[GH-ISSUE #3745] Avast Antivirus stops ollama_llama_server.exe from being executed due to malware alert #48820

Closed
opened 2026-04-28 09:33:29 -05:00 by GiteaMirror · 6 comments
Owner

Originally created by @samyIO on GitHub (Apr 19, 2024).
Original GitHub issue: https://github.com/ollama/ollama/issues/3745

Originally assigned to: @dhiltgen on GitHub.

What is the issue?

Avast states that the behavioural signature of ollama_llama_server.exe is looking like IDP.generic virus.
Could you please disprove this? Ollama is unusable in my company with this signature

OS

Windows

GPU

Nvidia

CPU

Intel

Ollama version

0.1.32

Originally created by @samyIO on GitHub (Apr 19, 2024). Original GitHub issue: https://github.com/ollama/ollama/issues/3745 Originally assigned to: @dhiltgen on GitHub. ### What is the issue? Avast states that the behavioural signature of ollama_llama_server.exe is looking like IDP.generic virus. Could you please disprove this? Ollama is unusable in my company with this signature ### OS Windows ### GPU Nvidia ### CPU Intel ### Ollama version 0.1.32
GiteaMirror added the bugwindows labels 2026-04-28 09:33:34 -05:00
Author
Owner

@dhiltgen commented on GitHub (Apr 19, 2024):

I'm sorry you're hitting this.

I just double checked and these binaries in 0.1.32 are correctly signed. I uploaded the 5 different runners to Virus Total, which includes Avast, and they are all reported clean. This component is new (was not present as an executable in 0.1.31) so perhaps it takes a little time for the AV vendors to build up reputation data and trust it.

Are you still seeing the IDP.generic virus reported by Avast, or has this gone away now? If you're still seeing it, can you share more information from the tool?

<!-- gh-comment-id:2067282221 --> @dhiltgen commented on GitHub (Apr 19, 2024): I'm sorry you're hitting this. I just double checked and these binaries in 0.1.32 are correctly signed. I uploaded the 5 different runners to Virus Total, which includes Avast, and they are all reported clean. This component is new (was not present as an executable in 0.1.31) so perhaps it takes a little time for the AV vendors to build up reputation data and trust it. Are you still seeing the IDP.generic virus reported by Avast, or has this gone away now? If you're still seeing it, can you share more information from the tool?
Author
Owner

@samyIO commented on GitHub (Apr 20, 2024):

Hey,

thanks for responding so quickly.
I just tried it out again. Same behaviour.
i made a screenshot this time, maybe this helps.

olid

If i can support any further please dont hesitate to ask.

<!-- gh-comment-id:2067529704 --> @samyIO commented on GitHub (Apr 20, 2024): Hey, thanks for responding so quickly. I just tried it out again. Same behaviour. i made a screenshot this time, maybe this helps. ![olid](https://github.com/ollama/ollama/assets/65492678/b9638158-05e5-48b1-a377-91e086a1755f) If i can support any further please dont hesitate to ask.
Author
Owner

@AdamM68 commented on GitHub (Apr 23, 2024):

still the same problem : Avast is blocking as IDP.Generic

<!-- gh-comment-id:2071840198 --> @AdamM68 commented on GitHub (Apr 23, 2024): still the same problem : Avast is blocking as IDP.Generic
Author
Owner

@dhiltgen commented on GitHub (Apr 23, 2024):

I've submitted a false positive report to Avast. Looks like their turn-around is 48 hours, so hopefully this will be cleared up in a few days.

<!-- gh-comment-id:2072823524 --> @dhiltgen commented on GitHub (Apr 23, 2024): I've submitted a false positive report to Avast. Looks like their turn-around is 48 hours, so hopefully this will be cleared up in a few days.
Author
Owner

@samyIO commented on GitHub (Apr 24, 2024):

For me the problem is solved. Avast ignores it now like supposed.
Thank you for your time.

<!-- gh-comment-id:2073981959 --> @samyIO commented on GitHub (Apr 24, 2024): For me the problem is solved. Avast ignores it now like supposed. Thank you for your time.
Author
Owner

@docpainting commented on GitHub (Jan 23, 2025):

Took out my main computer last night after a heated back and forth block for block using windsurfs cascade. Ps its been a lot fun I'm new into the scene within two years of coding. I don't know if you guys have seen the movie zero cool but I swear I went back to 15 years old. They got my Google account hitting from a server through port after port. I have to Day 1 it now but the experience was good. They don't use ollama that you have on your computer they installed one called ollama app. . They use a neural network that's downloaded able off github I pulled a bunch of files with panda. I tried blocking they literally don't stop when you pull lan or wifi it's a server always this time it's rita server. So I pulled a ton of files with a USB I checked it with virus software and it's now in my laptop. I noticed a different powershell installed that's how I blocked them at the moment. I put the labtop in airplane mode. I noticed them taking over programs so even when you think your using command terminal it's their program. You have to stop it by adding a new account quickly and making it admin then deleting the accounts they create. They go straight for the throat trying to take you over through Microsoft. Fucking insane use your face recognition it works Everytime they will change your passwords.When they create z inside C you are close to where there literally living but everything is hidden. I hate being a rookie through this. I just don't know all the commands off the top of my head first kill was Linux.

<!-- gh-comment-id:2610993463 --> @docpainting commented on GitHub (Jan 23, 2025): Took out my main computer last night after a heated back and forth block for block using windsurfs cascade. Ps its been a lot fun I'm new into the scene within two years of coding. I don't know if you guys have seen the movie zero cool but I swear I went back to 15 years old. They got my Google account hitting from a server through port after port. I have to Day 1 it now but the experience was good. They don't use ollama that you have on your computer they installed one called ollama app. . They use a neural network that's downloaded able off github I pulled a bunch of files with panda. I tried blocking they literally don't stop when you pull lan or wifi it's a server always this time it's rita server. So I pulled a ton of files with a USB I checked it with virus software and it's now in my laptop. I noticed a different powershell installed that's how I blocked them at the moment. I put the labtop in airplane mode. I noticed them taking over programs so even when you think your using command terminal it's their program. You have to stop it by adding a new account quickly and making it admin then deleting the accounts they create. They go straight for the throat trying to take you over through Microsoft. Fucking insane use your face recognition it works Everytime they will change your passwords.When they create z inside C you are close to where there literally living but everything is hidden. I hate being a rookie through this. I just don't know all the commands off the top of my head first kill was Linux.
Sign in to join this conversation.
1 Participants
Notifications
Due Date
No due date set.
Dependencies

No dependencies set.

Reference: github-starred/ollama#48820