Author Topic: RK x64 Report: SYNCENG.dll is rootkit?  (Read 5158 times)

0 Members and 1 Guest are viewing this topic.

June 06, 2014, 08:08:56 AM

derek123456789

  • Newbie

  • Offline
  • *

  • 5
  • Reputation:
    0
    • View Profile
RK x64 Report: SYNCENG.dll is rootkit?
« on: June 06, 2014, 08:08:56 AM »
Hi - I ran RogueKiller x64 and it found Antirootkit the .dll referenced in the subject,,,I thought I had deleted it, but it came up again.  I downloaded TDSS Killer after this to see what it found, and it did not find any rootkits.

Please see report and advise what I should do.

Thanks very much.

RogueKiller V9.0.2.0 (x64) [Jun  3 2014] by Adlice Software
mail : http://www.adlice.com/contact/
Feedback : http://forum.adlice.com
Website : http://www.adlice.com/softwares/roguekiller/
Blog : http://www.adlice.com

Operating System : Windows 7 (6.1.7601 Service Pack 1) 64 bits version
Started in : Normal mode
User : D [Admin rights]
Mode : Scan -- Date : 06/06/2014  01:48:48

¤¤¤ Bad processes : 0 ¤¤¤

¤¤¤ Registry Entries : 0 ¤¤¤

¤¤¤ Scheduled tasks : 0 ¤¤¤

¤¤¤ Files : 0 ¤¤¤

¤¤¤ HOSTS File : 1 ¤¤¤
[C:\Windows\System32\drivers\etc\hosts] 127.0.0.1       localhost

¤¤¤ Antirootkit : 1 ¤¤¤
[EAT:Addr] (explorer.exe) SYNCENG.dll - DoCmd : C:\Windows\System32\framedynos.dll @ 0x7feed1ef5f8

¤¤¤ Web browsers : 0 ¤¤¤

¤¤¤ MBR Check : ¤¤¤
+++++ PhysicalDrive0: SAMSUNG HD501LJ +++++
--- User ---
[MBR] 8f8f368c032163e555f43f59bba7930f
[BSP] ceb84c3e7b096f62a58a22cb4210973b : Windows Vista/7/8 MBR Code
Partition table:
0 - [ACTIVE] NTFS (0x7) [VISIBLE] Offset (sectors): 63 | Size: 467469 MB
2 - [XXXXXX] NTFS (0x7) [VISIBLE] Offset (sectors): 957377610 | Size: 9467 MB
User = LL1 ... OK
User != LL2 ... KO!
--- LL2 ---
[MBR] 88e42e907aec80f2e3f36dffeac43632
[BSP] 096ca65415799301792a33c93b5e78da : Windows XP MBR Code
Partition table:

+++++ PhysicalDrive1: WD My Passport 0748 USB Device +++++
--- User ---
[MBR] 8752273f349251cedf7c6209cdd11aac
[BSP] 804dbf71ce7b1f906f09fbead2fc17a2 : Windows XP MBR Code
Partition table:
0 - [XXXXXX] NTFS (0x7) [VISIBLE] Offset (sectors): 2048 | Size: 953836 MB
User = LL1 ... OK
Error reading LL2 MBR! ([32] The request is not supported. )

+++++ PhysicalDrive2: Generic USB SD Reader USB Device +++++
Error reading User MBR! ([15] The device is not ready. )
Error reading LL1 MBR! NOT VALID!
Error reading LL2 MBR! ([32] The request is not supported. )

+++++ PhysicalDrive3: Generic USB CF Reader USB Device +++++
Error reading User MBR! ([15] The device is not ready. )
Error reading LL1 MBR! NOT VALID!
Error reading LL2 MBR! ([32] The request is not supported. )

+++++ PhysicalDrive4: Generic USB SM Reader USB Device +++++
Error reading User MBR! ([15] The device is not ready. )
Error reading LL1 MBR! NOT VALID!
Error reading LL2 MBR! ([32] The request is not supported. )

+++++ PhysicalDrive5: Generic USB MS Reader USB Device +++++
Error reading User MBR! ([15] The device is not ready. )
Error reading LL1 MBR! NOT VALID!
Error reading LL2 MBR! ([32] The request is not supported. )

+++++ PhysicalDrive6: SanDisk Cruzer USB Device +++++
--- User ---
[MBR] 09f1580e0e705f4d9330806f0b520171
[BSP] df4f83c1f72e36823a12b0dfc7617313 : Unknown MBR Code
Partition table:
0 - [XXXXXX] FAT32-LBA (0xc) [VISIBLE] Offset (sectors): 32 | Size: 61050 MB
User = LL1 ... OK
Error reading LL2 MBR! ([32] The request is not supported. )


============================================
RKreport_DEL_06062014_002513.log - RKreport_SCN_06062014_002259.log - RKreport_SCN_06062014_005633.log - RKreport_SCN_06062014_005923.log

Reply #1June 06, 2014, 08:22:01 AM

Tigzy

  • Administrator
  • Hero Member

  • Offline
  • *****

  • 957
  • Reputation:
    91
  • Personal Text
    Owner, Adlice Software
    • View Profile
    • Adlice Software
Re: RK x64 Report: SYNCENG.dll is rootkit?
« Reply #1 on: June 06, 2014, 08:22:01 AM »
Hello
The DLL is legit, it will be whitelisted for next version.