From: "Massimo S." Received: from [192.168.100.201] (HELO mail.2rosenthals.com) by 2rosenthals.com (CommuniGate Pro SMTP 5.4.10) with ESMTP id 11202327 for ecs-isp@2rosenthals.com; Fri, 01 Nov 2024 07:06:10 -0400 Received: from secmgr-va.2rosenthals.com ([50.73.8.217]:36583 helo=mail2.2rosenthals.com) by mail.2rosenthals.com with esmtps (TLS1.2) tls TLS_ECDHE_RSA_WITH_AES_256_GCM_SHA384 (Exim 4.97.1) (envelope-from ) id 1t6pTc-000000004Ik-1s5Q for ecs-isp@2rosenthals.com; Fri, 01 Nov 2024 07:06:01 -0400 Received: from mail2.quasarbbs.net ([80.86.52.115]:10057) by mail2.2rosenthals.com with esmtp (Exim 4.97.1) (envelope-from ) id 1t6pTY-000000005QU-1uNh for ecs-isp@2rosenthals.com; Fri, 01 Nov 2024 07:05:57 -0400 X-SASI-Hits: BODYTEXTP_SIZE_3000_LESS 0.000000, BODY_SIZE_2000_2999 0.000000, BODY_SIZE_5000_LESS 0.000000, BODY_SIZE_7000_LESS 0.000000, CTE_8BIT 0.000000, HTML_00_01 0.050000, HTML_00_10 0.050000, IN_REP_TO 0.000000, LEGITIMATE_SIGNS 0.000000, MSGID_SAMEAS_FROM_HEX_844412 0.100000, MSG_THREAD 0.000000, NO_CTA_URI_FOUND 0.000000, NO_URI_HTTPS 0.000000, REFERENCES 0.000000, REPLYTO_SAMEAS_FROM 0.000000, SENDER_NO_AUTH 0.000000, SUSP_DH_NEG 0.000000, TO_IN_SUBJECT 0.500000, USER_AGENT 0.000000, __ANY_URI 0.000000, __BEC_SUBJ_KEYWORD 0.000000, __BODY_NO_MAILTO 0.000000, __BOUNCE_CHALLENGE_SUBJ 0.000000, __BOUNCE_NDR_SUBJ_EXEMPT 0.000000, __CT 0.000000, __CTE 0.000000, __CT_TEXT_PLAIN 0.000000, __DQ_NEG_DOMAIN 0.000000, __DQ_NEG_HEUR 0.000000, __DQ_NEG_IP 0.000000, __FORWARDED_MSG 0.000000, __FRAUD_COMMON 0.000000, __FRAUD_PARTNERSHIP 0.000000, __FRAUD_REPLY 0.000000, __FROM_DOMAIN_NOT_IN_BODY 0.000000, __FROM_NAME_NOT_IN_ADDR 0.000000, __FROM_NAME_NOT_IN_BODY 0.000000, __FUR_HEADER 0.000000, __HAS_FROM 0.000000, __HAS_MSGID 0.000000, __HAS_REFERENCES 0.000000, __HAS_REPLYTO 0.000000, __HEADER_ORDER_FROM 0.000000, __IN_REP_TO 0.000000, __MAIL_CHAIN 0.000000, __MIME_BOUND_CHARSET 0.000000, __MIME_TEXT_ONLY 0.000000, __MIME_TEXT_P 0.000000, __MIME_TEXT_P1 0.000000, __MIME_VERSION 0.000000, __MOZILLA_USER_AGENT 0.000000, __MSGID_HEX_844412 0.000000, __NO_HTML_TAG_RAW 0.000000, __PHISH_SPEAR_SUBJ_ALERT 0.000000, __REFERENCES 0.000000, __REPLYTO_SAMEAS_FROM_ACC 0.000000, __REPLYTO_SAMEAS_FROM_ADDY 0.000000, __REPLYTO_SAMEAS_FROM_DOMAIN 0.000000, __SANE_MSGID 0.000000, __SCAN_D_NEG 0.000000, __SCAN_D_NEG2 0.000000, __SCAN_D_NEG_HEUR 0.000000, __SCAN_D_NEG_HEUR2 0.000000, __SUBJ_ALPHA_END 0.000000, __SUBJ_ALPHA_NEGATE 0.000000, __SUBJ_REPLY 0.000000, __TO_IN_SUBJECT 0.000000, __TO_MALFORMED_2 0.000000, __TO_NAME 0.000000, __TO_NAME_DIFF_FROM_ACC 0.000000, __TO_REAL_NAMES 0.000000, __URI_MAILTO 0.000000, __URI_NO_WWW 0.000000, __URI_NS 0.000000, __USER_AGENT 0.000000 X-SASI-Probability: 10% X-SASI-RCODE: 200 X-SASI-Version: Antispam-Engine: 5.1.4, AntispamData: 2024.11.1.94815 X-SASI-Hits: BODYTEXTP_SIZE_3000_LESS 0.000000, BODY_SIZE_2000_2999 0.000000, BODY_SIZE_5000_LESS 0.000000, BODY_SIZE_7000_LESS 0.000000, CTE_8BIT 0.000000, HTML_00_01 0.050000, HTML_00_10 0.050000, IN_REP_TO 0.000000, LEGITIMATE_SIGNS 0.000000, MSGID_SAMEAS_FROM_HEX_844412 0.100000, MSG_THREAD 0.000000, NO_CTA_URI_FOUND 0.000000, NO_URI_HTTPS 0.000000, REFERENCES 0.000000, REPLYTO_SAMEAS_FROM 0.000000, SUSP_DH_NEG 0.000000, TO_IN_SUBJECT 0.500000, USER_AGENT 0.000000, __ANY_URI 0.000000, __AUTH_RES_PASS 0.000000, __BEC_SUBJ_KEYWORD 0.000000, __BODY_NO_MAILTO 0.000000, __BOUNCE_CHALLENGE_SUBJ 0.000000, __BOUNCE_NDR_SUBJ_EXEMPT 0.000000, __CT 0.000000, __CTE 0.000000, __CT_TEXT_PLAIN 0.000000, __DQ_NEG_DOMAIN 0.000000, __DQ_NEG_HEUR 0.000000, __DQ_NEG_IP 0.000000, __FORWARDED_MSG 0.000000, __FRAUD_COMMON 0.000000, __FRAUD_PARTNERSHIP 0.000000, __FRAUD_REPLY 0.000000, __FROM_DOMAIN_NOT_IN_BODY 0.000000, __FROM_NAME_NOT_IN_ADDR 0.000000, __FROM_NAME_NOT_IN_BODY 0.000000, __FUR_HEADER 0.000000, __HAS_FROM 0.000000, __HAS_MSGID 0.000000, __HAS_REFERENCES 0.000000, __HAS_REPLYTO 0.000000, __HEADER_ORDER_FROM 0.000000, __IN_REP_TO 0.000000, __MAIL_CHAIN 0.000000, __MIME_BOUND_CHARSET 0.000000, __MIME_TEXT_ONLY 0.000000, __MIME_TEXT_P 0.000000, __MIME_TEXT_P1 0.000000, __MIME_VERSION 0.000000, __MOZILLA_USER_AGENT 0.000000, __MSGID_HEX_844412 0.000000, __NO_HTML_TAG_RAW 0.000000, __PHISH_SPEAR_SUBJ_ALERT 0.000000, __REFERENCES 0.000000, __REPLYTO_SAMEAS_FROM_ACC 0.000000, __REPLYTO_SAMEAS_FROM_ADDY 0.000000, __REPLYTO_SAMEAS_FROM_DOMAIN 0.000000, __SANE_MSGID 0.000000, __SCAN_D_NEG 0.000000, __SCAN_D_NEG2 0.000000, __SCAN_D_NEG_HEUR 0.000000, __SCAN_D_NEG_HEUR2 0.000000, __SUBJ_ALPHA_END 0.000000, __SUBJ_ALPHA_NEGATE 0.000000, __SUBJ_REPLY 0.000000, __TO_IN_SUBJECT 0.000000, __TO_MALFORMED_2 0.000000, __TO_NAME 0.000000, __TO_NAME_DIFF_FROM_ACC 0.000000, __TO_REAL_NAMES 0.000000, __URI_MAILTO 0.000000, __URI_NO_WWW 0.000000, __URI_NS 0.000000, __USER_AGENT 0.000000 X-SASI-Probability: 10% X-SASI-RCODE: 200 X-SASI-Version: Antispam-Engine: 5.1.4, AntispamData: 2024.11.1.94815 Received: from [192.168.10.199] (dtp [192.168.10.199]) by srv2 (Weasel v2.9-0001 ) for ; Fri, 01 Nov 2024 11:52:42 -0000 Reply-To: ml@ecomstation.it Subject: Re: [eCS-ISP] clamscan issue - directories with a lot of files To: eCS ISP Mailing List References: Organization: Massimo S. Message-ID: <6d4f3078-6bb2-2ae9-86d8-82c73d31ac76@ecomstation.it> Date: Fri, 1 Nov 2024 12:05:54 +0100 User-Agent: Mozilla/5.0 (OS/2; U; Warp 4.5; it-IT; rv:1.7.13) Gecko/20060424 Thunderbird/1.0.8 Mnenhy/0.7.4.0 MIME-Version: 1.0 In-Reply-To: Content-Type: text/plain; charset=iso-8859-15; format=flowed Content-Language: it-IT Content-Transfer-Encoding: 8bit Il 01/11/2024 10:56, Massimo S. ha scritto: > > > Il 30/10/2024 13:50, Massimo S. ha scritto: >> >> >> Il 03/08/2024 23:40, Steven Levine ha scritto: >>> In , on 07/30/24 >>>     at 10:33 AM, "Massimo S." said: >>> >>> Hi Massimo, >>> >>>>> unfortunately no >>>>> X:/weasel/MailRoot/mydomain.com/info/OA82H9.MSG: Can't read file ERROR >>>>> maybe it give this error when clamscan have to scan a big directory >>> >>>> clamscan still have the issue that show "Can't read file ERROR" in >>>> directories with a number of files >>> >>>> how can i help? >>> >>> This error message is generic in the sense that it can be generated at >>> several places in the code. >>> >>> The next time it happens, run clamscan and add the >>> >>>      --debug                              Enable libclamav's debug messages >>> >>> option to the command line.  The extra output might allow us to figure out >>> which specific read operation is failing. >>> >>> Steven >> >> >> Hi, >> >> damn, i just deleted a debug.txt output for mistake.. :-( >> >> anyway it was a 4GB file, i don't have it in the bkups, >> maybe ZIP is not able to add a so large file >> >> i will try to generate it again >> >> and i guess that the issue of "Can't read file ERROR" >> is not related to a directory with a lot of files inside >> since it appears allmost the times in "big dirs", but >> it may happens that clamscan keep on working again in the same dir >> e.g. in this case: >> >> X:/weasel/MailRoot/mydomain.com/myemail/OLAYI6.MSG: Can't read file ERROR >> X:/weasel/MailRoot/mydomain.com/myemail/OLAZFS.MSG: Can't read file ERROR >> X:/weasel/MailRoot/mydomain.com/myemail/OLB25S.MSG: Can't read file ERROR >> X:/weasel/MailRoot/mydomain.com/myemail/OLB3TA.MSG: Can't read file ERROR >> X:/weasel/MailRoot/mydomain.com/myemail/OLB5K9.MSG: Can't read file ERROR >> X:/weasel/MailRoot/mydomain.com/myemail/ORWBT5.MSG: Heuristics.Phishing.Email.SpoofedDomain FOUND >> X:/weasel/MailRoot/mydomain.com/myemail/ORWBT5.MSG: moved to 'X:/quarantine/ORWBT5.MSG' >> X:/weasel/MailRoot/mydomain.com/myemail/OS0VTD.MSG: Sanesecurity.Phishing.Fake.Coin.29146.UNOFFICIAL FOUND >> X:/weasel/MailRoot/mydomain.com/myemail/OS0VTD.MSG: moved to 'X:/quarantine/OS0VTD.MSG' >> >> massimo > > i'm able to reproduce the debug output > uncompressed it's 5,6GB..  doh  :-) > compressed is 2,6GB > > i can put it on an ftp > let me know > > thanks > > massimo when it show the errors i see a lot of these in the output on the screen: LibClamAV Error: fmap_readpage: pread error: Not enough memory the VM has 4GB ram assigned (i know /2 see only about 3,3GB) and vaddresslimit is 3072 massimo