Welcome, Guest
Please Login or Register.
Lost Password?
Re:Getting rid of clamav (1 viewing)
Post Reply

TOPIC: Re:Getting rid of clamav

#17255
lance (User)
Posts: 3
graphgraph
Getting rid of clamav 2008/10/27 04:52  
Clamav is causing a lot of issues. None of my clients run Windows so its use is debatable. The only reason I haven't gotten rid of it yet is because I'm not quite sure how, it looks like apt-get remove will break the mail wrappers.

Any tips for what I should do so I don't run into a mail-breaking gotcha?
  The administrator has disabled public write access.
#17256
andreychek (Moderator)
Posts: 860
graphgraph
Re:Getting rid of clamav 2008/10/27 05:15  
Well, first off, some of those issues may be fixable.

However, if you're really interested in getting rid of it, rather than deleting it altogether, I might first just get your system to stop using it.

If you log into Virtualmin, and go into Server Settings -> Features and Plugins, you can disable Virus Scanning from in there.

Once you've disabled it, you can stop the clamav service.
-Eric
  The administrator has disabled public write access.
#17286
Joe (Admin)
Posts: 4213
graph
Re:Getting rid of clamav 2008/10/27 18:15  
Even if your users don't use exploitable systems (good for them!), I'm sure they still don't want to receive a bunch of messages that are just viruses. It's like spam, only without trying to sell something (although sometimes virus emails double up their functionality and contain both a virus and a spam payload: woohoo, bonus!).

Just a thought. Me and Eric and Jamie are not worried about viruses on our own machines...but we don't want to receive those emails, either. So we've got ClamAV running on Virtualmin.com killing those messages on arrival.

And, as Eric mentioned, whatever issues you have can be fixed. We get tons of mail, and we aren't seeing any problems. You probably just need to switch to the clamdscan processing mode rather than clamscan.
  The administrator has disabled public write access.
#17478
lance (User)
Posts: 3
graphgraph
Re:Getting rid of clamav 2008/11/04 14:07  
Thanks for the tips.

I've already done enough yak shaving and I'm not really inclined to spend any more time given the extremely low volume of email I get.

The main issue is it takes 1 hour 20 minutes for the clamd socket to come up. This is on a 2.0ghz machine with 512mb of ram and an average load of 1.0. If I get any mail during that time, it spawns a clamscan thread at normal priority, and the cron reports alone will bring the load factor up to 200. (My workaround was to kill postfix on boot, wait for the socket, then start postfix again. This was till I found out about the socket issue being fixed in 0.90.3.)

This was because the version of clamd that comes with debian stable is 0.90.1. I selectively upgraded to the testing repo which has 0.94. Now the socket comes up instantly but it still takes 1 hour 20 minutes to read through the signatures db. Freshclam updates roughly every hour, which means that I'm almost always reloading the signatures database.

Also, when I updated packages from virtualmin, I run into this: It thinks 0.90.1 is installed, and apt says that 0.94 is available, so it offers to upgrade me. If it updates it instead install -forces the package available from the default repository (stable) which is 0.90.1.
  The administrator has disabled public write access.
Post Reply
get the latest posts directly to your desktop

Talk and Get Help

Support
Forums
Bugs and Issues

Get Virtualmin

OS Support
Buy Online
Download
Copyright 2005-2007 Virtualmin, Inc. All rights reserved.