

2021-04-27 Thread Michael Wang
Hello All: I would like to automate the clamav install on windows. The method I have in mind is to create a GPO which is a scheduled job written in powershell, and this job will install ClamAV, setup other jobs to download the database and do the scan. I could find info on the topic, so please sha

Re: [clamav-users] Samba vfs_virusfilter and clamd

2021-04-27 Thread G.W. Haywood via clamav-users
Hi there, On Tue, 27 Apr 2021, Matthias Leopold via clamav-users wrote: do I get it right that clamd has to run as root to work with vfs_virusfilter in Samba 4.13? I really thought I ran it as non-root the last time I tested it, but now I can't reproduce it and this confuses me. If you're sa

Re: [clamav-users] automate clamav on windows and user manual popup

2021-04-27 Thread G.W. Haywood via clamav-users
Hi there, On Tue, 27 Apr 2021, Michael Wang wrote: I would like to automate the clamav install on windows ... please share what you have done successfully automating on a large number of servers. Have you looked at things like 'Puppet'? Be aware that there's now more DOS protection for the

Re: [clamav-users] Odd behavior when scanning eicar test files

2021-04-27 Thread G.W. Haywood via clamav-users
Hi there, On Mon, 26 Apr 2021, Haukur Valgeirsson via clamav-users wrote: The only config I was able to locate is below. ... # cat /etc/clamav/freshclam.conf ... NotifyClamd /etc/clamav/clamd.conf This seems to be saying you have a clamd.conf, otherwise freshclam wouldn't be able to find it a