How to Install and Use ClamAV on Linux: Complete Step-by-Step Guide
Published by Jahid Shah | Technical Security & Linux Administration Guide
ClamAV (Clam AntiVirus) is the industry standard, open-source antivirus toolkit designed for detecting trojans, viruses, webshells, and malicious payloads on Linux servers, web roots, and mail gateways. This practical guide covers installation, virus database management, file scanning, and production automation.
1. Understanding Core ClamAV Components
ClamAV consists of three primary modules:
- clamscan: A standalone, on-demand command-line scanning engine.
- freshclam: The automatic signature database updater.
- clamd / clamav-daemon: A persistent, background scanning daemon that keeps definitions loaded in memory for faster scans via
clamdscan.
2. Installing ClamAV
Ubuntu / Debian
sudo apt update
sudo apt install clamav clamav-daemon -y
RHEL / AlmaLinux / Rocky Linux / CentOS
sudo dnf install epel-release -y
sudo dnf install clamav clamd clamav-update -y
3. Updating Virus Signatures (freshclam)
Before scanning any files, synchronize the latest signature database. The freshclam service frequently runs in the background immediately upon installation; stop it momentarily to execute an initial manual sync:
# Stop the daemon temporarily to release the lock file
sudo systemctl stop clamav-freshclam
# Update definitions manually
sudo freshclam
# Start and enable the automatic updater daemon
sudo systemctl start clamav-freshclam
sudo systemctl enable clamav-freshclam
4. Practical Scanning Commands (clamscan)
Basic Syntax and Daily Commands
| Task | Command |
|---|---|
| Scan a single file | clamscan /path/to/file.php |
| Scan directory recursively, showing infected files only | clamscan -r -i /var/www/html |
| Scan entire system, excluding pseudo-filesystems | sudo clamscan -r -i --exclude-dir="^/sys" --exclude-dir="^/proc" --exclude-dir="^/dev" / |
| Log scan results to an output file | clamscan -r -i /var/www/html --log=/var/log/clamav/scan.log |
Quarantining vs. Removing Threats
Safety Rule: Avoid using --remove=yes blindly on production web servers, as false positives can break applications. Move suspicious files to a dedicated quarantine directory instead.
# Create a dedicated quarantine directory
sudo mkdir -p /var/quarantine
# Run recursive scan and move infected files to quarantine
sudo clamscan -r -i --move=/var/quarantine /var/www/html
5. Performance Optimization: clamscan vs clamdscan
| Feature | clamscan | clamdscan |
|---|---|---|
| Daemon Required | No | Yes (clamav-daemon) |
| Database Loading | Reloads definitions on every execution | Kept continuously in system memory |
| Scan Startup Speed | Slower (loads 300MB+ database) | Near instantaneous execution |
| Ideal Use Case | One-off manual checks | Automated cron jobs & active servers |
To use clamdscan, ensure the daemon is running:
sudo systemctl enable --now clamav-daemon
clamdscan -m --fdpass /var/www/html
6. Automating Scans with Cron
Automate daily security scans by adding a cron job to root's crontab:
sudo crontab -e
Add the following line to schedule a daily scan of the web root at 03:00 AM, logging results to /var/log/clamav/daily-scan.log:
0 3 * * * /usr/bin/clamscan -r -i /var/www/html --log=/var/log/clamav/daily-scan.log --move=/var/quarantine
7. Testing the Configuration
Validate that ClamAV triggers alerts properly using the standard harmless EICAR test string:
# Download the harmless EICAR test signature
curl -s -O https://secure.eicar.org/eicar.com.txt
# Run the scanner
clamscan -i eicar.com.txt
If ClamAV displays eicar.com.txt: Win.Test.EICAR_HDB-1 FOUND, the scanner and detection database are functioning properly.