CPGuard Antivirus: How It Protects Hosting Servers from Viruses
CPGuard Antivirus combines ClamAV with additional detection engines to scan hosting files and email attachments for viruses.
Contents
What is CPGuard Antivirus?
CPGuard Antivirus is a server-level virus detection and removal module using ClamAV as its core engine, supplemented by additional signature databases. It detects viruses, worms, trojans, ransomware, and other malicious code hidden in hosting files or email attachments, working alongside the malware scanner with a specific focus on virus patterns.
- ClamAV engine with additional signature databases
- Detects viruses, worms, trojans, ransomware
- Scans both server files and email attachments
- Automatic virus signature updates daily
- Coordinates with malware scanner without overlap
What is ClamAV and Why Does CPGuard Use It?
ClamAV is the world's most widely used open-source antivirus engine for Linux servers — designed for lightweight operation, frequent updates, and fast scanning. CPGuard uses ClamAV as its core engine because of its large signature database, active maintenance community, and low server resource consumption — critical for shared hosting environments.
- Open-source, no additional license cost
- Large signature database with millions of known patterns
- Updated multiple times daily by the ClamAV community
- Low RAM/CPU consumption — ideal for shared hosting
- Industry standard for Linux server antivirus
Threat Types Detected by CPGuard Antivirus
Beyond classic viruses, CPGuard Antivirus detects a wide range of modern threats commonly found on web hosting servers.
- Virus / Worm: self-replicating code that spreads between files
- Trojan: programs that disguise dangerous payloads as legitimate software
- Ransomware: encrypts files and demands payment for decryption
- Cryptominer: steals CPU resources for cryptocurrency mining
- Backdoor: maintains persistent attacker access to the server
- Dropper: code that downloads and installs other malware
Email Attachment Scanning
CPGuard Antivirus works with the Email Security module to scan every attachment before it reaches mailboxes — detecting viruses in Office documents (macro viruses), PDFs, ZIP files, and other formats. Email is the primary ransomware delivery channel. Server-level scanning before delivery is more effective than user-side antivirus on individual PCs.
- Scans attachments before they reach mailboxes
- Detects macro viruses in Office documents
- Scans compressed archives (ZIP, RAR) for hidden malicious content
- Blocks dangerous file types before they reach recipients
Real-Time Scanning on File Upload
CPGuard performs real-time antivirus scanning when files are uploaded via FTP or DirectAdmin's File Manager — detecting viruses immediately on upload, before the file is ever executed. This minimises the time any malicious file can exist on the server before being caught and quarantined.
- Scans immediately on FTP upload
- Scans immediately on DirectAdmin File Manager upload
- Detects before first execution
- Automatic quarantine when a virus is detected
Virus Signature Updates
New viruses appear every day — outdated signatures quickly fall behind new threats. CPGuard automatically updates ClamAV virus signatures multiple times daily from the official ClamAV database and additional sources, keeping protection current without administrator intervention.
- Multiple ClamAV signature updates per day
- Pulls from official ClamAV database
- Supplements with additional security intelligence sources
- No manual update work required from administrators
Managing False Positives
Antivirus engines can produce false positives — particularly with files whose structure resembles viruses but are legitimate programs. CPGuard supports whitelisting files or directories that are incorrectly flagged, allowing administrators to manage exceptions without disabling scanning entirely.
- Whitelist files or directories that are incorrectly flagged
- Always verify suspected false positives before whitelisting
- Log all false positives for ongoing review
- Report confirmed false positives to the ClamAV community for correction
Choosing Hosting with Server-Level Antivirus
Server-level antivirus provides broader protection than client-side antivirus because it inspects files before any user can download them to a local device. AsiaGB.com provides hosting and VPS with server-level security, SSD storage, DirectAdmin, 24-hour Thai support, and 99% uptime.
- Server antivirus scans files before they reach any client device
- Protects all users who download files from the server
- Works alongside malware scanner for complementary coverage
- Ask your provider whether server-level antivirus is included