ClamWin Free Antivirus Forum Index
ClamWin Free Antivirus
Support and Discussion Forums
Reply to topic
heuristic database format

Joined: 13 Apr 2017
Posts: 3
Reply with quote
I would like to know if in the futur heuristic analysis would be used in ClamAV (or ClamWin) what would be the format of the database to find suspicious binaries ? or no one know and you will need to discuss about it ?

what is the format for other AV for their DB?
View user's profileSend private message

Joined: 09 Jul 2006
Posts: 4203
Location: USA
Reply with quote
Clam AV has not/does not discuss database formats, but you can look at samples of the various signature formats yourself. Do some searching on the web for "clam AV signatures" or something like that.

In my opinion, over the years, Clam AV has not shown any desire to use heuristic signatures. It would rather use file hashes and unique file strings. Even their bytecode signatures are not based on true heuristics, and there are not very many of them--it has been a long time since I saw a bytecode signature detect some malware.

Each AV has a different format (unless it uses another AV's engine-many AVs use Bitdefender's engine now). They all use file hashes for some of their signatures--maybe the majority.

View user's profileSend private message
heuristic database format
You cannot post new topics in this forum
You cannot reply to topics in this forum
You cannot edit your posts in this forum
You cannot delete your posts in this forum
You cannot vote in polls in this forum
All times are GMT  
Page 1 of 1  

 Reply to topic