File shield not working in Big Sur

Hello,

I’ve tried Avast on 2 Macbook Airs (2017 & 2019 version) both installed with different Big Sur beta’s. I’ve tried the Eicar testfile on both machines. They don’t give a popup warning and let me open the file. When I do a manual scan, the files do get detected and identified as Eicar testfiles.

My conclusion is that file shield (realtime protection) doesn’t work on Big Sur. Am I correct…?

Thank you!

Hello,
while all the executable files are always scanned by our File Shield component, for non-executables a heuristic is used to determine whether the file should be scanned. This takes into consideration file content, file name, which process is executing it etc., and it is done to minimise performance impact.
Kind regards,
Ondrej Kolacek

Hello Ondrej,

I even tried it with a legitimate keylogger → blazingtools.com → Perfect Keylogger for MAC. It doesn’t get detected by the File Shield and even let me install it, but it does get detected by the manual scan.

So I assume that de realtime protection is not working in Big Sur Beta… Can you confirm this…?

Thank you!

Hello,

Few days ago we have released a repack of 14.8 with several bugfixes; it contains a bug that for some users causes File Shield to not work on Big Sur. We are investigating how this could have gotten through our Quality Assurance, as this should have been caught by our automated test suite that has been run on the build prior of the release. Unfortunately our ongoing tests have already been switched to the new Avast 14.9 in the meantime…

Please update Avast AV immediately (eg. in menu select Avast Antivirus → Check for updates); Avast 14.9 should be working normally.

Thanks a lot for reporting this; we are very sorry that something like this could have happened. The issue been caused by improperly freezing one of the components’ version in the 14.8 branch; thus the rebuild used a wrong version of the component which in some cases does not work correctly.

We will push the fix out to everyone ASAP.

Kind regards,
Ondrej Kolacek

Everything works as expected in 14.9. It even detects the EICAR-testfile. Thank you :slight_smile: