I have also re-checked with Avast, and double-checked the actual file that is provided for download at the Sonic Visualiser download page, and have continued to find nothing wrong. Builds are carried out on a virtual machine dedicated to the task, which I would have expected to be clean.
I then tested with Panda to see whether I got the same result as you, and I found that I did -- it gives me the same report for the Sonic Visualiser 2.4.1 executable. I believe it is simply mistaken, but it's not clear to me how I could prove that.
Chris