ClamAV app icon

Security and privacy

ClamAV

Scan files and folders on Windows with Cisco Talos's open-source antivirus engine, updated signature databases and a command-line scanner.

WindowsmacOSLinuxGPL-2.0

An open-source scanning engine for files and servers

ClamAV is an open-source antivirus engine maintained by Cisco Talos. It has been the standard choice for scanning mail gateways and file uploads on servers for years, and it also runs on Windows as an on-demand scanner. The Windows installer provides the engine, the command-line scanner, a daemon that can answer scan requests and the updater that keeps the signature database current.

What the engine detects

Detection covers malware, potentially unwanted applications and many archive and document formats, because the engine unpacks containers before scanning what is inside. Signatures arrive as versioned database files that the updater refreshes, and the same engine processes enormous volumes of attachments on mail gateways and content scanners. On Windows it behaves as a scanner rather than a background monitor, inspecting files when you ask it to rather than as they are opened.

Scanning, updating and where it fits

A scan is started with a command against a file, a folder or a whole drive, and results are printed or written to a log. The updater pulls signature and engine updates over the internet from the project's distribution servers, and it should be scheduled or run manually before important scans, since a stale database detects much less. On Windows, ClamAV does not install a real-time file system filter: it inspects files when asked to, not as they are opened. That single fact determines the right use case. It suits scanning a download folder, checking a USB drive, verifying files on a file server, or adding a second opinion to an existing security setup. For web browsers, mail clients and everyday desktop use, it is a complement rather than a replacement for the protection already built into Windows.

Configuration and practical limits

The behaviour of the daemon and the updater is controlled by configuration files that ship with the package, and the project documentation explains options for archive size limits, exclusions, log paths and scheduled scans. Signature updates need outbound internet access; on locked-down networks the update files have to be fetched by other means. The database is large, so the first update takes a while. Archive scanning is deliberately bounded, because a deeply nested or huge archive can consume enormous memory and time, and those limits exist for good reason. False positives are possible with any signature engine, and the log should be reviewed before deleting anything that is flagged. Scans of network shares are limited by disk speed, and scanning a whole machine takes far longer than scanning the folders that actually receive new files.

When ClamAV is not enough

If you want continuous protection with no manual scans, use the antivirus component already present in Windows or a commercial product with real-time monitoring and behavioural detection. ClamAV does not provide web filtering, ransomware rollback or exploit protection. Its value is being free, auditable, scriptable and widely deployed on the server side, which is why administrators who already run it elsewhere often keep a Windows install for checking files before they are moved or shared.

Best for
Users and administrators who want a free, scriptable scanning engine for checking downloads, removable drives and file shares, or as a second opinion alongside another antivirus.
Good to know
The Windows build scans on demand only; it does not add real-time file monitoring. Update the signature database before scanning, and review flagged files in the log before deleting anything.

ClamAV is an open-source scanning engine you run on demand against files and folders.

How to get started

  1. Install the Windows MSI and note where the engine and configuration files are placed.
  2. Run the updater once so the signature database is current; the first download is large.
  3. Scan a test folder from the command line and read the summary at the end of the output.
  4. Point a scan at your download folder and any removable drives you use regularly.
  5. Review the log for anything flagged, and check the file before deciding what to do with it.
  6. Schedule the updater, or run it manually before every scan, so detections are not missed because signatures are stale.

Questions & answers

Does ClamAV protect files in real time?

Not on Windows. It scans when asked and does not monitor files as they are opened, so keep the protection already built into Windows enabled as well.

How often should signatures be updated?

Before any scan you rely on. The updater is quick once the database exists, but a stale database detects far less than a current one.

Is it suitable for a file server?

Yes. Many administrators use it exactly that way, scanning uploads and shared folders on a schedule, and the exit codes and logs make it easy to automate.

More in security and privacy

View category