What Maldet is and why you might install it
Maldet (short for Malware Detect) is a Linux malware scanner that runs from the command line. It searches your system for known malware signatures and suspicious file patterns, then quarantines or removes what it finds. Unlike graphical antivirus programs, Maldet works in the background and uses minimal system resources, making it practical for servers and older machines.
Maldet is free and open-source. It does not require a paid subscription, though it does need periodic signature updates to recognize new threats. On Linux Mint, you install it once and then run scans manually or set them to run on a schedule.
The trade-off is that Maldet requires comfort with the terminal. If you prefer a graphical interface, Linux Mint also includes ClamAV (another free scanner with a GUI called ClamTk), but Maldet is lighter and faster for most users.
Key Takeaways
- Maldet installs from the terminal using wget to download the installer, then running the setup script with sudo permissions.
- After installation, you must update the malware signatures before your first scan, using the command sudo maldet -u.
- Run a full system scan with sudo maldet -a /, which takes 10 to 30 minutes depending on your disk size and speed.
- Maldet stores quarantined files in /usr/local/maldetect/quarantine, where you can review or permanently delete them.
- You can schedule automatic scans using cron, though manual weekly or monthly scans are sufficient for most home users.
Download and install Maldet from the terminal
Open the terminal on your Linux Mint machine. Press Ctrl+Alt+T or click the terminal icon in your taskbar. Then download the latest Maldet installer by typing:
cd /tmp && wget https://www.rfxn.com/downloads/maldetect-latest.tar.gz
This command moves you to the temporary folder and downloads the compressed Maldet file. Once the download finishes, extract it:
tar -xzf maldetect-latest.tar.gz
Then move into the extracted folder and run the installer:
cd maldetect-* && sudo ./install.sh
The system will ask for your password (the one you use to log into Linux Mint). Type it and press Enter. The installer creates the Maldet directory at /usr/local/maldetect and sets up the necessary files. Installation takes less than a minute.
Update malware signatures before your first scan
Maldet comes with older signature data. Before you run any scan, update the signatures to recognize current threats:
sudo maldet -u
This command downloads the latest malware definitions from the Maldet servers. The first update takes a few minutes and requires an internet connection. After this, you can set Maldet to update automatically once a week, or update manually before each scan.
To check that the update worked, type:
sudo maldet -v
This shows the current signature version and the date of the last update. If you see a recent date, you are ready to scan.
Run your first scan
A full system scan checks every file on your computer. Start with:
sudo maldet -a /
The forward slash tells Maldet to scan from the root directory downward, covering your entire system. On a typical Linux Mint installation with 100 GB of data, this takes 15 to 30 minutes. Maldet prints progress to the terminal as it works.
If you want to scan only your home folder (faster, but less thorough), use:
sudo maldet -a /home
When the scan finishes, Maldet displays a summary: the number of files scanned, the scan time, and any threats found. If threats are detected, Maldet shows their file paths and suggests actions.
Quarantine or remove detected threats
When Maldet finds malware, it does not delete it automatically. Instead, it moves the file to quarantine — a separate folder where it cannot run. To quarantine all detected threats from your last scan, type:
sudo maldet -q SCANID
Replace SCANID with the scan number shown in your scan results (for example, sudo maldet -q 210924-1847.15342). Quarantined files go to /usr/local/maldetect/quarantine.
To permanently delete quarantined files instead of keeping them, use:
sudo maldet -p SCANID
Only delete files if you are certain they are malware. If you are unsure, leave them quarantined and research the filename first.
Schedule regular scans with cron
Running scans manually works fine, but you can automate them using cron, a Linux scheduler. Open the cron editor:
sudo crontab -e
Choose a text editor (nano is simplest if you have not used this before). Add a line like:
0 2 * * 0 /usr/local/maldetect/maldet -a /home
This runs a scan of your home folder every Sunday at 2 AM. The five numbers represent minute, hour, day of month, month, and day of week. Change the time or path to match your preference. Save and exit (in nano, press Ctrl+X, then Y, then Enter).
Cron scans run in the background, so you do not need to be at your computer. Maldet logs the results to /usr/local/maldetect/logs, where you can review them later.
Check scan results and logs
After each scan, Maldet creates a log file with the results. View recent scans:
sudo maldet -l
This lists all scans with their IDs and dates. To see the full details of a specific scan, type:
sudo maldet -r SCANID
The report shows every file scanned, detection counts, and what action was taken. Logs are stored in /usr/local/maldetect/logs if you want to read them directly in a text editor.
Keep logs for at least a few months so you can track whether threats are recurring or new. If the same malware appears in multiple scans, it may indicate a persistent infection or a vulnerable application that needs updating.
Frequently Asked Questions
Do I need to uninstall other antivirus software before installing Maldet?
No. Maldet works alongside other security tools. However, running two real-time scanners at the same time can slow your system. If you have ClamAV or another active scanner running, you can disable it or let Maldet handle scheduled scans while the other tool runs on-demand.
What should I do if Maldet finds a false positive?
A false positive is a legitimate file that Maldet flags as malware. If you recognize the file and trust its source, do not quarantine it. You can also add the file path to Maldet's whitelist at /usr/local/maldetect/ignore_paths to prevent future alerts. Open the file in a text editor and add the path on a new line.
Can I scan an external drive or USB stick with Maldet?
Yes. Plug in the drive, find its mount point (usually /media/username/drivename), then scan it with sudo maldet -a /media/username/drivename. This is useful for checking removable media before transferring files to your main system.
How often should I update Maldet signatures?
Weekly updates are standard and catch most new threats. If you want more frequent updates, you can set cron to update daily with 0 3 * * * /usr/local/maldetect/maldet -u. For most home users, weekly is sufficient.
What if Maldet stops working or gives errors?
First, check that your signatures are current with sudo maldet -u. If you see permission errors, make sure you are using sudo before each command. If Maldet will not start, reinstall it by downloading the latest version and running the installer again. The new installation overwrites the old one without losing your scan history.