| Windows 7: Niwus.exe is a virus or spyware? |
11 Feb 2010
|
#1 | | |
Niwus.exe is a virus or spyware? Hi everybody.....
When I start my laptop shown that niwus.exe want to connect internet, this program come from \program files\windows NT\, if I am allowed to connect to the Internet, the program spends approximately Internet quotas 70kb
Is this kind a new variant virus or spyware?, can't I delete them and how the the safe way to to remove them?
And here another file in windows NT, it call niwus.nof
The lister of niwus.nof:
URL,,Stealth Redirect To, http://stebuklas.dgorter2.hop.*********.net/ ,0,0
URL,,Stealth Redirect To, http://stebuklas.brammidas.hop.*********.net/ ,0,0
URL,,Stealth Redirect To, http://stebuklas.websellers.hop.*********.net/ ,0,0
URL,,Stealth Redirect To, http://stebuklas.btbet.hop.*********.net/ ,0,0
URL,,Stealth Redirect To, http://stebuklas.cragar.hop.*********.net/ ,0,0
URL,p,Stealth Redirect To, http://stebuklas.postyourhm.hop.*********.net/ ,0,0
Why this progam want to connect internet by visit to those sites?
2nd question:
My laptop installed AVG Internet Security v9.0.733
If I connect the internet my firewall say that the following program (windows) trying to connect:
wermgr.exe
rundll32.exe
service.xe
taskhost.exe
isass.exe
svchost.exe
msdt.exe
msiexec.exe
Can't I stop them by blocking to the internet connection?, and why Windows always try connect internet?
Please, I need advise. | My System Specs |
| OS windows 7 ultimate CPU Compaq Presario |
11 Feb 2010
|
#2 | | |
Upload the file (Niwus.exe) to Virus Total, and if any A/V scanners pick it up as something nasty.
I can tell you that rundll32.exe, service.exe, taskhost.exe, svchost.exe, and msiexec.exe are safe if they are running from the \Windows\System32 or \Windows\SysWOW64 directories. The others in your second question may be safe, but I can't comment on them. | My System Specs | | System Manufacturer/Model Number Custom OS Windows 7 RTM CPU i7 920 Motherboard eVGA x58 SLi Memory 6 GB Patriot Graphics Card eVGA GeForce 275 GTX Sound Card Soundblaster X-Fi Gamer Monitor(s) Displays Acer 225Tw PSU Corsair 750 W Case Antec Twelve Hundred Cooling Stock Hard Drives WD 1 TB |
11 Feb 2010
|
#3 | | Windows 7 Ultimate - 64-bit | Windows 8 Pro - 64-bit |

Quote: Originally Posted by Damarwulan Hi everybody.....
When I start my laptop shown that niwus.exe want to connect internet, this program come from \program files\windows NT\, if I am allowed to connect to the Internet, the program spends approximately Internet quotas 70kb
Is this kind a new variant virus or spyware?, can't I delete them and how the the safe way to to remove them?
And here another file in windows NT, it call niwus.nof
The lister of niwus.nof:
URL,,Stealth Redirect To, http://stebuklas.dgorter2.hop.*********.net/ ,0,0
URL,,Stealth Redirect To, http://stebuklas.brammidas.hop.*********.net/ ,0,0
URL,,Stealth Redirect To, http://stebuklas.websellers.hop.*********.net/ ,0,0
URL,,Stealth Redirect To, http://stebuklas.btbet.hop.*********.net/ ,0,0
URL,,Stealth Redirect To, http://stebuklas.cragar.hop.*********.net/ ,0,0
URL,p,Stealth Redirect To, http://stebuklas.postyourhm.hop.*********.net/ ,0,0
Why this progam want to connect internet by visit to those sites?
2nd question:
My laptop installed AVG Internet Security v9.0.733
If I connect the internet my firewall say that the following program (windows) trying to connect:
wermgr.exe
rundll32.exe
service.xe
taskhost.exe
isass.exe
svchost.exe
msdt.exe
msiexec.exe
Can't I stop them by blocking to the internet connection?, and why Windows always try connect internet?
Please, I need advise.
Hello, Welcome to SF,
According to some forums that file is a Virus. best thing to do would be disable from Startup.
Start > msconfig > Startup then if you find it uncheck it and reboot the System that should prevent from Starting up.
Also download Malwarebytes and run it.
Other services that your referring to are Windows services which you don't want to block.
Hope this helps,
Captain | My System Specs | | System Manufacturer/Model Number Samsung NP550P5C-S02IN OS Windows 7 Ultimate - 64-bit | Windows 8 Pro - 64-bit CPU Intel® Core™ i7 Processor 3,610QM (2.30Hz, 6MB L3 Cach Memory 8 GB Graphics Card NVIDIA® GeForce® GT 650M 2GB Graphics, Optimus™ techno Sound Card SoundAlive™ JBL 3 Speakers (With sub-Woofer) Monitor(s) Displays 39.62cm (15.6) SuperBright 300nit HD+ LED Display Screen Resolution 1,600 x 900, Anti-Reflective Hard Drives 1TB S-ATA II Hard Drive (5,400RPM) |
12 Feb 2010
|
#4 | | |
Ok, stoping this program using msconfig.exe
If this virus, can't I delete folder \program files\windows NT\*.* ?
Many thanks | My System Specs | | OS windows 7 ultimate CPU Compaq Presario |
12 Feb 2010
|
#5 | | |
I would follow the advice given if i were you.
cheers. | My System Specs | | System Manufacturer/Model Number Self OS W7, Xp Pro CPU AMD Sempron 2600+ Motherboard K8V-MX Memory 1GB Graphics Card Radeon HD3650 Sound Card Soundmax Monitor(s) Displays 17" HP CRT Screen Resolution 1024x768 Keyboard M$S Mouse Optical PSU ? 460W Case Coolermaster Cooling enough Hard Drives 1x WDC WD800BB
1x HDS728080 Internet Speed 1500kbs Other Info OLD!!! does the job i need. |
12 Feb 2010
|
#6 | | |
Hi
As advised previously... 1 - Upload a File to Virustotal- Highlight all the following in purple and press Ctrl+C on your keyboard to copy
- c:\program files\windows NT\niwus.exe
- Please click >here< to visit Virustotal
- Click into the blank box on the Virus Total page and press Ctrl+V on your keyboard to paste
- Click the Send File button
- Copy and paste the Virustotal results back here please
| My System Specs | | |
14 Feb 2010
|
#7 | | Windows 7 Ultimate 64 bit Cardiff/Wales |
theres a new antivirus out that runs as a BAT file
called
ComboFix
try it let us know if it workss
even
Malwarebytes
dont panic and run them all at the same time if its a bad virus or spyware run in safe mode and use the antivirus to scan there thn youll have no porgrams running but your OS
cya | My System Specs | | System Manufacturer/Model Number ASUS custamized build OS Windows 7 Ultimate 64 bit CPU AMD PHenom(tm) II X4 955 Processor Motherboard ASUS M4N68T-LE V2 Memory 4GB HYperX Kingston CL5 Graphics Card Sapphire HD 6950 2GB GDDR5 Sound Card Onboard Monitor(s) Displays 1 22 INCH monitor, 1 32 INCH LCD tv Screen Resolution 1600 x 1200 Keyboard - Mouse - PSU 650W Corsair TX Case CoolerMaster Storm Scout Cooling HyperX Memory Fan, 1 120m front, 120m top, 120m fan back Hard Drives C drive Sata 150 gb
1 portable hardrive 250 gb Internet Speed 1MB |
14 Feb 2010
|
#8 | | |
ComboFix is not an Antivirus. Quote: You should not run ComboFix unless you are specifically asked to by a helper. Also, due to the power of this tool it is strongly advised that you do not attempt to act upon any of the information displayed by ComboFix without supervision from someone who has been properly trained. If you do so, it may lead to problems with the normal functionality of your computer. I would add,, a skilled helper that gives you specific advice on how to use it and run it. Mainly the guys at the forums listed at the bottom of the link i provided. | My System Specs | | System Manufacturer/Model Number Self Built OS Win 7 Ultimate 32bit CPU C2D E6600 2.4Ghz Motherboard Intel D965WH Memory 4G Kingston KHX5400D2 Graphics Card EVGA GTX 570 HD SC (012-P3-1573-KR) Sound Card On-Board Monitor(s) Displays Samsung 226BW Screen Resolution 1680 x 1050 PSU Corsair TX750W Case In-Win C589 Cooling Stock Intel Cooling Hard Drives 2 x 250 Seagate Barracuda
2 x 500 Seagate Barracuda (Raid1) |
14 Feb 2010
|
#9 | | |
Very true Tepid. Only EVER use Combofix when asked to by a Trusted person on a Trusted Security forum!!!
Same goes for any advanced Removal/ analysis software. | My System Specs | | System Manufacturer/Model Number Self OS W7, Xp Pro CPU AMD Sempron 2600+ Motherboard K8V-MX Memory 1GB Graphics Card Radeon HD3650 Sound Card Soundmax Monitor(s) Displays 17" HP CRT Screen Resolution 1024x768 Keyboard M$S Mouse Optical PSU ? 460W Case Coolermaster Cooling enough Hard Drives 1x WDC WD800BB
1x HDS728080 Internet Speed 1500kbs Other Info OLD!!! does the job i need. |
15 Feb 2010
|
#10 | | |

Quote: Originally Posted by Tepid ComboFix is not an Antivirus. Quote: You should not run ComboFix unless you are specifically asked to by a helper. Also, due to the power of this tool it is strongly advised that you do not attempt to act upon any of the information displayed by ComboFix without supervision from someone who has been properly trained. If you do so, it may lead to problems with the normal functionality of your computer. I would add,, a skilled helper that gives you specific advice on how to use it and run it. Mainly the guys at the forums listed at the bottom of the link i provided. Yep! That cannot be stressed enough. | My System Specs | | Niwus.exe is a virus or spyware? problems? All times are GMT -5. The time now is 05:58 PM. | |