{"id":47272,"date":"2026-06-27T22:44:56","date_gmt":"2026-06-27T13:44:56","guid":{"rendered":"https:\/\/raybeam.jp\/docs\/initial-server-setup\/how-to-install-and-configure-clamav-to-scan-your-server-regularly-for-malware\/"},"modified":"2026-06-27T22:45:23","modified_gmt":"2026-06-27T13:45:23","slug":"cach-cai-dat-va-cau-hinh-clamav-de-quet-may-chu-cua-ban-thuong-xuyen-nham-phat-hien-phan-mem-doc-hai","status":"publish","type":"docs","link":"https:\/\/raybeam.jp\/vi\/docs\/initial-server-setup\/how-to-install-and-configure-clamav-to-scan-your-server-regularly-for-malware\/","title":{"rendered":"C\u00e1ch c\u00e0i \u0111\u1eb7t v\u00e0 c\u1ea5u h\u00ecnh ClamAV \u0111\u1ec3 qu\u00e9t ph\u1ea7n m\u1ec1m \u0111\u1ed9c h\u1ea1i tr\u00ean m\u00e1y ch\u1ee7 c\u1ee7a b\u1ea1n \u0111\u1ecbnh k\u1ef3"},"content":{"rendered":"<p class=\"is-style-text-annotation is-style-text-annotation--1 wp-block-paragraph\">B\u00e0i vi\u1ebft n\u00e0y gi\u1ea3 \u0111\u1ecbnh r\u1eb1ng b\u1ea1n s\u1ebd s\u1eed d\u1ee5ng Ubuntu Server 20.04 ho\u1eb7c 24.04.<\/p>\n\n\n\n<h2 id=\"motivation\" class=\"wp-block-heading\">\u0110\u1ed9ng l\u1ef1c<\/h2>\n\n\n\n<p class=\"wp-block-paragraph\">Scan for viruses and malware regularly and directly on the server while consuming low resources.<\/p>\n\n\n\n<h2 id=\"alternatives\" class=\"wp-block-heading\">C\u00e1c l\u1ef1a ch\u1ecdn thay th\u1ebf<\/h2>\n\n\n\n<p class=\"wp-block-paragraph\"><a href=\"https:\/\/www.rfxn.com\/projects\/linux-malware-detect\/\">LMD (maldet)<\/a> on your server or the WordPress plugins <a href=\"https:\/\/www.wordfence.com\/\">Wordfence<\/a> V\u00e0 <a href=\"https:\/\/nintechnet.com\/ninjascanner\/\">NinjaScanner<\/a> are good options.<\/p>\n\n\n\n<h2 id=\"install-clamav\" class=\"wp-block-heading\">Install ClamAV<\/h2>\n\n\n\n<p class=\"wp-block-paragraph\">ClamAV is part of WordOps Stack and can be installed with (we need to also install two additional packages):<\/p>\n\n\n\n<pre class=\"wp-block-code\"><code>wo stack install --clamav\nsudo apt install clamav-daemon clamdscan -y<\/code><\/pre>\n\n\n\n<p class=\"wp-block-paragraph\">B\u1ea1n c\u0169ng c\u00f3 th\u1ec3 c\u00e0i \u0111\u1eb7t n\u00f3 tr\u00ean Ubuntu b\u1eb1ng APT:<\/p>\n\n\n\n<pre class=\"wp-block-code\"><code>sudo apt update\nsudo apt install clamav clamav-daemon clamdscan -y<\/code><\/pre>\n\n\n\n<h2 id=\"add-custom-database-signatures\" class=\"wp-block-heading\">Add custom database signatures<\/h2>\n\n\n\n<p class=\"wp-block-paragraph\">To enhance malware and virus detection capabilities, you can optionally incorporate the database signatures offered by <a href=\"https:\/\/www.rfxn.com\/projects\/linux-malware-detect\/\">RFXN&#8217;s Linux Malware Detect (LMD)<\/a>, commonly referred to as maldet. Append the following configuration to the end of the<em> <code class=\"\">\/etc\/clamav\/freshclam.conf<\/code><\/em> file:<\/p>\n\n\n\n<pre class=\"wp-block-code\"><code>DatabaseCustomURL https:\/\/www.rfxn.com\/downloads\/rfxn.ndb\nDatabaseCustomURL https:\/\/www.rfxn.com\/downloads\/rfxn.hdb\nDatabaseCustomURL https:\/\/www.rfxn.com\/downloads\/rfxn.yara<\/code><\/pre>\n\n\n\n<h2 id=\"perform-a-full-scan-of-your-files\" class=\"wp-block-heading\">Perform a full scan of your files<\/h2>\n\n\n\n<p class=\"wp-block-paragraph\">Let&#8217;s now manually update the virus database before running it (it may be required to stop the <em>clamav-freshclam<\/em> service so that we can run it manually):<\/p>\n\n\n\n<pre class=\"wp-block-code\"><code>sudo systemctl stop clamav-freshclam.service\nsudo freshclam<\/code><\/pre>\n\n\n\n<p class=\"wp-block-paragraph\">And run a complete scan on our sites directory:<\/p>\n\n\n\n<pre class=\"wp-block-code\"><code>sudo clamscan -r \/var\/www<\/code><\/pre>\n\n\n\n<h2 id=\"enable-clamav-as-a-service-and-schedule-a-cron-job\" class=\"wp-block-heading\">Enable ClamAV as a service and schedule a cron job<\/h2>\n\n\n\n<p class=\"wp-block-paragraph\">There are two ways of running ClamAV, with the standalone command <em>clamscan<\/em> or with the alternative <em>qu\u00e9t ngao<\/em>, which access the service daemon and stores the virus database direct on memory, with a much better performance. Let&#8217;s start and enable the required daemons with the following:<\/p>\n\n\n\n<pre class=\"wp-block-code\"><code>sudo systemctl start clamav-freshclam.service\nsudo systemctl enable clamav-freshclam.service\nsudo systemctl start clamav-daemon.service\nsudo systemctl enable clamav-daemon.service<\/code><\/pre>\n\n\n\n<p class=\"wp-block-paragraph\">The following command is designed to scan only new or modified files within the last 25 hours. You can install it in your sudo crontab. Additionally, you have the option to configure your email at the beginning to receive notifications following each scan.<\/p>\n\n\n\n<pre class=\"wp-block-code\"><code>MAILTO=\"<span \n                data-original-string='qgLhvPqWydOyf8uDqH1LzQ==a66m+WEWvxNZmr4jLO9uRJ3T17zb37XUcZ9bSe+kLwgpPc='\n                class='apbct-email-encoder'\n                title='This contact has been encoded by Anti-Spam by CleanTalk. Click to decode. To finish the decoding make sure that JavaScript is enabled in your browser.'>al<span class=\"apbct-blur\">****<\/span>@<span class=\"apbct-blur\">*****<\/span>le.com<\/span>\"\n0 2 * * * find \/var\/www -type f -mmin -1500 -print0 | xargs -0 clamdscan --fdpass --multiscan --infected<\/code><\/pre>\n\n\n\n<div class=\"wp-block-group is-style-default has-small-font-size has-global-padding is-layout-constrained wp-block-group-is-layout-constrained\">\n<p class=\"wp-block-paragraph\">T\u00e0i nguy\u00ean:<\/p>\n\n\n\n<ul class=\"wp-block-list\">\n<li><a href=\"https:\/\/www.liquidweb.com\/blog\/linux-malware-detect-ubuntu-20-04\/\">https:\/\/www.liquidweb.com\/blog\/linux-malware-detect-ubuntu-20-04\/<\/a><\/li>\n\n\n\n<li><a href=\"https:\/\/malware.expert\/howto\/extending-clamav-signatures-with-rfxn-database-for-php-malwares\">https:\/\/malware.expert\/howto\/extending-clamav-signatures-with-rfxn-database-for-php-malwares<\/a><\/li>\n\n\n\n<li><a href=\"https:\/\/tcpip.wtf\/en\/clamav-scan-only-new-modified-files.htm\">https:\/\/tcpip.wtf\/en\/clamav-scan-only-new-modified-files.htm<\/a><\/li>\n\n\n\n<li><a href=\"https:\/\/radeksprta.eu\/posts\/automatic-clamav-scans-with-email-notifications\/\">https:\/\/radeksprta.eu\/posts\/automatic-clamav-scans-with-email-notifications\/<\/a><\/li>\n<\/ul>\n<\/div>","protected":false},"featured_media":0,"parent":47233,"menu_order":1,"comment_status":"open","ping_status":"closed","template":"","meta":{"_seopress_titles_title":"","_seopress_titles_desc":"","_seopress_robots_index":"","_seopress_robots_follow":"","_seopress_robots_imageindex":"","_seopress_robots_snippet":"","_seopress_robots_primary_cat":"","_seopress_robots_breadcrumbs":"","_seopress_robots_freeze_modified_date":"","_seopress_robots_custom_modified_date":"","_seopress_robots_canonical":"","_seopress_social_fb_title":"","_seopress_social_fb_desc":"","_seopress_social_fb_img":"","_seopress_social_fb_img_attachment_id":0,"_seopress_social_fb_img_width":0,"_seopress_social_fb_img_height":0,"_seopress_social_twitter_title":"","_seopress_social_twitter_desc":"","_seopress_social_twitter_img":"","_seopress_social_twitter_img_attachment_id":0,"_seopress_social_twitter_img_width":0,"_seopress_social_twitter_img_height":0,"_seopress_redirections_value":"","_seopress_redirections_enabled":"","_seopress_redirections_enabled_regex":"","_seopress_redirections_logged_status":"","_seopress_redirections_param":"","_seopress_redirections_type":0,"_seopress_analysis_target_kw":"","pmpro_default_level":"","nav_title":"","positive":"","negative":"","footnotes":""},"docs_category":[],"class_list":["post-47272","docs","type-docs","status-publish","hentry","pmpro-has-access"],"_links":{"self":[{"href":"https:\/\/raybeam.jp\/vi\/wp-json\/wp\/v2\/docs\/47272","targetHints":{"allow":["GET"]}}],"collection":[{"href":"https:\/\/raybeam.jp\/vi\/wp-json\/wp\/v2\/docs"}],"about":[{"href":"https:\/\/raybeam.jp\/vi\/wp-json\/wp\/v2\/types\/docs"}],"replies":[{"embeddable":true,"href":"https:\/\/raybeam.jp\/vi\/wp-json\/wp\/v2\/comments?post=47272"}],"version-history":[{"count":1,"href":"https:\/\/raybeam.jp\/vi\/wp-json\/wp\/v2\/docs\/47272\/revisions"}],"predecessor-version":[{"id":47273,"href":"https:\/\/raybeam.jp\/vi\/wp-json\/wp\/v2\/docs\/47272\/revisions\/47273"}],"up":[{"embeddable":true,"href":"https:\/\/raybeam.jp\/vi\/wp-json\/wp\/v2\/docs\/47233"}],"wp:attachment":[{"href":"https:\/\/raybeam.jp\/vi\/wp-json\/wp\/v2\/media?parent=47272"}],"wp:term":[{"taxonomy":"docs_category","embeddable":true,"href":"https:\/\/raybeam.jp\/vi\/wp-json\/wp\/v2\/docs_category?post=47272"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}