<?xml version="1.0"?>
<feed xmlns="http://www.w3.org/2005/Atom" xml:lang="en">
	<id>http://wiki.qmailtoaster.org:80/index.php?action=history&amp;feed=atom&amp;title=Clamav</id>
	<title>Clamav - Revision history</title>
	<link rel="self" type="application/atom+xml" href="http://wiki.qmailtoaster.org:80/index.php?action=history&amp;feed=atom&amp;title=Clamav"/>
	<link rel="alternate" type="text/html" href="http://wiki.qmailtoaster.org:80/index.php?title=Clamav&amp;action=history"/>
	<updated>2026-04-29T12:39:21Z</updated>
	<subtitle>Revision history for this page on the wiki</subtitle>
	<generator>MediaWiki 1.41.0</generator>
	<entry>
		<id>http://wiki.qmailtoaster.org:80/index.php?title=Clamav&amp;diff=1413&amp;oldid=prev</id>
		<title>Ebroch at 18:54, 19 October 2024</title>
		<link rel="alternate" type="text/html" href="http://wiki.qmailtoaster.org:80/index.php?title=Clamav&amp;diff=1413&amp;oldid=prev"/>
		<updated>2024-10-19T18:54:06Z</updated>

		<summary type="html">&lt;p&gt;&lt;/p&gt;
&lt;table style=&quot;background-color: #fff; color: #202122;&quot; data-mw=&quot;interface&quot;&gt;
				&lt;col class=&quot;diff-marker&quot; /&gt;
				&lt;col class=&quot;diff-content&quot; /&gt;
				&lt;col class=&quot;diff-marker&quot; /&gt;
				&lt;col class=&quot;diff-content&quot; /&gt;
				&lt;tr class=&quot;diff-title&quot; lang=&quot;en&quot;&gt;
				&lt;td colspan=&quot;2&quot; style=&quot;background-color: #fff; color: #202122; text-align: center;&quot;&gt;← Older revision&lt;/td&gt;
				&lt;td colspan=&quot;2&quot; style=&quot;background-color: #fff; color: #202122; text-align: center;&quot;&gt;Revision as of 12:54, 19 October 2024&lt;/td&gt;
				&lt;/tr&gt;&lt;tr&gt;&lt;td colspan=&quot;2&quot; class=&quot;diff-lineno&quot; id=&quot;mw-diff-left-l1&quot;&gt;Line 1:&lt;/td&gt;
&lt;td colspan=&quot;2&quot; class=&quot;diff-lineno&quot;&gt;Line 1:&lt;/td&gt;&lt;/tr&gt;
&lt;tr&gt;&lt;td class=&quot;diff-marker&quot; data-marker=&quot;−&quot;&gt;&lt;/td&gt;&lt;td style=&quot;color: #202122; font-size: 88%; border-style: solid; border-width: 1px 1px 1px 4px; border-radius: 0.33em; border-color: #ffe49c; vertical-align: top; white-space: pre-wrap;&quot;&gt;&lt;div&gt;[[Configuration#&lt;del style=&quot;font-weight: bold; text-decoration: none;&quot;&gt;clamav&lt;/del&gt;|Back]]&amp;lt;br&amp;gt;&lt;/div&gt;&lt;/td&gt;&lt;td class=&quot;diff-marker&quot; data-marker=&quot;+&quot;&gt;&lt;/td&gt;&lt;td style=&quot;color: #202122; font-size: 88%; border-style: solid; border-width: 1px 1px 1px 4px; border-radius: 0.33em; border-color: #a3d3ff; vertical-align: top; white-space: pre-wrap;&quot;&gt;&lt;div&gt;[[Configuration#&lt;ins style=&quot;font-weight: bold; text-decoration: none;&quot;&gt;Clamav&lt;/ins&gt;|Back]]&amp;lt;br&amp;gt;&lt;/div&gt;&lt;/td&gt;&lt;/tr&gt;
&lt;tr&gt;&lt;td class=&quot;diff-marker&quot;&gt;&lt;/td&gt;&lt;td style=&quot;background-color: #f8f9fa; color: #202122; font-size: 88%; border-style: solid; border-width: 1px 1px 1px 4px; border-radius: 0.33em; border-color: #eaecf0; vertical-align: top; white-space: pre-wrap;&quot;&gt;&lt;div&gt;== About ClamAV ==&lt;/div&gt;&lt;/td&gt;&lt;td class=&quot;diff-marker&quot;&gt;&lt;/td&gt;&lt;td style=&quot;background-color: #f8f9fa; color: #202122; font-size: 88%; border-style: solid; border-width: 1px 1px 1px 4px; border-radius: 0.33em; border-color: #eaecf0; vertical-align: top; white-space: pre-wrap;&quot;&gt;&lt;div&gt;== About ClamAV ==&lt;/div&gt;&lt;/td&gt;&lt;/tr&gt;
&lt;tr&gt;&lt;td class=&quot;diff-marker&quot;&gt;&lt;/td&gt;&lt;td style=&quot;background-color: #f8f9fa; color: #202122; font-size: 88%; border-style: solid; border-width: 1px 1px 1px 4px; border-radius: 0.33em; border-color: #eaecf0; vertical-align: top; white-space: pre-wrap;&quot;&gt;&lt;br&gt;&lt;/td&gt;&lt;td class=&quot;diff-marker&quot;&gt;&lt;/td&gt;&lt;td style=&quot;background-color: #f8f9fa; color: #202122; font-size: 88%; border-style: solid; border-width: 1px 1px 1px 4px; border-radius: 0.33em; border-color: #eaecf0; vertical-align: top; white-space: pre-wrap;&quot;&gt;&lt;br&gt;&lt;/td&gt;&lt;/tr&gt;
&lt;/table&gt;</summary>
		<author><name>Ebroch</name></author>
	</entry>
	<entry>
		<id>http://wiki.qmailtoaster.org:80/index.php?title=Clamav&amp;diff=1338&amp;oldid=prev</id>
		<title>Ebroch at 16:09, 19 October 2024</title>
		<link rel="alternate" type="text/html" href="http://wiki.qmailtoaster.org:80/index.php?title=Clamav&amp;diff=1338&amp;oldid=prev"/>
		<updated>2024-10-19T16:09:55Z</updated>

		<summary type="html">&lt;p&gt;&lt;/p&gt;
&lt;table style=&quot;background-color: #fff; color: #202122;&quot; data-mw=&quot;interface&quot;&gt;
				&lt;col class=&quot;diff-marker&quot; /&gt;
				&lt;col class=&quot;diff-content&quot; /&gt;
				&lt;col class=&quot;diff-marker&quot; /&gt;
				&lt;col class=&quot;diff-content&quot; /&gt;
				&lt;tr class=&quot;diff-title&quot; lang=&quot;en&quot;&gt;
				&lt;td colspan=&quot;2&quot; style=&quot;background-color: #fff; color: #202122; text-align: center;&quot;&gt;← Older revision&lt;/td&gt;
				&lt;td colspan=&quot;2&quot; style=&quot;background-color: #fff; color: #202122; text-align: center;&quot;&gt;Revision as of 10:09, 19 October 2024&lt;/td&gt;
				&lt;/tr&gt;&lt;tr&gt;&lt;td colspan=&quot;2&quot; class=&quot;diff-lineno&quot; id=&quot;mw-diff-left-l1&quot;&gt;Line 1:&lt;/td&gt;
&lt;td colspan=&quot;2&quot; class=&quot;diff-lineno&quot;&gt;Line 1:&lt;/td&gt;&lt;/tr&gt;
&lt;tr&gt;&lt;td colspan=&quot;2&quot; class=&quot;diff-side-deleted&quot;&gt;&lt;/td&gt;&lt;td class=&quot;diff-marker&quot; data-marker=&quot;+&quot;&gt;&lt;/td&gt;&lt;td style=&quot;color: #202122; font-size: 88%; border-style: solid; border-width: 1px 1px 1px 4px; border-radius: 0.33em; border-color: #a3d3ff; vertical-align: top; white-space: pre-wrap;&quot;&gt;&lt;div&gt;&lt;ins style=&quot;font-weight: bold; text-decoration: none;&quot;&gt;[[Configuration#clamav|Back]]&amp;lt;br&amp;gt;&lt;/ins&gt;&lt;/div&gt;&lt;/td&gt;&lt;/tr&gt;
&lt;tr&gt;&lt;td class=&quot;diff-marker&quot;&gt;&lt;/td&gt;&lt;td style=&quot;background-color: #f8f9fa; color: #202122; font-size: 88%; border-style: solid; border-width: 1px 1px 1px 4px; border-radius: 0.33em; border-color: #eaecf0; vertical-align: top; white-space: pre-wrap;&quot;&gt;&lt;div&gt;== About ClamAV ==&lt;/div&gt;&lt;/td&gt;&lt;td class=&quot;diff-marker&quot;&gt;&lt;/td&gt;&lt;td style=&quot;background-color: #f8f9fa; color: #202122; font-size: 88%; border-style: solid; border-width: 1px 1px 1px 4px; border-radius: 0.33em; border-color: #eaecf0; vertical-align: top; white-space: pre-wrap;&quot;&gt;&lt;div&gt;== About ClamAV ==&lt;/div&gt;&lt;/td&gt;&lt;/tr&gt;
&lt;tr&gt;&lt;td class=&quot;diff-marker&quot;&gt;&lt;/td&gt;&lt;td style=&quot;background-color: #f8f9fa; color: #202122; font-size: 88%; border-style: solid; border-width: 1px 1px 1px 4px; border-radius: 0.33em; border-color: #eaecf0; vertical-align: top; white-space: pre-wrap;&quot;&gt;&lt;br&gt;&lt;/td&gt;&lt;td class=&quot;diff-marker&quot;&gt;&lt;/td&gt;&lt;td style=&quot;background-color: #f8f9fa; color: #202122; font-size: 88%; border-style: solid; border-width: 1px 1px 1px 4px; border-radius: 0.33em; border-color: #eaecf0; vertical-align: top; white-space: pre-wrap;&quot;&gt;&lt;br&gt;&lt;/td&gt;&lt;/tr&gt;
&lt;/table&gt;</summary>
		<author><name>Ebroch</name></author>
	</entry>
	<entry>
		<id>http://wiki.qmailtoaster.org:80/index.php?title=Clamav&amp;diff=115&amp;oldid=prev</id>
		<title>Ebroch: Created page with &quot;== About ClamAV ==  From: [http://www.clamav.net Clamav.net]  ClamAV is an open source (GPL) antivirus engine designed for detecting Trojans, viruses, malware and other malicious threats. It is the de facto standard for mail gateway scanning. It provides a high performance mutli-threaded scanning daemon, command line utilities for on demand file scanning, and an intelligent tool for automatic signature updates. The core ClamAV library provides numerous file format detect...&quot;</title>
		<link rel="alternate" type="text/html" href="http://wiki.qmailtoaster.org:80/index.php?title=Clamav&amp;diff=115&amp;oldid=prev"/>
		<updated>2024-03-16T16:10:26Z</updated>

		<summary type="html">&lt;p&gt;Created page with &amp;quot;== About ClamAV ==  From: [http://www.clamav.net Clamav.net]  ClamAV is an open source (GPL) antivirus engine designed for detecting Trojans, viruses, malware and other malicious threats. It is the de facto standard for mail gateway scanning. It provides a high performance mutli-threaded scanning daemon, command line utilities for on demand file scanning, and an intelligent tool for automatic signature updates. The core ClamAV library provides numerous file format detect...&amp;quot;&lt;/p&gt;
&lt;p&gt;&lt;b&gt;New page&lt;/b&gt;&lt;/p&gt;&lt;div&gt;== About ClamAV ==&lt;br /&gt;
&lt;br /&gt;
From: [http://www.clamav.net Clamav.net]&lt;br /&gt;
&lt;br /&gt;
ClamAV is an open source (GPL) antivirus engine designed for detecting Trojans, viruses, malware and other malicious threats. It is the de facto standard for mail gateway scanning. It provides a high performance mutli-threaded scanning daemon, command line utilities for on demand file scanning, and an intelligent tool for automatic signature updates. The core ClamAV library provides numerous file format detection mechanisms, file unpacking support, archive support, and multiple signature languages for detecting threats. The core ClamAV library is utilized in Immunet 3.0, powered by ClamAV, which is a fast, fully featured Desktop AV solution for Windows. &lt;br /&gt;
&lt;br /&gt;
In Qmailtoaster, ClamAV works side-by-side with SpamAssassin under Simscan to make sure all incoming email is free of virus and spam.&lt;br /&gt;
&lt;br /&gt;
== Disable / Enable ==&lt;br /&gt;
&lt;br /&gt;
You can disable (and enable it again) ClamAV per domain or server-wide, make sure you know what you are doing and have a strong reason.&lt;br /&gt;
&lt;br /&gt;
=== Per Domain ===&lt;br /&gt;
&lt;br /&gt;
If you have multiple domains, and you want to disable ClamAV feature just for 1 domain you can do it like this:&lt;br /&gt;
&lt;br /&gt;
1. Edit file /var/qmail/control/simcontrol&lt;br /&gt;
   vi /var/qmail/control/simcontrol&lt;br /&gt;
2. Look for line that contains domain you want to disable ClamAV (something like this):&lt;br /&gt;
   pala.bo-tak.info:clam=yes,spam=yes,spam_hits=11.5,attach=.bat:.chm:.cmd:.com:.dll:.dot:.email:.exe:.hlp:.hta:.inf:.msi:.pif:.reg:.scr:.url:.vbs&lt;br /&gt;
3. Change clam=yes into clam=no, so the line look like this:&lt;br /&gt;
   pala.bo-tak.info:clam=yes,spam=yes,spam_hits=11.5,attach=.bat:.chm:.cmd:.com:.dll:.dot:.email:.exe:.hlp:.hta:.inf:.msi:.pif:.reg:.scr:.url:.vbs&lt;br /&gt;
4. Save the file and quit &lt;br /&gt;
&lt;br /&gt;
5. Compile simcontrol file to make rule active&lt;br /&gt;
   service qmail cdb&lt;br /&gt;
&lt;br /&gt;
To enable ClamAV feature again just follow the steps above but on step 3 change clam=no into clam=yes&lt;br /&gt;
&lt;br /&gt;
=== Server Wide===&lt;br /&gt;
==== Temporary ====&lt;br /&gt;
If you want to stop clamav service temporarily (for whatever reason) here&amp;#039;s how:&lt;br /&gt;
NOTE: clamav service will not be available until you start it manually or server restarted.&lt;br /&gt;
&lt;br /&gt;
If you have [http://qtp.qmailtoaster.com/ QmailToaster Plus tool] installed:&lt;br /&gt;
&lt;br /&gt;
1. Stop clamd&lt;br /&gt;
   qmail-clam stop&lt;br /&gt;
2. Check clamd status&lt;br /&gt;
   qmail-clam stat&lt;br /&gt;
3. Start clamd&lt;br /&gt;
   qmail-clam start&lt;br /&gt;
&lt;br /&gt;
If you do not have QmailToaster Plus installed:&lt;br /&gt;
&lt;br /&gt;
1. Stop clamd&lt;br /&gt;
   svc -d /var/qmail/supervise/clamd /var/qmail/supervise/clamd/log&lt;br /&gt;
2. Check clamd status&lt;br /&gt;
   svstat /var/qmail/supervise/clamd&lt;br /&gt;
   svstat /var/qmail/supervise/clamd/log&lt;br /&gt;
3. Start clamd&lt;br /&gt;
   svc -u /var/qmail/supervise/clamd /var/qmail/supervise/clamd/log&lt;br /&gt;
&lt;br /&gt;
==== Forever ====&lt;br /&gt;
If you have another Email-Scanning-Proxy device before your qmailtoaster box you may want to disable ClamAV scanning to save memory. Here&amp;#039;s how:&lt;br /&gt;
&lt;br /&gt;
1. Touch down file on clamav service.&lt;br /&gt;
   touch /var/qmail/supervise/clamd/down&lt;br /&gt;
   touch /var/qmail/supervise/clamd/log/down&lt;br /&gt;
2. Stop qmail.&lt;br /&gt;
   service qmail stop&lt;br /&gt;
3. Stop existing freshclam process.&lt;br /&gt;
   service freshclam stop&lt;br /&gt;
4. Remove freshclam from running automatically when server starts. &lt;br /&gt;
   chkconfig freshclam off&lt;br /&gt;
5. Make sure all qmail service has stopped, if not kill the running PID.&lt;br /&gt;
   service qmail stat&lt;br /&gt;
6. Start qmail service again.&lt;br /&gt;
   service qmail start&lt;br /&gt;
&lt;br /&gt;
== Update ==&lt;br /&gt;
=== Definition update ===&lt;br /&gt;
&lt;br /&gt;
By default if freshclam service is running it will update clamav definition automatically. But if you want to make sure you have the latest definition you can run this command:&lt;br /&gt;
 freshclam&lt;br /&gt;
 ClamAV update process started at Wed Mar 23 11:41:16 2011&lt;br /&gt;
 main.cvd is up to date (version: 53, sigs: 846214, f-level: 53, builder: sven)&lt;br /&gt;
 Downloading daily-12882.cdiff [100%]&lt;br /&gt;
 Downloading daily-12883.cdiff [100%]&lt;br /&gt;
 daily.cld updated (version: 12883, sigs: 76664, f-level: 60, builder: ccordes)&lt;br /&gt;
 bytecode.cld is up to date (version: 142, sigs: 40, f-level: 60, builder: acab)&lt;br /&gt;
 Database updated (922918 signatures) from db.id.clamav.net (IP: 62.75.137.14)&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
=== Engine update ===&lt;br /&gt;
&lt;br /&gt;
ClamAV team will release new version periodically. If they release new version, QMT team will release new clamav-toaster as soon as possible. Here&amp;#039;s how to update your clamav engine version:&lt;br /&gt;
&lt;br /&gt;
If you have [http://qtp.qmailtoaster.com QmailToaster Plus] tool installed you can run [http://qtp.qmailtoaster.comtrac/wiki/qtp-newmodel qtp-newmodel] but this tool not just only updating your clamav engine but also other *-toaster packages if new version available.&lt;br /&gt;
&lt;br /&gt;
 qtp-newmodel&lt;br /&gt;
&lt;br /&gt;
If you do not have QmailToaster Plus or you only want to update clamav version only, do these steps:&lt;br /&gt;
&lt;br /&gt;
1. Stop qmail service&lt;br /&gt;
   service qmail stop&lt;br /&gt;
2. Remove existing clamav package&lt;br /&gt;
   rpm -e --nodeps clamav-toaster&lt;br /&gt;
3. Download new clamav-toaster source package from [http://mirrors.qmailtoaster.net/ Qmailtoaster Mirros]&lt;br /&gt;
   wget http://mirrors.qmailtoaster.net/clamav-toaster-0.97.0-1.3.41.src.rpm&lt;br /&gt;
4. Rebuild new clamav-toaster source package, replace $DISTRO with your OS Name and version. Detail $DISTRO can be see at install-script on [http://www.qmailtoaster.net/distro/ Qmailtoaster Distro]&lt;br /&gt;
   rpmbuild --rebuild --with $DISTRO clamav-toaster-newpkg.src.rpm&lt;br /&gt;
   rpmbuild --rebuild --with $cnt4064 clamav-toaster-newpkg.src.rpm&lt;br /&gt;
5. Install clamav-toaster binary RPM&lt;br /&gt;
   rpm -Uvh clamav-toaster-new.rpm&lt;br /&gt;
   rpm -Uvh /usr/src/redhat/RPMS/x86_64/clamav-toaster-0.97.0-1.3.41.x86_64.rpm&lt;br /&gt;
6. Compile qmail cdb and start.&lt;br /&gt;
   service qmail cdb&lt;br /&gt;
   service qmail start&lt;br /&gt;
&lt;br /&gt;
== Additional definition ==&lt;br /&gt;
&lt;br /&gt;
There are additional clamav definitions to help your server minimize incoming spam. Those definitions are provided by:&lt;br /&gt;
* [http://www.sanesecurity.com/clamav/index.htm SaneSecurity]&lt;br /&gt;
* [http://msrbl.com/ MSRBL]&lt;br /&gt;
* [http://www.securiteinfo.com/services/clamav_unofficial_malwares_signatures.shtml SecuriteInfo]&lt;br /&gt;
* [http://malwarepatrol.com.br/ MalwarePatrol]&lt;br /&gt;
* [http://www.oitc.com/winnow/clamsigs/index.html OITC]&lt;br /&gt;
* [http://www.inetmsg.com/pub/ InetMsg]&lt;br /&gt;
&lt;br /&gt;
The easiest way to install additional clamav definitions is by invoking command&lt;br /&gt;
&lt;br /&gt;
 qtp-install-sanesecurity&lt;br /&gt;
&lt;br /&gt;
if you have installed [http://qtp.qmailtoaster.com/ QmailToaster Plus]. Details about qtp-install-sanesecurity can be found at [http://qtp.qmailtoaster.com/trac/wiki/Features#qtp-install-sanesecurity QTP site]&lt;br /&gt;
&lt;br /&gt;
If you do not have QmailToaster Plus, consult directly to each definition providers.&lt;br /&gt;
&lt;br /&gt;
== Log Monitoring ==&lt;br /&gt;
If you have [http://qtp.qmailtoaster.com/ QmailToaster Plus] you can run:&lt;br /&gt;
Check with [http://qtp.qmailtoaster.com/trac/wiki/Features#qmlog qmlog manual] for other options:&lt;br /&gt;
 qmlog -f clamd&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
If you do not have QTP then you can run:&lt;br /&gt;
 tail -f /var/log/qmail/clamd/current | tai64nlocal&lt;br /&gt;
 grep pdf /var/log/qmail/clamd/current | tai64nlocal | more&lt;br /&gt;
 grep -v OK /var/log/qmail/clamd/current | tai64nlocal | more&lt;/div&gt;</summary>
		<author><name>Ebroch</name></author>
	</entry>
</feed>