ClamAV
ClamAV: A powerful open-source antivirus solution for Linux systems.

How to Install and Use ClamAV on Linux: Complete Step-by-Step Guide

Published by Jahid Shah | Technical Security & Linux Administration Guide

ClamAV (Clam AntiVirus) is the industry standard, open-source antivirus toolkit designed for detecting trojans, viruses, webshells, and malicious payloads on Linux servers, web roots, and mail gateways. This practical guide covers installation, virus database management, file scanning, and production automation.

1. Understanding Core ClamAV Components

ClamAV consists of three primary modules:

  • clamscan: A standalone, on-demand command-line scanning engine.
  • freshclam: The automatic signature database updater.
  • clamd / clamav-daemon: A persistent, background scanning daemon that keeps definitions loaded in memory for faster scans via clamdscan.

2. Installing ClamAV

Ubuntu / Debian


sudo apt update
sudo apt install clamav clamav-daemon -y

RHEL / AlmaLinux / Rocky Linux / CentOS

sudo dnf install epel-release -y
sudo dnf install clamav clamd clamav-update -y

3. Updating Virus Signatures (freshclam)

Before scanning any files, synchronize the latest signature database. The freshclam service frequently runs in the background immediately upon installation; stop it momentarily to execute an initial manual sync:

# Stop the daemon temporarily to release the lock file
sudo systemctl stop clamav-freshclam

# Update definitions manually
sudo freshclam

# Start and enable the automatic updater daemon
sudo systemctl start clamav-freshclam
sudo systemctl enable clamav-freshclam

4. Practical Scanning Commands (clamscan)

Basic Syntax and Daily Commands

Task Command
Scan a single file clamscan /path/to/file.php
Scan directory recursively, showing infected files only clamscan -r -i /var/www/html
Scan entire system, excluding pseudo-filesystems sudo clamscan -r -i --exclude-dir="^/sys" --exclude-dir="^/proc" --exclude-dir="^/dev" /
Log scan results to an output file clamscan -r -i /var/www/html --log=/var/log/clamav/scan.log

Quarantining vs. Removing Threats

Safety Rule: Avoid using --remove=yes blindly on production web servers, as false positives can break applications. Move suspicious files to a dedicated quarantine directory instead.
# Create a dedicated quarantine directory
sudo mkdir -p /var/quarantine

# Run recursive scan and move infected files to quarantine
sudo clamscan -r -i --move=/var/quarantine /var/www/html

5. Performance Optimization: clamscan vs clamdscan

Feature clamscan clamdscan
Daemon Required No Yes (clamav-daemon)
Database Loading Reloads definitions on every execution Kept continuously in system memory
Scan Startup Speed Slower (loads 300MB+ database) Near instantaneous execution
Ideal Use Case One-off manual checks Automated cron jobs & active servers

To use clamdscan, ensure the daemon is running:

sudo systemctl enable --now clamav-daemon
clamdscan -m --fdpass /var/www/html

6. Automating Scans with Cron

Automate daily security scans by adding a cron job to root's crontab:

sudo crontab -e

Add the following line to schedule a daily scan of the web root at 03:00 AM, logging results to /var/log/clamav/daily-scan.log:

0 3 * * * /usr/bin/clamscan -r -i /var/www/html --log=/var/log/clamav/daily-scan.log --move=/var/quarantine

7. Testing the Configuration

Validate that ClamAV triggers alerts properly using the standard harmless EICAR test string:

# Download the harmless EICAR test signature
curl -s -O https://secure.eicar.org/eicar.com.txt

# Run the scanner
clamscan -i eicar.com.txt

If ClamAV displays eicar.com.txt: Win.Test.EICAR_HDB-1 FOUND, the scanner and detection database are functioning properly.