Clam AV 0.96, running a definition update, scanning a file and identifying a Trojan from the command-line.
|Stable release||0.98.6 / January 27, 2015|
|Written in||C, C++|
|License||GNU General Public License|
Clam AntiVirus (ClamAV) is a free and open-source, cross-platform antivirus software tool-kit able to detect many types of malicious software, including viruses. One of its main uses is on mail servers as a server-side email virus scanner. The application was developed for Unix and has third party versions available for AIX, BSD, HP-UX, Linux, OS X, OpenVMS, OSF (Tru64) and Solaris. As of version 0.97.5, ClamAV builds and runs on Microsoft Windows. Both ClamAV and its updates are made available free of charge.
Sourcefire, a maker of intrusion detection products and the owner of Snort, announced on 17 August 2007 that it had acquired the trademarks and copyrights to ClamAV from five key developers. In turn, Sourcefire was acquired by Cisco in 2013.
The application also features a Milter interface for sendmail and on-demand scanning. It has support for Zip, RAR, Tar, Gzip, Bzip2, OLE2, Cabinet, CHM, BinHex, SIS formats, most mail file formats, ELF executables and Portable Executable (PE) files compressed with UPX, FSG, Petite, NsPack, wwpack32, MEW, Upack and obfuscated with SUE, Y0da Cryptor. It also supports many document formats, including Microsoft Office, HTML, Rich Text Format (RTF) and Portable Document Format (PDF).
ClamAV is currently tested daily in comparative tests against other antivirus products on Shadowserver. In 2011, Shadowserver tested over 25 million samples against ClamAV and numerous other antivirus products. Out of the 25 million samples tested, ClamAV scored 76.60% ranking 12 out of 19, a higher rating than some much more established competitors.
ClamAV was included in comparative tests against other antivirus products. In the 2008 AV-Test it rated: on-demand: very poor, false positives: poor, on-access: poor, response time: very good, rootkits: very poor.
In a Shadowserver six-month test between June and December 2011, ClamAV detected over 75.45% of all viruses tested, putting it in fifth place behind AhnLab, Avira, BitDefender and Avast. AhnLab, the top antivirus, detected 80.28%.
The ClamAV engine can be reliably used to detect several kinds of files. In particular, some phishing emails can be detected using antivirus techniques. However, false positive rates are inherently higher than those of traditional malware detection. Sanesecurity is an organization that maintains a number of such databases; in addition they distribute and classify a number of similar databases from other parties, such as CRDF Threat Center, SecuriteInfo, Porcupine, Julian Field, MalwarePatrol.
ClamAV Unofficial Signatures are mainly used by system administrators to filter email messages. Detections of these groups should be scored, rather than causing an outright block of the "infected" message.
On Linux servers ClamAV can be run in daemon mode, servicing requests to scan files sent from other processes. These can include mail exchange programs, files on Samba shares, or packets of data passing through a proxy server (IPCop, for example, has an add-on called Copfilter which scans incoming packets for malicious data).
On Linux and BSD desktops ClamAV provides on-demand scanning of individual files, directories or the whole PC.
Mac OS X
Apple Mac OS X Server has included ClamAV since version 10.4. It is used within the operating system's email service. A graphical user interface is available in the form of ClamXav. Additionally, Fink, Homebrew and MacPorts have ported ClamAV to the platform too. It is also available in the Mac App Store as a free download.
Another program which uses the ClamAV engine, on Mac OS X, is Counteragent. Working alongside the Eudora Internet Mail Server program, Counteragent scans emails for viruses using ClamAV and also optionally provides spam filtering through SpamAssassin.
ClamAV for OpenVMS is available for DEC Alpha and Itanium platforms. The build process is simple and provides basic functionality, including: library, clamscan utility, clamd daemon and freshclam for update.
ClamAV for Windows is now a part of the Immunet client produced by Sourcefire.
ClamAV for eComStation (OS/2) is available from OS/2 Power Wiki. "The main purpose of this software is the integration with mail servers (attachment scanning). The package provides a flexible and scalable multi-threaded daemon, a command line scanner, and a tool for automatic updating via Internet. The programs are based on a shared library distributed with the Clam AntiVirus package, which you can use with your own software. Most importantly, the virus database is kept up to date."
Since ClamAV does not include a graphical user interface (GUI) but instead is run from the command line, a number of third-party developers have written GUIs for the application for various platforms and uses.
- Mac OS X
- ClamXav is a freeware port which includes a graphical user interfaces and has a "sentry" service which can watch for changes or new files in many cases. There is also an update and scanning scheduler through a cron job facilitated by the graphical interface. ClamXav can detect malware specific to Mac OS X, Unix, or Windows. The ClamXav application and the ClamAV engine, are updated regularly.
- Tiger Cache Cleaner is shareware software which installs and presents a graphic interface for using ClamAV to scan for viruses, and provides other unrelated functions.
- Microsoft Windows
ClamWin is a graphical user interface front end for ClamAV for Microsoft Windows built by ClamWin Pty Ltd. Features include on-demand (user started) scanning, automatic updates, scan scheduling, context menu integration to Explorer, and an add-in for Microsoft Outlook. ClamWin does not provide on-access scanning, additional software must be used.
Plugins for Mozilla Firefox which use ClamWin to scan downloaded files are also available. Several other extensions allow users to process downloaded files with any software and scan the files with ClamWin.
Clam Sentinel  is a free software system tray application that detects file system changes and scans the files modified using ClamWin in real-time. It works with Windows 98/98SE/ME/XP/Vista/7/8. Its features a real-time scanner for ClamWin, optional system change messages and proactive heuristic protection.
Real-time file scanning
ClamAV is not a real-time virus scanner (does not scan when a file is read or written), but can be used with other applications such as ClamFS (for any Unix-like operating system supporting FUSE), DazukoFS (for Linux), Clam Sentinel and Winpooch (both for Windows) to provide real-time checks.
|This section is outdated. (August 2014)|
In 2008, Barracuda Networks was sued by Trend Micro for its distribution of ClamAV as part of a security package. Trend Micro claimed that Barracuda's utilization of ClamAV infringes on a software patent for filtering viruses on an Internet gateway. The free software community has responded in part by calling for a boycott against Trend Micro. The boycott has been endorsed by the Free Software Foundation. Barracuda Networks counter-sued with IBM obtained patents in July 2008.
- ClamAV (2007). "About ClamAV". Retrieved 2008-12-25.
- ClamAV (2007). "ClamAV Packages and Ports". Retrieved 2008-12-31.
- "Sourcefire acquires ClamAV". ClamAV. 2007-09-17. Retrieved 2008-02-12.
- "Cisco Completes Acquisition of Sourcefire". cisco.com. 2013-10-07. Retrieved 2014-06-18.
- ClamAV (August 2010). "Latest Stable Release". Retrieved 2010-08-21.
- "ShadowServer Yearly Stats". www.shadowserver.org. 2012-01-05. Retrieved 2012-01-05.
- "Anti-virus comparison test of current anti-malware products, Q1/2008". AV-Test GmbH. 22 January 2008. Archived from the original on 15 July 2011. Retrieved 12 February 2008.
- "ShadowServer 180 Day Stats". www.shadowserver.org. 2011-08-16. Retrieved 2011-12-16.
- Brad Wardman; Tommy Stallings; Gary Warner; Anthony Skjellum (5 August 2011). "High-Performance Content-Based Phishing Attack Detection". uab.edu. Retrieved 2 September 2014.
- Sanesecurity Phishing, Scam and Malware signatures for ClamAV
- "ClamAV Unofficial Signatures Updater". sourceforge.net. 24 May 2009. Retrieved 2 September 2014.
- ClamXav.com (n.d.). "ClamXAV.com". Retrieved 2009-01-24.
- Chupahin, Alexey (December 2008). "Clam AntiVirus OpenVMS Project News". Retrieved 2008-12-25.
- Mauroni, Dave (December 2008). "ClamTk Virus Scanner". Retrieved 2008-12-25.
- Mauroni, Dave (October 2008). "ClamTk README". Retrieved 2008-12-26.
- KlamAV F. (May 2006). "KlamAV - Main Page". Retrieved 2013-03-04.
- "wbmclamav project".
- ClamXav.com (November 2008). "ClamXav.com". Retrieved 2008-12-25.
- "CS Anti-Virus description". Softpedia.com. 2009-03-23. Retrieved 2010-11-09.
- "FireClam: Use ClamAV to scan Firefox downloads for viruses". Firefox Addons. Retrieved 2009-11-02.
- "ClamWin Antivirus Glue for Firefox". Firefox Addons. Retrieved 2008-04-15.[dead link]
- "Download Scan". Downloadstatusbar.mozdev.org. 2005-08-19. Retrieved 2010-11-09.
- Download Statusbar
- "Safe Download". Extensions.geckozone.org. Retrieved 2010-11-09.
- ClamWin Pty Ltd (2009). "About ClamWin Free Antivirus". Retrieved 2009-03-13.
- Clam Sentinel (2014-09-01). "Clam Sentinel - Free Realtime Antivirus".
- Cyber Pillar. "Clam Sentinel - Making ClamWin Be Used In Real-Time". Retrieved 2014-09-01.
- "Clam Sentinel". Retrieved 2014-06-19.
- "Winpooch". Retrieved 2014-06-19.
- "Trend Micro patent claim provokes FOSS community, leads to boycott". Linux.com. 2008-02-11. Retrieved 2008-02-12.
- "Boycott Trend Micro". Free Software Foundation. 2008-02-11. Retrieved 2008-02-12.
- Paul, Ryan (2008-07-02). "Barracuda bites back at Trend Micro in ClamAV patent lawsuit". Arstechnica.com. Retrieved 2012-02-14.
- An interview with ClamAV founder Tomasz Kojm archived version
|Wikimedia Commons has media related to ClamAV.|