The truth is, I believe the issue with amavis and monit was due to some disk errors that have been solved now
webserver:/var/log# monit summary
The monit daemon 4.10.1 uptime: 9h 15m
Process 'amavisd' running
File 'amavisd_bin' accessible
File 'amavisd_rc' accessible
Process 'apache' running
Process 'clamd' running
File 'clamavd_bin' accessible
File 'clamavd_rc' accessible
Process 'postfix' running
File 'postfix_rc' accessible
Process 'spamd' running
File 'spamd_bin' accessible
File 'spamd_rc' accessible
Process 'syslogd' running
File 'syslogd_file' accessible
System 'webserver.kd8q.com' running
So that part is solved but...
I still cannot figure out why clamav is dying ???
Feb 12 01:20:32 webserver amavis: (02275-05) (!!)ClamAV-clamd av-scanner FAILED: run_av error: Too many retries to talk to /var/run/clamav/clamd.ctl (Can't connect to UNIX socket /var/run/clamav/clamd.ctl: Connection refused) at (eval 88) line 309.
Feb 12 01:22:33 webserver amavis: (02275-06-6) (!!)TROUBLE in check_mail: virus_scan FAILED: virus_scan: ALL VIRUS SCANNERS FAILED: ClamAV-clamd av-scanner FAILED: run_av error: Too many retries to talk to /var/run/clamav/clamd.ctl (Can't connect to UNIX socket /var/run/clamav/clamd.ctl: Connection refused) at (eval 88) line 309.; ClamAV-clamscan av-scanner FAILED: run_av error: run_av: Exceeded allowed time at (eval 88) line 516.
At least monit gets clamav restarted but I would sure like to get to the bottom of this. I have to believe something is happening with a cron job. This may sound like a silly question, but where do the "root" emails disappear too on an ispconfig3 system? I think the fact that I cannot find them and I noticed most times the mail queue contained a mail to root at almost the exact time clamav dies, that maybe this is related!
Thank to all for your help