ClamAV detected by avast! ???

This started on the 12th and is getting annoying.
Please Fix this detection. Thanks

It has been posted elsewhere, Igor says it is unencrypted in the memory and being detected by avast.
I’m not sure if they can correct the detection. Seems an incompatibility of two running antivirus, don’t you think?

Maybe ALWIL will work with ClamWin to fix this problem. :slight_smile:

ClamAv isn’t resident. It’s on demand only.
Something Alwil needs to correct. it started on the 12th so it’s something that was changed in avast!
The problem wasn’t there prior to that date.


I have Clam AV installed with Spyware Terminator but I am not having any problems with avast.


Nope, it’s ClamAV problem and I’m personally again doing anything on our side. It’s usual non-encrypted data in their database, and it started because either them or we added that particular detection in the db.

But the root of the problem is still in their inability to provide inspection-safe db.

If you don’t intend to do anything, at least let me j=know what to do on my side so it stops annoying me. Thanks.

Uninstall clamav?

There is nothing to stop you excluding the .clamtmp files in both Program Settings and Standard Shield, using the wild cards add this, C:*\clamav-*.clamtmp that would save a) entering the full path and b) take account of the no doubt changing file names (e.g. the string between the clamav- and the .clamtmp file type.

Though personally I would be looking at the same suggestion as kubecj.

Hi you all,

Have the same alert as bob3160, only this started to-day, took no action on getting this alert:
Sign of “JS:ScriptSH=inf (Trj]” has been found in “K:\ClamWinPortable\Data\db\clamav-425ba79fa75915476839999d53b0a2c8f.00000039c.clamptmp” file,
So for the mo I have excluded ClamWin\ClamWinPortable\Data\db*
and everything fine,

polonus

that really should be ?:\ClamWin\ClamWinPortable\Data\db* the ? which allows for the clamwin portable version USB not being allocated the same drive letter and you need to have the \ after db and before the wildcard.

I’m also not keen on excluding a whole folder as that could leave a small hole in your security, but to exclude only the troublesome file types within that folder, ?:\ClamWin\ClamWinPortable\Data\db*.clamtmp

Hi DavidR,

Well tried the download with your suggestion, and got a alert, made the precision as ClamWin\ClamWinPortable\Data\db*clamptmp and all is well,

polonus

If it is now working then I think you made a typo in your post, clamPtmp ?

I TOO AM HAVING THE SAME PROBLEM, AND IT’S SLOWING DOWN MY COMPUTER ABD FREEZING IT UP.

This is where this trogan horse is located, spyware has “removed” it from my computer 3 times… Everytime i run a new scan it pops back up on my computer? Please someone help me remove this. If i were to restore my computer to an earlier time will is rid my compuer of this? Thank you for anyone who can help.
This is where it’s located.

C:\DOCUME~1\COMPAQ~1\LOCALS~1\Temp\clamav-1c59e8bbc0e3be87438a54cad29e8900.00000fb0.clamtmp\daily.ndb

This indicates that you also have clamav installed and the problem is that clamav doesn’t encrypt its virus signatures, so avast is detecting them.

So I don’t know if you have somehow got clamav running resident (though I though it was only on-demand) and that would cause a slowness. Freezing could also be caused by conflict between two AVs.

Personally I would suggest that you uninstall clamav or exclude the files as mentioned in the above posts.

Actually it’s not ClamWin’s problem at all, it’s a clear case of yet another ‘FALSE’ Positive made by Avast, which is why most of us have ClamWin installed in the first place!

A simple fix that has already been outlined here is to simply add a wildcard exemption for ClamWin’s various folders. So why can’t Avast include these exemptions in their next update?

Hi trumpy81,

I have reported this issue also, when avast flagged this. I use ClamWin just to close the vulnerability window on machine and because it has another range of signatures as the run of the mill av-vendors.
I agree with you, ClamWin portable apps functioned fine upon my machine until avast started to interfere, I made an exclusion for these alerts and I do hope the issue can be settled with an upcoming update,

polonus

Detecting someone’s virus signatures is not a false positive; they are virus signatures, not just some random unrelated file.

And why can’t Clam do their homework and properly scramble their virus database?

How can it possibly be a false positive, when avast is alerting on finding a virus signature, that is after all what an antivirus is meant to do. Why clamav haven’t encrypted the signatures is beyond me as they must be aware that installed resident scanners will detect them.

There is no guarantee that clamav will always be installed in the same location, there is also nothing stopping clamav changing the file name format breaking any exclusion created. Personally I would be a bit pi**ed if the use of wildecard exclusions as without care that wildcard could leave a large hole in your security.

I also don’t see why avast should chase other AVs issues of not encrypting their signatures like panda and calmav, two that I know of with the possibility of there being more.

David,
The exclusion you posted some time back as a reply to my original request for help
has work without any problems or risk to my system.
I’m again happily using avast! and have ClamAV available as a second opinion when needed.
Thanks :slight_smile: