# Scanning for malware with Linux Malware Detect (LMD)

Category: [Dedicated servers / VPS](https://www.cloudvip.com/en/faq/dedicated-servers-vps.md)
Source page: [https://www.cloudvip.com/en/faq/dedicated-servers-vps/scanning-for-malware-with-linux-malware-detect-lmd](https://www.cloudvip.com/en/faq/dedicated-servers-vps/scanning-for-malware-with-linux-malware-detect-lmd)
Keywords: linux, malware, maldet, linux malware detect

Linux Malware Detect (LMD), also known as “Maldet”, is a malware scanner designed for Linux and released under the GNU GPLv2 licence. It is particularly effective at detecting PHP backdoors, bulk email generators and various other malicious files that may be uploaded to a compromised website. This software will help you identify infected websites and clean up the infection. However, you must still secure the compromised user account or website to prevent reinfection.

You must be connected to the server as the root user via SSH.

Step 1 – Install Maldet:

    cd /usr/local/src/ && wget http://www.rfxn.com/downloads/maldetect-current.tar.gz && tar -xzvf maldetect-current.tar.gz && cd maldetect-* && sh install.sh

This will automatically install a cron job in /etc/cron.daily/maldet. A scan will therefore run every day to detect local cPanel or Plesk accounts.

Step 2 – Update to the latest versions and virus signatures:

    maldet -d && maldet -u

Step 3 – Run the first scan manually.

To scan the user's home directory, run the following command:

    maldet -a /home/user

 

To run a background scan of the public_html and public_ftp folders in all user home directories, run the following command:

    maldet -b --scan-all /home?/?/public_?

 

(We also recommend scanning the /tmp and /dev/shm/ directories.)

Step 4 – Check the scan report.

We recommend always reading scan reports before quarantining files. This allows you to identify infected websites for further action.

To display the times and SCANIDs of all scan reports:

    maldet --report list

 

To display the details of a specific report:

    maldet --report SCANID

 

To display the details of all reports from the log file:

    grep "{scan}" /usr/local/maldetect/event_log

 

Step 5 – Quarantine malicious files.

Quarantine is disabled by default. You must start it manually:

    maldet -q SCANID

Step 6 (optional) – Automatically quarantine detected malware.

Review these configuration variables in /usr/local/maldetect/conf.maldet:

Variable     Value     Description

quar_hits     number    If the number is not 0, automatic quarantine is enabled.

Step 7 (optional) – Configure email alerts for scan reports.

Maldet can send you an email alert whenever malware is detected. Review these configuration variables in /usr/local/maldetect/conf.maldet:

Variable     Value     Description

email_alert     1 or 0     enables or disables email alerts

email_addr      email address      the email address for notifications must be enclosed in quotation marks: "myuser@mydomain.com"

For more information: /usr/local/maldetect/conf.maldet or https://www.rfxn.com/projects/linux-malware-detect/
