ClamAV / LMD — antivirus

Installed, but the service is not running. Start it and enable autostart:
sudo systemctl enable --now clamav-daemon
How to set up (FAQ)
ClamAV
Installed
v1.0.7
clamd daemon
Inactive
DB version: 27323
Threats found
0
Files scanned: 189,596
Linux Malware Detect
Installed
v1.6.5
ClamAV
Status Inactive
DB version 27323
DB date Sun Oct 11 17:47:18 2026
Last scan 11.10.2026 06:51
Threats found 0
Recent threats

No threats detected

Why a Linux server runs antivirus at all

The objection is familiar: Linux does not get viruses. Mostly true, and mostly beside the point. A public server is not defending its own binaries, it is defending the directory where users upload files. Web shells dropped through a vulnerable upload form, malicious attachments passing through a mail server, and payloads staged in a writable temp directory are all things ClamAV recognises, and all things that arrive on Linux hosts constantly.

This page shows when the last scan ran, what it found, and — the field that matters most — how old the signature database is. ClamAV with stale signatures gives the appearance of protection and none of the substance. If freshclam has not run in a week, the scan results below it mean very little.

Linux Malware Detect is shown alongside, where installed. The two complement each other: ClamAV brings the broad signature set, LMD brings signatures for web-facing malware that general antivirus tends to miss.