I generally only fire up ClamXav if I have what them damned Yankees call "probable cause" - ie I know I've just done something dumb (usually my curiosity getting the better of me and then colliding with spazzy fingers).
I have the Sentry watching my downloads folder and will occasionally scan my mail folders to see who hasn't got properly configured servers (I trash most false negative spam once I have taught Mail.app about it, but occasionally my curiosity get the better of me) and once in a blue moon leave it scanning the whole system overnight.
There have been a couple of very well design phishing expeditions recently. One aping Skype immediately after the new Mac beta was announced, that I almost bit on (spotting the .ru domain just in time) and one, IIRC, Adobe, again straight after some hoo-ha or other.
Now that it has had decent UI attached to it, ClamXav also no longer requires a PhD in Advanced Geekery to get working. Which is nice.