@Stefano
No, la scansione del file system è sempre stata disattivata.
In etc/cron.d ho:
purge_junkmail
smolt
warnquota
ma direi che partono tutti la notte
mentre in etc/cron.daily ho questo:
Log of ls
Wed May 12 09:00:56 2010
00-makewhatis.cron
00-sa_keys
0anacron
check_pass.cron
conf-mod_ssl
freshclam
logrotate
prelink
rkhunter
rpm
sa_update
slocate.cron
smeserver-yum
tmpwatch
tmpwatch-formmagick
yum.cron
zz-sa_restart
Wed May 12 09:00:56 2010
----------------
clam è disattivato da web panel, però, se digito config show clamav:
Log of config show clamav
Wed May 12 09:04:14 2010
clamav=service
ArchiveBlockEncrypted=no
ArchiveBlockMax=no
ArchiveMaxCompressionRatio=300
Checks=24
DNSDatabaseInfo=current.cvd.clamav.net
DatabaseMirror=db.local.clamav.net
Debug=no
DetectBrokenExecutables=no
FilesystemScan=disabled
FilesystemScanExclude=/proc,/sys,/usr/share,/var
FilesystemScanFilesystems=/home/e-smith/files
FilesystemScanReportTo=admin
Foreground=yes
HTTPProxyPassword=
HTTPProxyPort=
HTTPProxyServer=
HTTPProxyUsername=
HeuristicScanPrecedence=no
IdleTimeout=60
LeaveTemporaryFiles=no
LogClean=no
LogFileUnlock=yes
LogTime=no
LogVerbose=yes
MaxAttempts=6
MaxConnectionQueueLength=30
MaxDirectoryRecursion=20
MaxFileSize=15M
MaxFiles=1500
MaxRecursion=8
MaxThreads=20
Quarantine=enabled
QuarantineDirectory=/var/spool/clamav/quarantine
ReadTimeout=300
ScanArchive=yes
ScanHTML=yes
ScanMail=yes
ScanOLE2=yes
ScanPE=yes
ScanRAR=no
SelfCheck=1800
ShowProxySettings=no
ShowUpdateSettings=no
SignaturesUpdated=unknown
UpdateNonOfficeHrs=disabled
UpdateOfficeHrs=disabled
UpdateWeekend=disabled
status=enabled
Wed May 12 09:04:15 2010
----------------
mi dice "status=enabled"
ho lanciato anche clamconf
Log of clamconf
Wed May 12 09:06:55 2010
Checking configuration files in /etc
Config file: clamd.conf
-----------------------
LogFile disabled
LogFileUnlock disabled
LogFileMaxSize = "1048576"
LogTime disabled
LogClean disabled
LogSyslog disabled
LogFacility = "LOG_LOCAL6"
LogVerbose = "yes"
PidFile disabled
TemporaryDirectory = "/var/tmp"
DatabaseDirectory = "/var/clamav"
OfficialDatabaseOnly disabled
LocalSocket = "/var/clamav/clamd.socket"
LocalSocketGroup disabled
LocalSocketMode disabled
FixStaleSocket = "yes"
TCPSocket disabled
TCPAddr disabled
MaxConnectionQueueLength = "30"
StreamMaxLength = "26214400"
StreamMinPort = "1024"
StreamMaxPort = "2048"
MaxThreads = "20"
ReadTimeout = "300"
CommandReadTimeout = "5"
SendBufTimeout = "500"
MaxQueue = "100"
IdleTimeout = "60"
ExcludePath disabled
MaxDirectoryRecursion = "20"
FollowDirectorySymlinks disabled
FollowFileSymlinks disabled
CrossFilesystems = "yes"
SelfCheck = "1800"
VirusEvent disabled
ExitOnOOM disabled
Foreground = "yes"
Debug disabled
LeaveTemporaryFiles disabled
User = "clamav"
AllowSupplementaryGroups = "yes"
Bytecode = "yes"
BytecodeSecurity = "TrustSigned"
BytecodeTimeout = "60000"
DetectPUA disabled
ExcludePUA disabled
IncludePUA disabled
AlgorithmicDetection = "yes"
ScanPE = "yes"
ScanELF = "yes"
DetectBrokenExecutables disabled
ScanMail = "yes"
ScanPartialMessages disabled
PhishingSignatures = "yes"
PhishingScanURLs = "yes"
PhishingAlwaysBlockCloak disabled
PhishingAlwaysBlockSSLMismatch disabled
HeuristicScanPrecedence disabled
StructuredDataDetection disabled
StructuredMinCreditCardCount = "3"
StructuredMinSSNCount = "3"
StructuredSSNFormatNormal = "yes"
StructuredSSNFormatStripped disabled
ScanHTML = "yes"
ScanOLE2 = "yes"
ScanPDF = "yes"
ScanArchive = "yes"
ArchiveBlockEncrypted disabled
MaxScanSize = "104857600"
MaxFileSize = "15728640"
MaxRecursion = "8"
MaxFiles = "1500"
ClamukoScanOnAccess disabled
ClamukoScannerCount = "3"
ClamukoScanOnOpen disabled
ClamukoScanOnClose disabled
ClamukoScanOnExec disabled
ClamukoIncludePath disabled
ClamukoExcludePath disabled
ClamukoMaxFileSize = "5242880"
DevACOnly disabled
DevACDepth disabled
Config file: freshclam.conf
---------------------------
LogFileMaxSize = "1048576"
LogTime disabled
LogSyslog disabled
LogFacility = "LOG_LOCAL6"
LogVerbose = "yes"
PidFile disabled
DatabaseDirectory = "/var/clamav"
Foreground = "yes"
Debug disabled
AllowSupplementaryGroups disabled
UpdateLogFile disabled
DatabaseOwner = "clamav"
Checks = "24"
DNSDatabaseInfo = "current.cvd.clamav.net"
DatabaseMirror = "db.local.clamav.net", "database.clamav.net"
MaxAttempts = "6"
ScriptedUpdates = "yes"
CompressLocalDatabase disabled
ExtraDatabase disabled
HTTPProxyServer disabled
HTTPProxyPort disabled
HTTPProxyUsername disabled
HTTPProxyPassword disabled
HTTPUserAgent disabled
NotifyClamd = "/etc/clamd.conf"
OnUpdateExecute = "/sbin/e-smith/freshclam-update-ok"
OnErrorExecute = "/sbin/e-smith/freshclam-update-failed"
OnOutdatedExecute disabled
LocalIPAddress disabled
ConnectTimeout = "30"
ReceiveTimeout = "30"
SubmitDetectionStats disabled
DetectionStatsCountry disabled
DetectionStatsHostID disabled
SafeBrowsing disabled
Bytecode = "yes"
clamav-milter.conf not found
Software settings
-----------------
Version: 0.96
Optional features supported: MEMPOOL CLAMUKO AUTOIT_EA06 BZIP2 RAR
Database directory: /var/clamav
main.cvd: version 52, sigs: 704727, built on Mon Feb 15 15:54:51 2010
main.cld: version 52, sigs: 704727, built on Mon Feb 15 15:54:51 2010
daily.cld: version 10983, sigs: 67461, built on Wed May 12 05:40:15 2010
Wed May 12 09:06:55 2010
----------------
La macchina è un celeron 2000, 512MB di ram e un paio di hard disk pata da 80gb.
Ho provato a cercare in giro qualcosa su cron, ho anche installato il contrib relativo, però pare tutto regolare.
Quindi suppongo che le cause siano da ricercare all'interno della configurazione di clam.
Mi metto alla ricerca di qualcosa

grazie di nuovo