# How to Install and Configure ClamAV for Linux Antivirus Protection

> Secure your Linux server by learning to install and configure ClamAV. This guide covers package installation, configuration file backups, service enablement, and on-demand malware scanning with clamscan.

- Repository: [IMTheNachoMan/How-To-Secure-A-Linux-Server](https://github.com/imthenachoman/How-To-Secure-A-Linux-Server)
- Tags: how-to-guide
- Published: 2026-05-14

---

**Install the three ClamAV packages (`clamav`, `clamav-freshclam`, `clamav-daemon`), back up [`/etc/clamav/freshclam.conf`](https://github.com/imthenachoman/How-To-Secure-A-Linux-Server/blob/main//etc/clamav/freshclam.conf) and [`/etc/clamav/clamd.conf`](https://github.com/imthenachoman/How-To-Secure-A-Linux-Server/blob/main//etc/clamav/clamd.conf), enable the systemd services, and use `clamscan` for on-demand malware detection.**

According to the `imthenachoman/How-To-Secure-A-Linux-Server` repository, ClamAV provides a complete open-source antivirus solution for Debian-based Linux servers. The following guide details the exact steps to deploy the scanning engine, automate signature updates, and configure the optional memory-resident daemon for faster scans.

## Understanding ClamAV Components

ClamAV operates through three distinct components that work together to provide comprehensive malware detection.

### Core Scanning Engine

The **`clamscan`** binary located at `/usr/bin/clamscan` serves as the command-line interface for on-demand file and directory scanning. This tool loads virus definitions from disk and checks specified paths against the signature database.

### Signature Updater

**`clamav-freshclam`** is the daemon responsible for maintaining current threat intelligence. It periodically downloads the latest virus database from ClamAV mirrors and runs as the `clamav-freshclam.service` systemd unit. Its behavior is controlled by [`/etc/clamav/freshclam.conf`](https://github.com/imthenachoman/How-To-Secure-A-Linux-Server/blob/main//etc/clamav/freshclam.conf).

### Memory-Resident Daemon

The optional **`clamd`** daemon keeps virus definitions loaded in RAM, eliminating the startup overhead required by `clamscan`. This service (`clamav-daemon.service`) reads configuration from [`/etc/clamav/clamd.conf`](https://github.com/imthenachoman/How-To-Secure-A-Linux-Server/blob/main//etc/clamav/clamd.conf) and listens on a Unix socket for scan requests, significantly improving performance for frequent scans.

## Installing ClamAV on Debian-Based Systems

Update package repositories and install all three components to ensure complete functionality.

```bash
sudo apt update
sudo apt install clamav clamav-freshclam clamav-daemon

```

This command installs the scanning engine, the signature updater, and the optional daemon in a single operation.

## Configuring ClamAV Services

Proper configuration requires backing up default settings before modification and adjusting update frequencies to match your security requirements.

### Back Up Configuration Files

Preserve original configurations using timestamped copies before editing:

```bash

# Freshclam config backup

sudo cp --archive /etc/clamav/freshclam.conf \
    /etc/clamav/freshclam.conf-COPY-$(date +"%Y%m%d%H%M%S")

# Clamd config backup

sudo cp --archive /etc/clamav/clamd.conf \
    /etc/clamav/clamd.conf-COPY-$(date +"%Y%m%d%H%M%S")

```

### Configure Virus Definition Updates

Adjust how frequently the system checks for new signatures using the interactive configuration tool:

```bash
sudo dpkg-reconfigure clamav-freshclam

```

This command launches a dialog where you can modify the `Checks` parameter, controlling how many times per day `freshclam` downloads updates. Alternatively, edit [`/etc/clamav/freshclam.conf`](https://github.com/imthenachoman/How-To-Secure-A-Linux-Server/blob/main//etc/clamav/freshclam.conf) directly to fine-tune mirror selection and notification settings.

### Daemon Configuration

If utilizing the `clamd` service, review [`/etc/clamav/clamd.conf`](https://github.com/imthenachoman/How-To-Secure-A-Linux-Server/blob/main//etc/clamav/clamd.conf) to configure the local socket path, maximum file size limits, and user permissions. The repository notes that the daemon may fail to notify properly if the socket does not exist, so verify socket directory permissions after configuration changes.

## Enabling and Managing Systemd Services

Start and enable services to ensure automatic operation across reboots.

Enable the signature updater:

```bash
sudo systemctl enable clamav-freshclam
sudo systemctl start clamav-freshclam
sudo systemctl status clamav-freshclam

```

Optionally enable the scanning daemon for improved performance:

```bash
sudo systemctl enable clamav-daemon
sudo systemctl start clamav-daemon
sudo systemctl status clamav-daemon

```

Verify both services show `active (running)` before proceeding to scan operations.

## Running Scans and Automation

Execute manual scans or implement automated scheduling to maintain continuous protection.

### Manual Scanning

Scan individual files or entire directories recursively, displaying only infected items:

```bash

# Scan a single file

sudo clamscan /path/to/file

# Scan directory recursively, showing infected only

sudo clamscan -r -i /path/to/directory

```

The `-r` flag enables recursive descent into subdirectories, while `-i` restricts output to infected files only, reducing log noise.

### Scheduled Scans with Cron

Create a daily automated scan by placing a script in `/etc/cron.daily/`:

```bash
sudo tee /etc/cron.daily/clamav-scan << 'EOF'
#!/bin/sh
LOG=/var/log/clamav-scan.log
/usr/bin/clamscan -r -i /home > "$LOG" 2>&1
EOF

```

Make the script executable:

```bash
sudo chmod +x /etc/cron.daily/clamav-scan

```

The system now executes this scan daily, logging results to `/var/log/clamav-scan.log`. Adjust the target path `/home` to match directories requiring regular monitoring.

## Summary

- **Install three packages**: `clamav` (scanner), `clamav-freshclam` (updater), and `clamav-daemon` (optional resident service) via `apt`.
- **Back up configs**: Archive [`/etc/clamav/freshclam.conf`](https://github.com/imthenachoman/How-To-Secure-A-Linux-Server/blob/main//etc/clamav/freshclam.conf) and [`/etc/clamav/clamd.conf`](https://github.com/imthenachoman/How-To-Secure-A-Linux-Server/blob/main//etc/clamav/clamd.conf) with timestamped copies before modification.
- **Enable services**: Start `clamav-freshclam.service` for automatic updates; optionally enable `clamav-daemon.service` for faster scanning.
- **Configure updates**: Use `dpkg-reconfigure clamav-freshclam` to set daily signature check frequency.
- **Execute scans**: Use `clamscan -r -i` for recursive scanning, or schedule automated scans via `/etc/cron.daily/` scripts.

## Frequently Asked Questions

### What is the difference between clamscan and clamd?

`clamscan` is a standalone binary that loads virus definitions from disk each execution, making it suitable for occasional scans. `clamd` is a persistent daemon that maintains definitions in memory, offering significantly faster response times for frequent scanning operations but consuming RAM continuously.

### How often does ClamAV update virus definitions?

By default, `freshclam` checks for updates multiple times per day, configurable via the `Checks` parameter in [`/etc/clamav/freshclam.conf`](https://github.com/imthenachoman/How-To-Secure-A-Linux-Server/blob/main//etc/clamav/freshclam.conf) or through `dpkg-reconfigure clamav-freshclam`. Most production environments benefit from hourly or bi-hourly updates to maintain current protection.

### Do I need to run the ClamAV daemon for basic protection?

No. The `clamav-daemon` is optional. You can perform comprehensive malware detection using only `clamscan` executed manually or via cron jobs. The daemon becomes necessary only when scan latency is critical or when integrating with applications that communicate via the ClamAV socket protocol.

### Where does ClamAV store its configuration files?

Configuration files reside in `/etc/clamav/`. Specifically, [`/etc/clamav/freshclam.conf`](https://github.com/imthenachoman/How-To-Secure-A-Linux-Server/blob/main//etc/clamav/freshclam.conf) controls signature updates, while [`/etc/clamav/clamd.conf`](https://github.com/imthenachoman/How-To-Secure-A-Linux-Server/blob/main//etc/clamav/clamd.conf) manages the daemon service. Always back up these files before editing, as incorrect configuration can prevent the services from starting.