Org.clamav.freshclam and permissions error on freshclam.log

This is an adjunct to a branched discussion in this thread regarding org.clamav.freshclam continually generating error reports in the system log.
After enabling, but not starting, Mail service on my server (XServe Dual-G5, 10.5.8 Server) my system log began filling with the error as per the referenced thread. The first entry when the error cropped up was:
Nov 5 15:23:20 xserve1 com.apple.launchd[1] (org.clamav.freshclam): Unknown key for integer: Iterations
Nov 5 15:23:20 xserve1 org.clamav.freshclam[40472]: ERROR: Incorrect argument format for option --checks (-c)
Nov 5 15:23:20 xserve1 org.clamav.freshclam[40472]: ERROR: Can't parse command line options
Nov 5 15:23:20 xserve1 com.apple.launchd[1] (org.clamav.freshclam[40472]): Exited with exit code: 1
Nov 5 15:23:20 xserve1 com.apple.launchd[1] (org.clamav.freshclam): Throttling respawn: Will start in 10 seconds
Per the instructions in the referenced thread, I ran
launchctl unload /System/Library/LaunchDaemons/org.clamav.freshclam.plist
I then used pico to edit the org.clamav.freshclamplist file, removing the space between the '-c' and value in the line:
<string>-c 4</string>
I also edited the /etc/freshclam.conf file to change the value:
#DatabaseMirror db.XY.clamav.net
to
DatabaseMirror db.us.clamav.net
I then ran
freshclam -v
followed by
launchctl load /System/Library/LaunchDaemons/org.clamav.freshclam.plist
Checking the log again, not only had the original error continued whilst I was editing, but also on the relaunch of freshclam a new error cropped up:
Nov 7 08:35:39 xserve1 com.apple.launchd[127] (org.clamav.freshclam): Unknown key for integer: Iterations
Nov 7 08:35:39 xserve1 com.apple.launchd[127] (org.clamav.freshclam): Ignored this key: UserName
*Nov 7 08:35:39 xserve1 org.clamav.freshclam[474]: ERROR: Problem with internal logger (UpdateLogFile = /var/log/freshclam.log).*
*Nov 7 08:35:39 xserve1 org.clamav.freshclam[474]: ERROR: Can't open /var/log/freshclam.log in append mode (check permissions!).*
Nov 7 08:35:39 xserve1 com.apple.launchd[127] (org.clamav.freshclam[474]): Exited with exit code: 62
Nov 7 08:35:39 xserve1 com.apple.launchd[127] (org.clamav.freshclam): Throttling respawn: Will start in 10 seconds
Nov 7 08:35:48 xserve1 org.clamav.freshclam[475]: ERROR: Incorrect argument format for option --checks (-c)
Nov 7 08:35:48 xserve1 org.clamav.freshclam[475]: ERROR: Can't parse command line options
Nov 7 08:35:48 xserve1 com.apple.launchd[1] (org.clamav.freshclam[475]): Exited with exit code: 1
Nov 7 08:35:48 xserve1 com.apple.launchd[1] (org.clamav.freshclam): Throttling respawn: Will start in 10 seconds
Nov 7 08:35:49 xserve1 org.clamav.freshclam[476]: ERROR: Problem with internal logger (UpdateLogFile = /var/log/freshclam.log).
Nov 7 08:35:49 xserve1 org.clamav.freshclam[476]: ERROR: Can't open /var/log/freshclam.log in append mode (check permissions!).
Nov 7 08:35:49 xserve1 com.apple.launchd[127] (org.clamav.freshclam[476]): Exited with exit code: 62
Nov 7 08:35:49 xserve1 com.apple.launchd[127] (org.clamav.freshclam): Throttling respawn: Will start in 10 seconds
(Note: after the first 'Exited with exit code: 1' entry, it only repeated the last four lines as above as it respawned.)
Checking the ownership / permissions on the freshclam.log file showed that the owner/goup was _clamav:admin and the permisions were -rw-r----- which is proper and in line with the other clamav files in the directory. Thinking that perhaps the logfile was corrupted, I deleted it and made a new one, setting the owner, group and permissions as per the original. The log errors continued.
Finally, in desparation, I ran
chmod 660 /var/log/freshclam.log
setting the permissions to -rw-rw---- and the errors ceased!
Now, this is not proper file permissions nor does it explain why freshclam suddenly could not append the logfile, but freshclam is now happily churning away without generating continuous log error entries. For the moment, I am not going to argue with successful results!
-Doug

Hi Fred,
interesting.. but I'm of the mind "If it ain't broke.." and it has been running without problem since applying the fix. I may end up having to migrate Mail services to a different server soon though, so I'll keep it in mind if the error crops up again. Thanks for the tip!
-Doug

Similar Messages

  • Verity unstable and permissions errors

    Our scheduled task to purge/reindex stopped working. Verity
    deleted the collections that it was supposed to index. The ws
    folder filled up. I followed the instructions in the TechNote below
    to clear the ws. After recreating collections that Verity deleted,
    and attempting to re-index I get the following errors in the logs.
    I verified that the account under which the service runs has
    "modify" permission in Windows. Any idea why we would get the
    errors in the log?
    ColdFusion TechNote:
    ColdFusion MX 7: Indexing a Verity collection fails with a Path not
    found error

    I forgot to mention that ColdFusion returned an error in the
    browser: "General Failure (-2)"

  • Macbook will not start after sharing and permissions error

    I was cleaning around my files and went into the info of my Mac.
    I clicked get info on the desktop icon and accidently messed up the sharing and permissions settings.
    My computer would not let me into my Mac icon on my desktop, saying I didn't have certain permissions.
    I tried restarting and now my Macbook will not startup. It turns on and loads, but never goes past that.
    I removed the battery and placed it back in but it is not working still.
    Thanks for the help guys!

    Click here and follow the instructions.
    (44677)

  • The overnight maintenance scripts and permissions errors

    I know that the weekly script modifies some permissions when it runs and then disk utility finds them and repairs them. I saw this one this time:
    2008-09-20 20:53:44 -0400: Permissions differ on "private/var/log/secure.log", should be -rw------- , they are -rw-r----- .
    2008-09-20 21:00:28 -0400: Permissions differ on "Library", should be drwxrwxr-t , they are drwxrwxr-x .
    2008-09-20 21:00:43 -0400: Group differs on "private/etc/cups", should be 0, group is 26.
    2008-09-20 21:00:43 -0400: Permissions differ on "private/var/spool/cups/cache/rss", should be drwxr-xr-x , they are drwxrwxr-x .
    The Library one I am not use to seeing. I wonder if the 10.5.5 update changed something.
    Note however, I ran the microsoft office 12.1.2 update before running this one two macbook pros (that are exactly the same). Only one macbook pro had this library thing, but, it hasn't run the weekly script yet either..
    anyone "in the know" know about this library thing?

    Well, I did the 10.5.5 update, ran Repair Permissions afterwards, and did not see /Library error. My /Library is drwxrwxr-t, as it is evidently meant to be. I believe the final "x" on directories is replaced with a "t" to mean that only the owner of files in that folder can delete them. I think it quite possible that it was changed to the more usual x by the the MS Updater. If so, the Repair Permissions process put it back to what it is supposed to be.
    Francine
    Francine
    Schwieder

  • Missing VSS System Writer and CAPI2 error in Event Log

    Hello,
    I'm having problems with making full system backup of Windows 2008 R2 x64. It looks like this is related to missing VSS System Writer. When I'm running command "vssadmin list writers" there is no System Writer in writers list and in event log CAPI2 error (event ID 513) is showing with this description:
    Cryptographic Services failed while processing the OnIdentity() call in the System Writer Object.
    Details:
    TraverseDir : Unable to push subdirectory.
    System Error:
    Unspecified error
    <Event xmlns="http://schemas.microsoft.com/win/2004/08/events/event">
    <System>
    <Provider Name="Microsoft-Windows-CAPI2" Guid="{5bbca4a8-b209-48dc-a8c7-b23d3e5216fb}" EventSourceName="Microsoft-Windows-CAPI2" />
    <EventID Qualifiers="0">513</EventID>
    <Version>0</Version>
    <Level>2</Level>
    <Task>0</Task>
    <Opcode>0</Opcode>
    <Keywords>0x8080000000000000</Keywords>
    <TimeCreated SystemTime="2010-03-14T01:06:35.639125000Z" />
    <EventRecordID>207975</EventRecordID>
    <Correlation />
    <Execution ProcessID="968" ThreadID="11588" />
    <Channel>Application</Channel>
    <Computer>System3</Computer>
    <Security />
    </System>
    <EventData>
    <Data>Details: TraverseDir : Unable to push subdirectory. System Error: Unspecified error</Data>
    </EventData>
    </Event>
    any idea what could be wrong?
    Thanks in advance

    Hello ,
    Based on the research, the VSS System Writer runs in the context of CryptSvc service on Windows Server 2008. To make the system writer works normally, please open services
    console to verify that the Cryptographic Services logon as the credentials of the "Network Service" account.
    The VSS system writer can be missing due to several reasons,  to isolate this issue, please refer to the following steps to boot the problematic server with clean
    boot mode to perform the test.
    Steps: Clean Boot
    1. On a problematic server perform a clean boot and check if the issue still exists
    2. Click Start->Run...->type msconfig and press Enter
    3. Click Services tab and select Hide All Microsoft Services and Disable All third party Services.
    4. Click Startup tab and Disable All startup items
    5. Click OK and choose Restart
    After the server reboot, please run "vssadmin list writers" to check if the "System Writer" can be displayed.
    If the issue still exists, please open a CMD prompt as Run As Administrator and type the following commands to see if it the system writer will be occure.
    CD c:\windows\system32
    Takeown /f %windir%\winsxs\filemaps\* /a
    icacls %windir%\winsxs\filemaps\*.* /grant "NT AUTHORITY\SYSTEM:(RX)"
    icacls %windir%\winsxs\filemaps\*.* /grant "NT Service\trustedinstaller:(F)"
    icacls %windir%\winsxs\filemaps\*.* /grant "BUILTIN\Users:(RX)"
    Moreover, based on the experience, it has been reported that there is some permissions issue which can cause this kind of issue. Please follow the steps below and check
    if it can be helpful.
    On domain controller
    1. Open Active Directory Users and Computers
    2. Click View and then "Advanced features"
    3. Right Click built and click properties.
    4. Click security tab.
    5. Grant read permission to 'Authenticated Users'
    6. Click Apply and OK.
    7. Restart Cryptographic Services.
    Note: By Default, it should have read permission for the system to take system state backup.
    Hope this can be helpful.
    MCTS: Windows Vista | Exchange Server 2007 MCITP: Enterprise Support Technician | Server & Enterprise Admin

  • 2 identical systemkeychains and keychain error in console.log

    I hope someone can help me out here. Posted this already under a solved item, by mistake.
    I do see 2 identical systemkeychains in Keychain . But in/library/keychains there's only one file. The systemkeychains content is 1: the password for my wireless modem, 2: a Dashboard Certificate.
    The same situation in the 2 other (user) accounts on my Mac.
    Also I noticed for some time now (every time I log in) this message in the systemlog:(:SecKeychainFindGenericPasswordError= -25308 (secErrStr= User interaction is not allowed.) (Current is : name of my wireless modem. Lately this message shows up now also in the console log.
    Thanks in advance...

    while using Spotlight searching; keychains Ifound something else: Spotlight marks under the folder /Users/my admin.usersname/library 2 items, but at opening the folder it shows only 1 item: login.keychain.
    Under Keychains/library it shows 1 item and if opening the folder I find one system.keychain file ??

  • Launchd: net.clamav.freshclam: exited with exit code: 62

    Mac OS X Server 10.4.10 (w/ all updates) and BIND9.4.1-P1
    I found this in my /var/log/system.log
    launchd: net.clamav.freshclam: exited with exit code: 62
    launchd: net.clamav.freshclam: respawning too quickly! throttling
    launchd: net.clamav.freshclam: too many failures in succession
    I understand that there is a launchd "startup item" /System/Library/LaunchDaemons/net.clamav.freshclam.plist that is failing to launch.
    How do I fix this?
    Also, I understand that there are three clamav "startup items" in /System/Library/LaunchDaemons/
    net.clamav.clamd.plist
    net.clamav.freshclam.plist
    org.clamav.freshclam.plist
    Are net.clamav.freshclam.plist and org.clamav.freshclam.plist redundant?

    Nevermind, I updated to the latest version of ClamAV using the always excellent osx.topicdesk.com resource, and the error message is gone.
    <http://downloads.topicdesk.com/docs/Updatingclamav_on_OS_XServer.pdf>
    <http://superb-west.dl.sourceforge.net/sourceforge/clamav/clamav-0.91.1.tar.gz>

  • Pacman downloading slowly and signature errors [Solved]

    So, I'm trying to do a clean install of Arch Linux. I've chrooted into the system and tried to download wireless_tools, netcfg, and dialog to set up my wireless connection but ran into two issues. First, sometimes I would get a message that says something like:
    error: failed retrieving file 'wireless_tools-29-7-x86_64.pkg.tar.xz' from mirror.us.leaseweb.net : Operation too slow. Less than 1024 bytes/sec transferred the last 10 seconds
    From what I gathered then it should try the next mirror in my mirrorlist until it finds one with a decent speed. However, then it checks the package integrity and I get more error messages. For each package there's a message like:
    error: wireless_tools: signature from "Gaetan Bisson <[email protected]>" is invalid
    and then:
    error: failed to commit transaction (invalid or corrupted package (PGP signature))
    Any ideas on what's causing this/how to fix it?
    Last edited by TKing (2012-10-02 21:45:47)

    Did you set the hostname in both files:
    https://wiki.archlinux.org/index.php/Be … e#Hostname
    /etc/hostname
    Needs to just contain one line, the hostname.
    /etc/hosts
    You need to edit two of the lines to the exact same text string you put in /etc/hostname
    My /etc/hostname:
    Jeremiah
    My /etc/hosts:
    # /etc/hosts: static lookup table for host names
    #<ip-address> <hostname.domain.org> <hostname>
    127.0.0.1 Jeremiah localhost
    ::1 Jeremiah localhost
    # End of file
    If those three different text entries do not exactly match then you will have network troubles.

  • Maximal log file exceeded (freshclam.log and clamav.log)

    Hello,
    Some of my log files (freshclam.log and clamav.log) are no longer logging, they display this error message:
    Log size = 7782920, max = 1048576
    LOGGING DISABLED (Maximal log file size exceeded).
    and
    Log size = 1049052, max = 1048576
    LOGGING DISABLED (Maximal log file size exceeded).
    I have tried editing /etc/clamd.conf and changing the log size to 0, but that has not helped.
    Thank you for your help in advance.

    Thank you.
    I think somewhere along the way, the checkbox to archive logs was unchecked. I'm not sure why.
    Anyway, I checked that box (and set it to rotate every 7 days), then I backed up the current log files and touched new log files. That's working for now, and hopefully they'll archive on their own now.

  • Freshclam.log and clamav.log suddenly empty...

    My mail server appears to be running fine, and the databases are updating...but...it appears the clamav and freshclam logs are suddenly empty. No config changes happened on the server, they just stopped logging and haven't restarted. One other odd thing: In Server Admin, under the "Update the virus databases X times per day" it shows "Last update: Not available."
    For the heck of it, I decided to temporarily rename the log files to see if I could get fresh versions to generate. Bad things happened...so I moved them back. Suddenly, the virus update log started to work again, but the clamav did not; it is still empty.
    Any ideas on what is happening?
    Message was edited by: Matt Domenici

    Hi,
    I had the very same problem, and I've been able to find a fix. It seems the script /etc/periodic/daily/700.daily.server.cyrus is unable to signal both freshclam and amavisd processes once the log files have been rotated, because it relies on a different "ps" program output, and this makes it fail when searching for the process ID.
    I've fixed the problem by changing line 137 of the script from:
    +($pid, $tt, $stat, $time, $cmdAndArgs) = split(' ', $line, 5);+
    to:
    +($pid, $tt, $time, $cmdAndArgs) = split(' ', $line, 5);+
    as "ps -axwww" doesn't output status column anymore.
    Hope this helps...

  • I tried to install up date 3.6.13 and received error message that I didn't have the right permissions on this mac book , but I am the administrator on my Mac Book Air? Any ideas how to resolve this?

    I tried to install up date 3.6.13 and received error message that I didn't have the system permissions required to install it. I am the administrator on my Mac Book Air? Any ideas how to resolve this?

    * Download a new copy of the Firefox program: http://www.mozilla.com/firefox/all.html
    * Trash the current Firefox application to do a clean (re)install.
    * Install the new version that you have downloaded.
    Your profile data is stored elsewhere in the [http://kb.mozillazine.org/Profile_folder_-_Firefox Firefox Profile Folder], so you won't lose your bookmarks and other personal data.

  • I am trying to authorize my computer and I get an error message: The required directory was not found or has a permissions error. Correct this permissions problem and try again, or deauthorize this computer if the permissions cannot be changed. Help?

    I am trying to authorize my computer and I get an error message: The required directory was not found or has a permissions error. Correct this permissions problem and try again, or deauthorize this computer if the permissions cannot be changed. Help?

    I used Terminal to change the permissions on the folder in question.  I followed the instructions in this article:
    iTunes: Missing folder or incorrect permissions may prevent authorization
    In my case, the folder was there, so I needed the command to change permissions on the folder, not to create one.   I was hesitant to use Terminal b/c I know that if I made an error I could wipe out my hard drive or render my computer unusable.  So to be SURE I didn't make an error, I carefully copied the command from that page and *pasted* it into Terminal.  Also, before I could do anything in Terminal, I had to go change my admin password (it had been a blank password before and that's not acceptable for making changes in Terminal).  I was just super careful when entering my password or doing anything else while Terminal was open (making sure I didn't accidently hit the spacebar or another key, etc.)  And it fixed the problem right away.
    What was confusing for me was that the iTunes error message said to change permissions in the FINDER, which is what I was trying to do.  It didn't mention Terminal.  What would really be helpful is if Apple included a link to a page like this in their error message.

  • We have iPhoto and Mavericks - Cannot play video and get error (OSStatus error -54). Have run permissions and rebuilt iphoto database.. This is most valuable 3 minute movie file I have... Help

    Has anyone a clue how I can save myself from losing most valuable video clip I have ever taken.? Have a fully up to date Macbbok pro retina and most recent iPhoto. Had 55,000 pictures and a few videos in iTunes database. Just a few months ago also installed iCloud. Now find my London Big Ben Fireworks shot of fireworks at midnight coming from clock just returns -54 error when I click it to play. Did a rebuild and permissions attempt at fixing without success. The front picture of start of video shows at start of pictures but only error box now pops up.
    I had a time machine backup that goes back some months and a old computer it may have been on but have not found it yet.
    I do not want to risk losing anything.  We are just finishing cruise of England and Med on our small boat-home and do not want to lose photos of our memories. Thought they were safe since in iTunes and backed up to TIME machine, and now learn they cannot be pulled out separately... Can anyone help us?
    Thanks. I am grateful for any help or ideas while we float out the winter here in England before trying to sail back to America next year.
    Happy Holidays.

    I could not find the original file.
    I did find a file folder named MASTERS.
    I did click down in it to where all the other original files seem to be listed in order.
    They are listed in files showing (name); (date modified); (date created); (size); (kind); and (date added)
    There is a symbol showing each file type, with one file type for photos and a separate symbol showing the movies before each file.
    All of them that are showing properly are listed in order with their name sequentially, ie:
    DSCN4738.JPG
    DSCN4739.JPG
    DSCN4740.JPG
    DSCN4742.MOV
    DSCN4743.MOV
    DSCN4744.MOV
    My valuable movie that now won't play is shown in iPhoto viewing page listing labeled DSCN4741.MOV
    I think I find it later...
    OUT OF SEQUENCE APPROXIMATELY 14 files later I show the file that is shown on the listing info when viewing now named
    New Years Eve Fireworks.MOV  1/1/12 Jan 1, 2012, 12:58 AM  258.1MB  QuickTime file  Feb 21, 2013, 3:46 PM
    NOTE: The creation time is exactly where it should be in sequence but camera taken with was off an hour
    Also, all files in list show the Feb 21, 2013 date - which is date Apple Store migrated my old computers files, which would have included my iPhoto library from my old MACBOOK PRO to the new one.
    I do now remember that in past I had played some of the files from the computer by clicking on them directly in the early hours of the morning - showing some of them to a friend - while messing around demoing this MacBk Pro Retina...
    Though I do not have a clear recall of it recall earlier having a hard time finding this file. I am now certain - based on the circumstantial evidence - I must have changed the name from DSCN4741.MOV to the name shown at the first line of the listing two paragraphs up.
    Now my quandary is how do I escape this mess I made for myself and restore it. I clearly am -- despite being 68 -- being more of a "script kiddie" than a "hacker", but not a competent one of either!
    Thanks for your help in analyzing this Terence, and hope you can help me fix my screwing it up.  Ed

  • Getting authorization error message: Required file was not found or has a permissions error. Correct this permissions problem and try again, or deauthorize this computer if the permissions cannot be changed.

    I have recently purchased this MacBook used and am trying to authorize it on the iTunes Store but even after uninstalling iTunes and re-installing it with a fresh copy I'm getting this error message: "The required file was not found or has a permissions error. Correct this permissions problem and try again, or deauthorize this computer if the permissions cannot be changed."  And I have no idea of where or how to fix this issue.  Any help or suggestions will be greatly appreciated.  I even tried to deauthorize this computer and got the same error message.  HELP!

    I used Terminal to change the permissions on the folder in question.  I followed the instructions in this article:
    iTunes: Missing folder or incorrect permissions may prevent authorization
    In my case, the folder was there, so I needed the command to change permissions on the folder, not to create one.   I was hesitant to use Terminal b/c I know that if I made an error I could wipe out my hard drive or render my computer unusable.  So to be SURE I didn't make an error, I carefully copied the command from that page and *pasted* it into Terminal.  Also, before I could do anything in Terminal, I had to go change my admin password (it had been a blank password before and that's not acceptable for making changes in Terminal).  I was just super careful when entering my password or doing anything else while Terminal was open (making sure I didn't accidently hit the spacebar or another key, etc.)  And it fixed the problem right away.
    What was confusing for me was that the iTunes error message said to change permissions in the FINDER, which is what I was trying to do.  It didn't mention Terminal.  What would really be helpful is if Apple included a link to a page like this in their error message.

  • I can't sync my macbook air with my ipad, problems with authorization... this keeps cropping up: "The required file was not found or has a permissions error. Correct this permissions problem and try again, or deauthorize this computer if the permi"

    Help, cannot sync completely with my ipad, and i also cannot remove or delete shared photos which are clogging up my ipad 64GB memory! Some issue with this keeps croppin gup, so frustrating:
    "The required file was not found or has a permissions error. Correct this permissions problem and try again, or deauthorize this computer if the permissions cannot be changed."
    Not sure how we can correct his permissions problem, and whether authorising or deautorizing makes any difference, with more and more errors keep popping up, this got to be such after an update of the OS, can remember which!?
    HELP!!!

    follow this:
    Launch iTunes
    select iTunes Store from the menu on the left side.
    sign in via the link on the top right area if you haven't done so already
    click the link where you Apple ID email appears, enter your Apple ID password, click View Account, this will take you to a page displaying detailed information about your Apple ID account.
    The last item under Apple ID summary should be Computer Authorisations, click Deauthorize All
    now reauthorize any computers as needed when the system prompts you.
    good luck.

Maybe you are looking for

  • How to change default installation directory sapinst_instdir TO other drive

    Hi, I am installing ECC 6.0 and have enough space in my disk for data files. I have alloted 20GB in C: drive which also comprise of Operating System.sapinst_ instdir directory grows more than 10GB and due to lack of space installation fails. How can

  • A question mark (?) instead of a icon for imovie

    I have tired to use imovie, but my icon in the dock is a question mark. I have hooked up the USB cable and got nothing, like it did not even exist. I bought this computer new a few years ago, and I think I am out of applecare. This is supposed to be

  • MBP in lid closed mode, will the display get to hot?

    i run my MBP in lid closed mode all of the time, as i have a Cinema Display hooked up. i'm not too worried about the MBP overheating, but i was wondering about the display getting extra hot from the MBP when it's closed. i do have a radtech microfibr

  • Updating folder

    I've right-clicked on a folder and clicked "Check for missing folder and files" but nothing happens when I know there are sub-folders that aren't displayed. The only way I can get now showing files to do a File|Import and point to the folder. Is this

  • To Update the IDOC segment values through report program

    My requirement is to update the Idoc segment through the report program. Any SAP provided standard function module is available to update the Idoc segment values. Please help needed.