ClamWin Free Antivirus Forum Index
ClamWin Free Antivirus
Support and Discussion Forums
Reply to topic
Clamwin does not delete or quarntine filles
jsteele


Joined: 20 Mar 2007
Posts: 0
Location: Miami
Reply with quote
I have ClamWin running on a machine with Merak Mailserver. Clamwin is configured to scan the mail directory (.TMP files) every 30 minutes and it does indeed find infected files --- at least it finds phishing infections I haven't seen any other types of viruses yet.

However regardless of the setting (remove or quarantine) all it ever does is identify the infected file and leaves it in place. So I have to go in manually and find the infected files and manually delete them. Anyone know why it will not delete the files fo rme?

Thanks
View user's profileSend private message
alch
Site Admin

Joined: 27 Nov 2005
Posts: 0
Reply with quote
examine the scan reports and paste appropriate portion here.
View user's profileSend private message
Herewith ...
jsteele


Joined: 20 Mar 2007
Posts: 0
Location: Miami
Reply with quote
Scan Started Sat Jul 21 09:30:00 2007
-------------------------------------------------------------------------------

E:\Merak\mail\icci-as.com\jsteph\20070721071821524D.tmp: Email.Phishing.RB-1017 FOUND
E:\Merak\mail\icci-as.com\jsteph\20070721071821524D.tmp: Not deleting/moving mailbox
E:\Merak\mail\icci-as.com\jsteph\200707210913405421.tmp: Email.Phishing.RB-1137 FOUND
E:\Merak\mail\icci-as.com\jsteph\200707210913405421.tmp: Not deleting/moving mailbox
E:\Merak\mail\insyte.com\kitsune\200707210440504ED8.tmp: Email.Phishing.RB-1221 FOUND
E:\Merak\mail\insyte.com\kitsune\200707210440504ED8.tmp: Not deleting/moving mailbox
E:\Merak\mail\insyte.com\kitsune\20070721070902521C.tmp: Email.Phishing.RB-1221 FOUND
E:\Merak\mail\insyte.com\kitsune\20070721070902521C.tmp: Not deleting/moving mailbox
E:\Merak\mail\panam.org\www\200707210114504C99.tmp: Email.Phishing.RB-1222 FOUND
E:\Merak\mail\panam.org\www\200707210114504C99.tmp: Not deleting/moving mailbox

----------- SCAN SUMMARY -----------
Known viruses: 139531
Engine version: 0.90.2
Scanned directories: 117
Scanned files: 923
Skipped non-executable files: 0
Infected files: 5
Data scanned: 10.77 MB
Time: 50.875 sec (0 m 50 s)
View user's profileSend private message
alch
Site Admin

Joined: 27 Nov 2005
Posts: 0
Reply with quote
clamwin by design does not remove/quarantine rfc822 files in order to preserve Thudnerbird and other email client mailboxes. You might consider running clamscan.exe command line scanner without "--keep-mbox" parameter.
View user's profileSend private message
jsteele


Joined: 20 Mar 2007
Posts: 0
Location: Miami
Reply with quote
I tried creating a batch file to run clamscan:

"c:\program files\clamwin\bin\clamscan.exe" -d "c:\documents and settings\all usera\.clamwin\db\daily.inc" --recursive --remove

but when I run it I get this error:

LibClamAV Error: cl_loaddbdir(): Can't get status of c:\documents and settings\all usera\.clamwin\db\daily.inc
ERROR: Input/Output error

I am trying to run this at the base of the mailbox direcoties (hence --recursive) and from what I can tell from the obscure help information the database files are located where I have indicated.

PS, Why not just give clamwin an option to remove mailboxes?
View user's profileSend private message
jsteele


Joined: 20 Mar 2007
Posts: 0
Location: Miami
Reply with quote
"c:\program files\clamwin\bin\clamscan.exe" -d "c:\documents and settings\all usera\.clamwin\db\daily.inc" --recursive --remove
"c:\program files\clamwin\bin\clamscan.exe" -d "c:\documents and settings\all users\.clamwin\db\daily.inc" --recursive --remove

Fixed a typo and it now works.

Thanks
View user's profileSend private message
sherpya


Joined: 22 Mar 2006
Posts: 0
Location: Italy
Reply with quote
your are using only daily virus db you should pass the toplevel db directory
View user's profileSend private message
jsteele


Joined: 20 Mar 2007
Posts: 0
Location: Miami
Reply with quote
You mean like this?

"c:\program files\clamwin\bin\clamscan.exe" -d "c:\documents and settings\all users\.clamwin\db" --recursive --remove
View user's profileSend private message
sherpya


Joined: 22 Mar 2006
Posts: 0
Location: Italy
Reply with quote
yes
View user's profileSend private message
Clamwin does not delete or quarntine filles
You cannot post new topics in this forum
You cannot reply to topics in this forum
You cannot edit your posts in this forum
You cannot delete your posts in this forum
You cannot vote in polls in this forum
All times are GMT  
Page 1 of 1  

  
  
 Reply to topic