TweakUI/subwoofer virus??

F

Fred Ma

Hi,

I have Spybot installed. It has a tool that enables/disables apps
from launching at system startup (like msconfig, but it seems to show
more items ie. some of which don't show up in msconfig). One such
item is TweakUI. Under the "Command line" column, it says
"RUNDLL32.EXE TWEAKUI.CPL TweakMeUp". If I select it, the following
information is shown.

| Current filename:
| RUNDLL32.EXE TWEAKUI.CPL,TweakMeUp
|
| Database status:
| Necessity depends on users preferences
| Value:
| Tweak UI
| Filename:
| rundll32.exe tweakui.cpl, tweakmeup
|
| Description
| Restores settings that can't be retained if you have Microsoft's Tweak UI "powertoy" installed
|
| Source:
| Paul Collins Startup list
| ____________________
|
| Current filename:
| RUNDLL32.EXE TWEAKUI.CPL,TweakMeUp
|
| Database status:
| Necessity depends on users preferences
| Value:
| Tweak UI
| Filename:
| rundll32.exe tweakui.cpl, tweaklogon
|
| Description
| Automatically logs you on if you have Microsoft's Tweak UI "powertoy" installed
|
| Source:
| Paul Collins Startup list
| ____________________
|
| Current filename:
| RUNDLL32.EXE TWEAKUI.CPL,TweakMeUp
|
| Database status:
| Necessity depends on users preferences
| Value:
| Tweak UI
| Filename:
| RunDLL32 tweakUI.DLL, TWEAKUI /tweakmeup
|
| Description
| Added as a result of the _ SUBWOOFER_ VIRUS! Note - the real Tweak UI entry for this is "rundll32.exe tweakui.cpl, tweakmeup"
|
| Source:
| Paul Collins Startup list

From the last few lines, I'm surprised that I am infected, since I
ordinarily have Norton AV updated and autoprotect running. I also
have Kerio firewall running with pretty restrictive settings. I tried
uninstalling TweakUI (there is no such process in the taskbar), but
"Add/Remove Programs" says that there were errors in the uninstall,
and asks whether I want to remove it from the list (of programs in
Add/Remove Programs). I say no. The TweakUI icon still appears on
the control panel.

There are very few hits under a Google Groups search for "tweakui
subwoofer virus" (without quotes), and nothing illuminating. Under a
plain Google search, there is a symantec posting from 2002 about this:
http://securityresponse.symantec.com/avcenter/venc/data/backdoor.subwoofer.html.
I am scanning my system as I type (it takes *forever*), and I am also
suppose to edit the registry (I hate doing that because of the
perils). The scan is for *all* files (I just finished a scan which
defaulted to just program and document files, and nothing came up).
A scan of the TweakUI download (tweakui.zip) also came up empty.

Is there any chance that this is a mistake? I don't visit lurid
websites, and I don't receive email on the PC. I wonder if it is a
false positive.

Fred

P.S. I've crossposted this to grc.security, alt.comp.virus, and
alt.comp.antivirus. I will manually keep the thread from fragmenting.
 
F

Fred Ma

+| Current filename:
| RUNDLL32.EXE TWEAKUI.CPL,TweakMeUp
|
| Database status:
| Necessity depends on users preferences
| Value:
| Tweak UI
+| Filename:
| RunDLL32 tweakUI.DLL, TWEAKUI /tweakmeup
|
| Description
-| Added as a result of the _ SUBWOOFER_ VIRUS! Note - the real Tweak UI entry for this is "rundll32.exe tweakui.cpl, tweakmeup"
|
| Source:
| Paul Collins Startup list

Just a followup to my posting...
Regarding the "+" lines in the Spybot info above, I am assuming that
"Current filename:" describes the actual case on my PC, and
"Filename:" is just describes the virus in the database. Note that
the "Current filename:" matches the "real Tweak UI entry" on the "-"
line above. This is also what shows up in the "Command line" field in
the Spybot tool for System Startup applications.

Another thing which makes me think that this is a wild goose chase is
that not all the registry entries are as described in Symantec's
posting for the Subwoofer virus. The registry fix is described as:

| Navigate to...
|
| HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Run
|
| ...delete the value
|
1| Tweak UI "RunDLL32 tweakUI.DLL, TWEAKUI /tweakmeup"
|
| Navigate to...
|
| HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\RunServices
|
| ...delete the value
|
2| Scheduling Agent "Scheduler.exe"

The key "1" above matches the "Filename:" field in the above Spybot
info, but my registry entry matches the "Current Filename:" field. As
well, I do not ahve a key "2" as shown above. Finally, the rigorous
AV scan (all files, not just programs and documents) comes up empty.

So the only curiosity is why I have a key "1" at all, considering that
I tried to remove TweakUI. As well, it is odd that it shows up in
Spybot's tool for System Startup. I guess I will tempt fate and
carefully remove that key.

Fred

P.S. I've crossposted this to grc.security, alt.comp.virus, and
alt.comp.antivirus. I will manually keep the thread from fragmenting.
 

Ask a Question

Want to reply to this thread or ask your own question?

You'll need to choose a username for the site, which only take a couple of moments. After that, you can post your question and our members will help you out.

Ask a Question

Top