Author Topic: sig.tmp files in C:/WINDOWS/Temp folder - what is that?  (Read 70568 times)

0 Members and 1 Guest are viewing this topic.

Offline Asyn

  • Avast Überevangelist
  • Certainly Bot
  • *****
  • Posts: 76037
    • >>>  Avast Forum - Deutschsprachiger Bereich  <<<
Re: sig.tmp files in C:/WINDOWS/Temp folder - what is that?
« Reply #30 on: October 22, 2011, 10:19:59 AM »
EDIT: it seems that sigN.tmp files are created 8 minutes after system boot (or perhaps after Avast! is started).

Hmm... avast runs a rootkit scan 8 minutes after start.
W8.1 [x64] - Avast Free AV 23.3.8047.BC [UI.757] - Firefox ESR 102.9 [NS/uBO/PB] - Thunderbird 102.9.1
Avast-Tools: Secure Browser 109.0 - Cleanup 23.1 - SecureLine 5.18 - DriverUpdater 23.1 - CCleaner 6.01
Avast Wissenswertes (Downloads, Anleitungen & Infos): https://forum.avast.com/index.php?topic=60523.0

Tetsuo

  • Guest
Re: sig.tmp files in C:/WINDOWS/Temp folder - what is that?
« Reply #31 on: October 22, 2011, 10:24:00 AM »
Hmm... avast runs a rootkit scan 8 minutes after start.

Asyn, could you please check when those files are created on your system? e.g. 8 minutes after system boot etc.

Offline Asyn

  • Avast Überevangelist
  • Certainly Bot
  • *****
  • Posts: 76037
    • >>>  Avast Forum - Deutschsprachiger Bereich  <<<
Re: sig.tmp files in C:/WINDOWS/Temp folder - what is that?
« Reply #32 on: October 22, 2011, 10:27:40 AM »
Hmm... avast runs a rootkit scan 8 minutes after start.

Asyn, could you please check when those files are created on your system? e.g. 8 minutes after system boot etc.

I'm away in a few minutes, but will check it later today.
W8.1 [x64] - Avast Free AV 23.3.8047.BC [UI.757] - Firefox ESR 102.9 [NS/uBO/PB] - Thunderbird 102.9.1
Avast-Tools: Secure Browser 109.0 - Cleanup 23.1 - SecureLine 5.18 - DriverUpdater 23.1 - CCleaner 6.01
Avast Wissenswertes (Downloads, Anleitungen & Infos): https://forum.avast.com/index.php?topic=60523.0

Tetsuo

  • Guest
Re: sig.tmp files in C:/WINDOWS/Temp folder - what is that?
« Reply #33 on: October 22, 2011, 01:05:10 PM »
I'm away in a few minutes, but will check it later today.

Thank you, Asyn.

Anyway, I was wondering if this thread shouldn't be moved in the avast! Free/Pro/Suite section  (http://forum.avast.com/index.php?board=2.0section) so maybe it could be more easily noticed by devs...

Offline DavidR

  • Avast Überevangelist
  • Certainly Bot
  • *****
  • Posts: 89034
  • No support PMs thanks
Re: sig.tmp files in C:/WINDOWS/Temp folder - what is that?
« Reply #34 on: October 22, 2011, 01:46:39 PM »
If this is happening about 8 minutes after boot, then given that it appears to be related to avastSvc.exe (FlyingRobot's image), then this could be the anti-rootkit scan (presumably controlled by the avastSvc.exe), which happens at about that time.

I found the sig*.tmp files yesterday after this topic and deleted all of them. This morning after seeing the additional posts I checked and I have a number of them again, and it would appear they were created about 8 minutes after boot (see image). The WGAErrLog.txt file date modified time would be around boot time, so the first sig7.tmp file creation was 8 minutes after that.

So I'm going to test for that and disable the anti-rootkit scan and check after a reboot if they are created.
Windows 10 Home 64bit/ Acer Aspire F15/ Intel Core i5 7200U 2.5GHz, 8GB DDR4 memory, 256GB SSD, 1TB HDD/ avast! free 24.3.6108 (build 24.3.8975.762) UI 1.0.801/ Firefox, uBlock Origin, uMatrix/ MailWasher Pro/ Avast! Mobile Security

Offline DavidR

  • Avast Überevangelist
  • Certainly Bot
  • *****
  • Posts: 89034
  • No support PMs thanks
Re: sig.tmp files in C:/WINDOWS/Temp folder - what is that?
« Reply #35 on: October 22, 2011, 02:16:41 PM »
OK, test complete, this is related to the avast anti-rootkit scan.

Deleted old sig*.tmp files, stopped the anti-rootkit scan on system startup, image1. Rebooted and boot started at roughly 12:50 to 12:51, WGAErrLog.txt Date modified time is now 22/10/11 12:50. So I wait well over 8 minutes 13 in fact and check the c:\windows\temp folder and no new sig*.tmp files, image2.

So something has changed or broken in the anti-rootkit scan. Why this anti-rootkit scan function doesn't send the files to the avast temp folder c:\windows\temp\_avast_ folder; or if sending to a different folder why it doesn't clean up after it has completed the scan as the other avast scans do I don't know.

Since as has been reported this appears to have started on or about the 18th October 2011, what changed or broke in the anti-rootkit scan at that time.

What to do: I wouldn't disable the anti-rootkit scan too valuable a resource. I would recommend you do as I do as part of my regular weekly system maintenance and that is to run CCleaner to clean temp files. This tool isn't too aggressive so it shouldn't dispose of temp files that may be in use.
Windows 10 Home 64bit/ Acer Aspire F15/ Intel Core i5 7200U 2.5GHz, 8GB DDR4 memory, 256GB SSD, 1TB HDD/ avast! free 24.3.6108 (build 24.3.8975.762) UI 1.0.801/ Firefox, uBlock Origin, uMatrix/ MailWasher Pro/ Avast! Mobile Security

Tetsuo

  • Guest
Re: sig.tmp files in C:/WINDOWS/Temp folder - what is that?
« Reply #36 on: October 22, 2011, 02:25:42 PM »
DavidR, do you know a quick way to let the devs know about this issue?

Offline DavidR

  • Avast Überevangelist
  • Certainly Bot
  • *****
  • Posts: 89034
  • No support PMs thanks
Re: sig.tmp files in C:/WINDOWS/Temp folder - what is that?
« Reply #37 on: October 22, 2011, 02:36:35 PM »
Not really, I'm just an avast user like yourself, but I will try.
Windows 10 Home 64bit/ Acer Aspire F15/ Intel Core i5 7200U 2.5GHz, 8GB DDR4 memory, 256GB SSD, 1TB HDD/ avast! free 24.3.6108 (build 24.3.8975.762) UI 1.0.801/ Firefox, uBlock Origin, uMatrix/ MailWasher Pro/ Avast! Mobile Security

alpha1

  • Guest
Re: sig.tmp files in C:/WINDOWS/Temp folder - what is that?
« Reply #38 on: October 22, 2011, 03:55:14 PM »
Not really, I'm just an avast user like yourself, but I will try.

dont be so modest dave.  ;)

Offline Asyn

  • Avast Überevangelist
  • Certainly Bot
  • *****
  • Posts: 76037
    • >>>  Avast Forum - Deutschsprachiger Bereich  <<<
Re: sig.tmp files in C:/WINDOWS/Temp folder - what is that?
« Reply #39 on: October 22, 2011, 04:25:49 PM »
I'm away in a few minutes, but will check it later today.

Thank you, Asyn.

Ok, I confirm the 8 minute delay and therefore the relation to the rootkit scan.

What to do: I wouldn't disable the anti-rootkit scan too valuable a resource.

Agree with you Dave.

This seems to be a newly introduced bug, but a VPS update should be able to fix this.
I'm still interested how afd.sys is related to a rootkit scan...!!?? ;)
W8.1 [x64] - Avast Free AV 23.3.8047.BC [UI.757] - Firefox ESR 102.9 [NS/uBO/PB] - Thunderbird 102.9.1
Avast-Tools: Secure Browser 109.0 - Cleanup 23.1 - SecureLine 5.18 - DriverUpdater 23.1 - CCleaner 6.01
Avast Wissenswertes (Downloads, Anleitungen & Infos): https://forum.avast.com/index.php?topic=60523.0

Offline DavidR

  • Avast Überevangelist
  • Certainly Bot
  • *****
  • Posts: 89034
  • No support PMs thanks
Re: sig.tmp files in C:/WINDOWS/Temp folder - what is that?
« Reply #40 on: October 22, 2011, 04:55:52 PM »
<snip>
I'm still interested how afd.sys is related to a rootkit scan...!!?? ;)

I'm not convinced that it is connected, just that it happened to be in the temp folder when you did your checking. If it were connected to the rootkit scan, then I guess after I clered the temp folder and the next day after boot there were some sig*.tmp files there but no afd.sys file as in the image in Reply #34 above and I can't recall having seen that file in temp (not that I go looking in temp often).

Windows 10 Home 64bit/ Acer Aspire F15/ Intel Core i5 7200U 2.5GHz, 8GB DDR4 memory, 256GB SSD, 1TB HDD/ avast! free 24.3.6108 (build 24.3.8975.762) UI 1.0.801/ Firefox, uBlock Origin, uMatrix/ MailWasher Pro/ Avast! Mobile Security

Offline Asyn

  • Avast Überevangelist
  • Certainly Bot
  • *****
  • Posts: 76037
    • >>>  Avast Forum - Deutschsprachiger Bereich  <<<
Re: sig.tmp files in C:/WINDOWS/Temp folder - what is that?
« Reply #41 on: October 22, 2011, 05:07:21 PM »
I'm not convinced that it is connected, just that it happened to be in the temp folder when you did your checking. If it were connected to the rootkit scan, then I guess after I clered the temp folder and the next day after boot there were some sig*.tmp files there but no afd.sys file as in the image in Reply #34 above and I can't recall having seen that file in temp (not that I go looking in temp often).

Seems I wasn't clear enough. ;)
Ok, I try again...
There are several empty files and one file with the size of 136Kb for each day/reboot.
The 136Kb file is a copy of afd.sys (See Reply #27 & #29)
It's not named afd.sys though.
Hope you understand what I mean now.
W8.1 [x64] - Avast Free AV 23.3.8047.BC [UI.757] - Firefox ESR 102.9 [NS/uBO/PB] - Thunderbird 102.9.1
Avast-Tools: Secure Browser 109.0 - Cleanup 23.1 - SecureLine 5.18 - DriverUpdater 23.1 - CCleaner 6.01
Avast Wissenswertes (Downloads, Anleitungen & Infos): https://forum.avast.com/index.php?topic=60523.0

Offline DavidR

  • Avast Überevangelist
  • Certainly Bot
  • *****
  • Posts: 89034
  • No support PMs thanks
Re: sig.tmp files in C:/WINDOWS/Temp folder - what is that?
« Reply #42 on: October 22, 2011, 05:26:37 PM »
Well that could have been the analysis of that file by the anti-rootkit scan as in the First post example of the contents of one of the files viewed in a text editor.
Windows 10 Home 64bit/ Acer Aspire F15/ Intel Core i5 7200U 2.5GHz, 8GB DDR4 memory, 256GB SSD, 1TB HDD/ avast! free 24.3.6108 (build 24.3.8975.762) UI 1.0.801/ Firefox, uBlock Origin, uMatrix/ MailWasher Pro/ Avast! Mobile Security

Offline Asyn

  • Avast Überevangelist
  • Certainly Bot
  • *****
  • Posts: 76037
    • >>>  Avast Forum - Deutschsprachiger Bereich  <<<
Re: sig.tmp files in C:/WINDOWS/Temp folder - what is that?
« Reply #43 on: October 22, 2011, 06:09:02 PM »
Well that could have been the analysis of that file by the anti-rootkit scan as in the First post example of the contents of one of the files viewed in a text editor.

No, it's not an analysis of the file, it's a copy of the file (afd.sys) itself.
But with a name like sig*.tmp
W8.1 [x64] - Avast Free AV 23.3.8047.BC [UI.757] - Firefox ESR 102.9 [NS/uBO/PB] - Thunderbird 102.9.1
Avast-Tools: Secure Browser 109.0 - Cleanup 23.1 - SecureLine 5.18 - DriverUpdater 23.1 - CCleaner 6.01
Avast Wissenswertes (Downloads, Anleitungen & Infos): https://forum.avast.com/index.php?topic=60523.0

Offline DavidR

  • Avast Überevangelist
  • Certainly Bot
  • *****
  • Posts: 89034
  • No support PMs thanks
Re: sig.tmp files in C:/WINDOWS/Temp folder - what is that?
« Reply #44 on: October 22, 2011, 06:16:54 PM »
But that doesn't change the overall context of my answer, it is being analysed and that may require making a copy to work with. So it is still the same association, it is being scanned by the anti-rootkit scan not used by it as such.
Windows 10 Home 64bit/ Acer Aspire F15/ Intel Core i5 7200U 2.5GHz, 8GB DDR4 memory, 256GB SSD, 1TB HDD/ avast! free 24.3.6108 (build 24.3.8975.762) UI 1.0.801/ Firefox, uBlock Origin, uMatrix/ MailWasher Pro/ Avast! Mobile Security