Withera.exe keeps asking to coonect to the web?


Go Back   Computer Help Articles > Windows XP Help and Support
User Name
Password
FAQ Members List Calendar Search Today's Posts Mark Forums Read

Reply
 
Thread Tools Search this Thread Display Modes
  #1  
Old 01-05-2006, 02:43 AM
Big Dave
 
Posts: n/a
Default Withera.exe keeps asking to coonect to the web?

Hi all

Withera.exe a file inside my Windows\system32 folder keeps on asking
permission to connect to the web. I always deny it and searching the web for
the file gives no results. I run Adaware and Spybot Search & destroy at
regular intervals and always keep them up-to-date.

Do any of you know withera.exe is and the affect it has having on my PC?

TIA Big Dave


Reply With Quote
  #2  
Old 01-05-2006, 02:43 AM
Will Denny
 
Posts: n/a
Default Re: Withera.exe keeps asking to coonect to the web?

Hi

Have you tried the following programs as well:

Microsoft AntiSpyware -
http://www.microsoft.com/athome/secu...e/default.mspx
CWShredder - http://forum.aumha.org/downloads/cwshredder.zip
Spy Sweeper - www.webroot.com

Try SpyWareBlaster to stop intrusions:

http://www.javacoolsoftware.co*m/spywareblaster.html

Also see the following links:

http://aumha.org/a/parasite.ht*m
http://mvps.org/winhelp2002/un*wanted.htm

Also virus check your system with the latest definitions for your AV
program.

--


Will Denny
MS MVP Windows Shell/User
Please reply to the News Groups

"Big Dave" <Dave_le_rave_remove@yahoo.co.uk> wrote in message
news:%233WDGuuCGHA.2700@TK2MSFTNGP14.phx.gbl...
> Hi all
>
> Withera.exe a file inside my Windows\system32 folder keeps on asking
> permission to connect to the web. I always deny it and searching the web
> for the file gives no results. I run Adaware and Spybot Search & destroy
> at regular intervals and always keep them up-to-date.
>
> Do any of you know withera.exe is and the affect it has having on my PC?
>
> TIA Big Dave
>



Reply With Quote
  #3  
Old 01-05-2006, 02:43 AM
David H. Lipman
 
Posts: n/a
Default Re: Withera.exe keeps asking to coonect to the web?

From: "Big Dave" <Dave_le_rave_remove@yahoo.co.uk>

| Hi all
|
| Withera.exe a file inside my Windows\system32 folder keeps on asking
| permission to connect to the web. I always deny it and searching the web for
| the file gives no results. I run Adaware and Spybot Search & destroy at
| regular intervals and always keep them up-to-date.
|
| Do any of you know withera.exe is and the affect it has having on my PC?
|
| TIA Big Dave
|


Please submit a sample of "Withera.exe" to Virus Total --
http://www.virustotal.com/flash/index_en.html
The submission will then be tested against 18 different AV vendor's scanners.
That will give you an idea what it is and who recognizes it. In addition, unless told
otherwise, Virus Total will provide the sample to all participating vendors.

You can also submit a suspect, one at a time, via the following email URL...
mailto:scan@virustotal.com?subject=SCAN

When you get the report, please post back the exact results.

--
Dave
http://www.claymania.com/removal-trojan-adware.html
http://www.ik-cs.com/got-a-virus.htm


Reply With Quote
  #4  
Old 01-05-2006, 02:43 AM
Big Dave
 
Posts: n/a
Default Re: Withera.exe keeps asking to coonect to the web?

Results of test

Antivirus Version Update Result
AntiVir 6.33.0.70 12.27.2005 no virus found
Avast 4.6.695.0 12.27.2005 no virus found
AVG 718 12.27.2005 no virus found
Avira 6.33.0.70 12.27.2005 no virus found
BitDefender 7.2 12.27.2005 no virus found
CAT-QuickHeal 8.00 12.27.2005 no virus found
ClamAV devel-20051108 12.26.2005 no virus found
DrWeb 4.33 12.27.2005 no virus found
eTrust-Iris 7.1.194.0 12.26.2005 no virus found
eTrust-Vet 12.4.1.0 12.25.2005 no virus found
Fortinet 2.54.0.0 12.27.2005 no virus found
F-Prot 3.16c 12.26.2005 no virus found
Ikarus 0.2.59.0 12.27.2005 no virus found
Kaspersky 4.0.2.24 12.27.2005 no virus found
McAfee 4660 12.27.2005 no virus found
NOD32v2 1.1340 12.26.2005 no virus found
Norman 5.70.10 12.27.2005 no virus found
Panda 8.02.00 12.27.2005 no virus found
Sophos 4.01.0 12.27.2005 no virus found
Symantec 8.0 12.27.2005 no virus found
TheHacker 5.9.1.062 12.27.2005 no virus found
VBA32 3.10.5 12.27.2005 no virus found


My own virus checker is on the list.

Big Dave

"David H. Lipman" <DLipman~nospam~@Verizon.Net> wrote in message
news:%231daR1uCGHA.4004@tk2msftngp13.phx.gbl...
> From: "Big Dave" <Dave_le_rave_remove@yahoo.co.uk>
>
> | Hi all
> |
> | Withera.exe a file inside my Windows\system32 folder keeps on asking
> | permission to connect to the web. I always deny it and searching the web
> for
> | the file gives no results. I run Adaware and Spybot Search & destroy at
> | regular intervals and always keep them up-to-date.
> |
> | Do any of you know withera.exe is and the affect it has having on my PC?
> |
> | TIA Big Dave
> |
>
>
> Please submit a sample of "Withera.exe" to Virus Total --
> http://www.virustotal.com/flash/index_en.html
> The submission will then be tested against 18 different AV vendor's
> scanners.
> That will give you an idea what it is and who recognizes it. In addition,
> unless told
> otherwise, Virus Total will provide the sample to all participating
> vendors.
>
> You can also submit a suspect, one at a time, via the following email
> URL...
> mailto:scan@virustotal.com?subject=SCAN
>
> When you get the report, please post back the exact results.
>
> --
> Dave
> http://www.claymania.com/removal-trojan-adware.html
> http://www.ik-cs.com/got-a-virus.htm
>
>



Reply With Quote
  #5  
Old 01-05-2006, 02:43 AM
David H. Lipman
 
Posts: n/a
Default Re: Withera.exe keeps asking to coonect to the web?

From: "Big Dave" <Dave_le_rave_remove@yahoo.co.uk>

| Results of test
|
| Antivirus Version Update Result
| AntiVir 6.33.0.70 12.27.2005 no virus found
| Avast 4.6.695.0 12.27.2005 no virus found
| AVG 718 12.27.2005 no virus found
| Avira 6.33.0.70 12.27.2005 no virus found
| BitDefender 7.2 12.27.2005 no virus found
| CAT-QuickHeal 8.00 12.27.2005 no virus found
| ClamAV devel-20051108 12.26.2005 no virus found
| DrWeb 4.33 12.27.2005 no virus found
| eTrust-Iris 7.1.194.0 12.26.2005 no virus found
| eTrust-Vet 12.4.1.0 12.25.2005 no virus found
| Fortinet 2.54.0.0 12.27.2005 no virus found
| F-Prot 3.16c 12.26.2005 no virus found
| Ikarus 0.2.59.0 12.27.2005 no virus found
| Kaspersky 4.0.2.24 12.27.2005 no virus found
| McAfee 4660 12.27.2005 no virus found
| NOD32v2 1.1340 12.26.2005 no virus found
| Norman 5.70.10 12.27.2005 no virus found
| Panda 8.02.00 12.27.2005 no virus found
| Sophos 4.01.0 12.27.2005 no virus found
| Symantec 8.0 12.27.2005 no virus found
| TheHacker 5.9.1.062 12.27.2005 no virus found
| VBA32 3.10.5 12.27.2005 no virus found
|
| My own virus checker is on the list.
|
| Big Dave

What it is I don't know but it does not appear to be malicious.

Right-Click on the file and view its properties. What are they ?

--
Dave
http://www.claymania.com/removal-trojan-adware.html
http://www.ik-cs.com/got-a-virus.htm


Reply With Quote
  #6  
Old 01-05-2006, 02:43 AM
Big Dave
 
Posts: n/a
Default Re: Withera.exe keeps asking to coonect to the web?

Thanks for the swift reply. I have viewed the file's properties and al lthe
information it gives is the size of the file at 188kb. I have opened the
file within Wordpad and copied some of the readable text. All of the rest is
unreadable.The first line of the file reads "This program cannot be run in
DOS mode."

MSWHEEL_ROLLMSG .INI .HLP XB  X B CFile (9B EA zA
@ }A A A A ȁ@ {A {A }A ~A ~A }A N}A s~A ~A S~A }A ~A A
x9B 'A @ @ =A
rA )Q E> RichEdit Text and Objects Rich Text Format FileNameW
FileName Link Source Descriptor Object Descriptor Link Source Embed
Source Embedded Object ObjectLink OwnerLink Native :B "A "A "A
"A :#A #A $A $A #$A +$A $A $A $A #$A B  B
CFileException B B COleException P:B A A@ @ οA
rA A PB `&B <         
:B qA A @ 1A 3A 2A 2A 2A 2A 2A 2A B3A 2A <3A A 2A
83A 2A 2A 2A
A A A eA A 6A ;B A A A A OA A @B PB
COleBusyDialog hB ` @A COleDialog ;B BA A @ 46A WKA
2A 2A 2A 2A 2A W"A B3A 2A <3A 3A 2A 83A 2A 2A 2A ;A _IA hKA ?IA
eYA vLA 2A rOA dA dA }VA WA KA @ @ @ 5A hA PA PA KA ;A ZA
=A 2A 59A A }<A zVA ]"A t"A ;A %2 %5 %2\CLSID %1 %2\Insertable
%2\protocol\StdFileEditing\verb\0 &Edit %2\protocol\StdFileEditing\server %3
CLSID\%1 %5 CLSID\%1\ProgID %2 CLSID\%1\InprocHandler32 ole32.dll
CLSID\%1\LocalServer32 %3 CLSID\%1\Verb\0 &Edit,0,2 CLSID\%1\Verb\1
&Open,0,2 CLSID\%1\Insertable CLSID\%1\AuxUserType\2 %4
CLSID\%1\AuxUserType\3 %6 CLSID\%1\DefaultIcon %3,%7 CLSID\%1\MiscStatus
32 CLSID\%1\InProcServer32 %3 CLSID\%1\DocObject 0 %2\DocObject 0
CLSID\%1\Printable CLSID\%1\DefaultExtension %9, %8 HB \B lB B B
8B TB lB B B HB \B lB B B TB lB B B HB \B lB
B B 8B TB lB B B B B B PB B B B B B
PB B B B B HB B PB B B B B HB B
PB B B B PB B B PB B B B B B 0B TB B
B B B B 8B DB B hB TB B B B B B 8B XB B hB ;B
QA `A B S * y"A @@ T@ 0<B
і@ @ @ @ =@ csm 
 @ /@ ֦@ Q@ @
T@ ?H:mm:ss dddd, MMMM dd, yyyy M/d/yy PM AM December November
October September August July June April March February
January Dec Nov Oct Sep Aug Jul Jun May Apr Mar Feb Jan Saturday Friday
Thursday Wednesday Tuesday Monday Sunday Sat Fri Thu Wed Tue Mon Sun
C@ M@ ҽ@ @ @ @ @ j@ s@
@ @ @ l@ X@ \@ __GLOBAL_HEAP_SELECTED
__MSVCRT_HEAP_SELECT runtime error
TLOSS error
SING error
DOMAIN error
R6028
- unable to initialize heap
R6027
- not enough space for lowio initialization
R6026
- not enough space for stdio initialization
R6025
- pure virtual function call
R6024
- not enough space for _onexit/atexit table
R6019
- unable to open console device
R6018
- unexpected heap error
R6017
- unexpected multithread lock error
R6016
- not enough space for thread data

abnormal program termination
R6009
- not enough space for environment
R6008
- not enough space for arguments
R6002
- floating point not loaded
Microsoft Visual C++ Runtime Library

Runtime Error!

Program: ... <program name unknown> H@ @
@ @ z@ ~@ .@ 2@ ~PA
GAIsProcessorFeaturePresent KERNEL32 e+000 _yn _y1 _y0 frexp
fmod _hypot _cabs ldexp modf fabs floor ceil tan cos sin
sqrt atan2 atan acos asin tanh cosh sinh log10 log
pow exp SunMonTueWedThuFriSat JanFebMarAprMayJunJulAugSepOctNovDec TZ
     EEE50 P (8PX 700WP  `h```` ppxxxx
     ( n u l l ) (null) GetLastActivePopup GetActiveWindow
MessageBoxA user32.dll

timeGetTime WINMM.dll } ExitProcess Sleep J CreateThread
XGetSystemDefaultLangID GetCurrentThreadId GetCurrentThread
lstrcmpiA lstrcmpA GlobalDeleteAtom GlobalAlloc GlobalLock
$GetModuleFileNameA  CloseHandle LoadResource FindResourceA
LockResource GlobalFree GlobalUnlock >GetProcAddress
&GetModuleHandleA lstrcpyA GlobalFindAtomA GlobalAddAtomA
GlobalGetAtomNameA lstrcatA tGetVersion FreeLibrary
LoadLibraryA *InterlockedDecrement hGetThreadLocale
MultiByteToWideChar lstrlenA InterlockedIncrement qSetLastError
MulDiv WideCharToMultiByte LocalAlloc LocalFree
InitializeCriticalSection TlsAlloc U DeleteCriticalSection
GlobalHandle TlsFree LeaveCriticalSection GlobalReAlloc f
EnterCriticalSection TlsSetValue LocalReAlloc TlsGetValue
lstrcpynA GlobalFlags WritePrivateProfileStringA GetLastError
EGetProcessVersion GetCPInfo 1GetOEMCP dSetErrorMode c
DuplicateHandle GetCurrentProcess 4 CreateFileA ReadFile WriteFile
jSetFilePointer FlushFileBuffers LockFile UnlockFile
aSetEndOfFile FindClose FindFirstFileA wGetVolumeInformationA
GetFullPathNameA FileTimeToSystemTime FileTimeToLocalFileTime
mGetTickCount
GetFileAttributesA GetFileSize GetFileTime FormatMessageA
/RtlUnwind PGetStartupInfoA GetCommandLineA TerminateProcess
HeapFree HeapAlloc RaiseException HeapReAlloc HeapSize GetACP
pGetTimeZoneInformation *UnhandledExceptionFilter
FreeEnvironmentStringsA FreeEnvironmentStringsW GetEnvironmentStrings
GetEnvironmentStringsW mSetHandleCount RGetStdHandle GetFileType
GetEnvironmentVariableA uGetVersionExA HeapDestroy HeapCreate
VirtualFree VirtualAlloc IsBadWritePtr SetUnhandledExceptionFilter
SGetStringTypeA VGetStringTypeW LCMapStringA LCMapStringW
IsBadReadPtr IsBadCodePtr |SetStdHandle ! CompareStringA "
CompareStringW bSetEnvironmentVariableA KERNEL32.dll PostMessageA
RGetWindow FindWindowExA LoadIconA SendMessageA DrawIcon
GetClientRect FGetSystemMetrics IsIconic EnableWindow
PostQuitMessage &SetCursor MessageBoxA VGetWindowLongA
IsWindowEnabled GetLastActivePopup 5GetParent bSetWindowsHookExA
GetCursorPos PeekMessageA IsWindowVisible ValidateRect 
CallNextHookEx GetKeyState GetActiveWindow DispatchMessageA
TranslateMessage *GetMessageA 3GetNextDlgTabItem GetFocus
EnableMenuItem 4 CheckMenuItem 9SetMenuItemBitmaps ModifyMenuA
'GetMenuState LoadBitmapA GetMenuCheckMarkDimensions GetDlgItem
DestroyWindow L CreateDialogIndirectParamA IsWindow SetActiveWindow
EndDialog WSetWindowContextHelpId [SetWindowPos MapDialogRect
\GetWindowRect [GetWindowPlacement qSystemParametersInfoA OffsetRect
RegisterWindowMessageA XSetWindowLongA 0SetForegroundWindow
GetForegroundWindow ,GetMessagePos -GetMessageTime DefWindowProcA
RemovePropA  CallWindowProcA :GetPropA UnhookWindowsHookEx BSetPropA
GetClassLongA Y CreateWindowExA GetDlgCtrlID ^GetWindowTextA
ZSetWindowPlacement #GetMenuItemID BGetSubMenu "GetMenuItemCount
GetMenu RegisterClassA GetClassInfoA wsprintfA WinHelpA
GetCapture IsChild LGetTopWindow D CopyRect  AdjustWindowRectEx
/SetFocus CGetSysColor MapWindowPoints SendDlgItemMessageA
UpdateWindow IsDialogMessageA ^SetWindowTextA MoveWindow
jShowWindow % CharNextA : ClientToScreen GetDC ReleaseDC
TGetWindowDC BeginPaint EndPaint sTabbedTextOutA DrawTextA
dGrayStringA LoadCursorA GetDesktopWindow GetClassNameA PtInRect
DGetSysColorBrush LoadStringA @ CopyAcceleratorTableA DSetRect
2GetNextDlgGroupItem MessageBeep DestroyMenu / CharUpperA
RegisterClipboardFormatA PostThreadMessageA USER32.dll $ CreateBitmap
GetClipBox SetTextColor SetBkColor OGetObjectA iGetTextColor
GetBkColor %GetDeviceCaps _GetStockObject P DeleteDC SaveDC
RestoreDC SelectObject SetMapMode SetViewportOrgEx
OffsetViewportOrgEx SetViewportExtEx ScaleViewportExtEx
SetWindowExtEx ScaleWindowExtEx S DeleteObject xGetViewportExtEx
{GetWindowExtEx PtVisible RectVisible TextOutA ExtTextOutA
Escape N DPtoLP LPtoDP GGetMapMode GDI32.dll  GetFileTitleA
comdlg32.dll  ClosePrinter G DocumentPropertiesA | OpenPrinterA
WINSPOOL.DRV [RegCloseKey _RegCreateKeyExA rRegOpenKeyExA
RegSetValueExA ADVAPI32.dll SHELL32.dll COMCTL32.dll oledlg.dll 
CLSIDFromProgID  CLSIDFromString  CoGetClassObject
StgOpenStorageOnILockBytes StgCreateDocfileOnILockBytes `
CreateILockBytesOnHGlobal O CoTaskMemFree N CoTaskMemAlloc OleInitialize
OleUninitialize  CoFreeUnusedLibraries @ CoRegisterMessageFilter G
CoRevokeClassObject OleFlushClipboard OleIsCurrentClipboard ole32.dll
OLEPRO32.DLL OLEAUT32.dll UnregisterClassA

O p e n  S a v e A s  A l l F i l e s ( * . * )  U n t i t l e d
 a n u n n a m e d f i l e  & H i d e
 N o e r r o r m e s s a g e i s a v a i l a b l e . ' A n u n s
u p p o r t e d o p e r a t i o n w a s a t t e m p t e d . $ A r e
q u i r e d r e s o u r c e w a s u n a v a i l a b l e .  O u t o
f m e m o r y .  A n u n k n o w n e r r o r h a s o c c u r r e
d .  I n v a l i d f i l e n a m e .  F a i
l e d t o o p e n d o c u m e n t .  F a i l e d t o s a v e d
o c u m e n t .  S a v e c h a n g e s t o % 1 ? F a i l e d t o
c r e a t e e m p t y d o c u m e n t .  T h e f i l e i s t o o
l a r g e t o o p e n .  C o u l d n o t s t a r t p r i n t j
o b .  F a i l e d t o l a u n c h h e l p .  I n t e r n a l a p
p l i c a t i o n e r r o r .  C o m m a n d f a i l e d . ) I n s u f
f i c i e n t m e m o r y t o p e r f o r m o p e r a t i o n . P S
y s t e m r e g i s t r y e n t r i e s h a v e b e e n r e m o v
e d a n d t h e I N I f i l e ( i f a n y ) w a s d e l e t
e d . B N o t a l l o f t h e s y s t e m r e g i s t r y e n t
r i e s ( o r I N I f i l e ) w e r e r e m o v e d . F T h i s
p r o g r a m r e q u i r e s t h e f i l e % s , w h i c h w a
s n o t f o u n d o n t h i s s y s t e m . t T h i s p r o g r
a m i s l i n k e d t o t h e m i s s i n g e x p o r t % s
i n t h e f i l e % s . T h i s m a c h i n e m a y h a v e
a n i n c o m p a t i b l e v e r s i o n o f % s .
# U n a b l e t o r e a d w r i t e - o n l y p r o p e r t y . # U
n a b l e t o w r i t e r e a d - o n l y p r o p e r t y .
 U n e x p e c t e d f i l e f o r m a t . V % 1
C a n n o t f i n d t h i s f i l e .
P l e a s e v e r i f y t h a t t h e c o r r e c t p a t h a n
d f i l e n a m e a r e g i v e n .  D e s t i n a t i o n d i s
k d r i v e i s f u l l . 5 U n a b l e t o r e a d f r o m %
1 , i t i s o p e n e d b y s o m e o n e e l s e . A U n a b l
e t o w r i t e t o % 1 , i t i s r e a d - o n l y o r o
p e n e d b y s o m e o n e e l s e . . A n u n e x p e c t e d e
r r o r o c c u r r e d w h i l e r e a d i n g % 1 . . A n u n e
x p e c t e d e r r o r o c c u r r e d w h i l e w r i t i n g %
1 .  P l e a s e e n t e r a n i n t e g e r .
 P l e a s e e n t e r a n u m b e r . * P l e a s e e n t e r a
n i n t e g e r b e t w e e n % 1 a n d % 2 . ( P l e a s e e n
t e r a n u m b e r b e t w e e n % 1 a n d % 2 . ( P l e a s e
e n t e r n o m o r e t h a n % 1 c h a r a c t e r s .  P l e a
s e s e l e c t a b u t t o n . * P l e a s e e n t e r a n i n
t e g e r b e t w e e n 0 a n d 2 5 5 . P l e a s e e n t e r
a p o s i t i v e i n t e g e r . P l e a s e e n t e r a d a t
e a n d / o r t i m e .  P l e a s e e n t e r a c u r r e n c y
..  N o e r r o r o c c u r r e d . - A n u n k n o
w n e r r o r o c c u r r e d w h i l e a c c e s s i n g % 1 . 
% 1 w a s n o t f o u n d .  % 1 c o n t a i n s a n i n v a l
i d p a t h . = % 1 c o u l d n o t b e o p e n e d b e c a u s
e t h e r e a r e t o o m a n y o p e n f i l e s .  A c c e s
s t o % 1 w a s d e n i e d . . A n i n v a l i d f i l e h a
n d l e w a s a s s o c i a t e d w i t h % 1 . < % 1 c o u l d
n o t b e r e m o v e d b e c a u s e i t i s t h e c u r r e
n t d i r e c t o r y . 6 % 1 c o u l d n o t b e c r e a t e d
b e c a u s e t h e d i r e c t o r y i s f u l l .  S e e k f a
i l e d o n % 1 5 A h a r d w a r e I / O e r r o r w a s r e
p o r t e d w h i l e a c c e s s i n g % 1 . 0 A s h a r i n g v
i o l a t i o n o c c u r r e d w h i l e a c c e s s i n g % 1 . 0
A l o c k i n g v i o l a t i o n o c c u r r e d w h i l e a c c
e s s i n g % 1 .  D i s k f u l l w h i l e a c c e s s i n g %
1 . . A n a t t e m p t w a s m a d e t o a c c e s s % 1 p a
s t i t s e n d .  N o e r r o r o c c u r r e d . - A n u
n k n o w n e r r o r o c c u r r e d w h i l e a c c e s s i n g
% 1 . / A n a t t e m p t w a s m a d e t o w r i t e t o t h
e r e a d i n g % 1 . . A n a t t e m p t w a s m a d e t o a
c c e s s % 1 p a s t i t s e n d . 0 A n a t t e m p t w a s
m a d e t o r e a d f r o m t h e w r i t i n g % 1 .  % 1 h
a s a b a d f o r m a t . " % 1 c o n t a i n e d a n u n e x p
e c t e d o b j e c t . % 1 c o n t a i n s a n i n c o r r e c t
s c h e m a . # U n a b l e t o l o a d m a i l
s y s t e m s u p p o r t .  M a i l s y s t e m D L L i s i n v
a l i d . ! S e n d M a i l f a i l e d t o s e n d m e s s a g e
..  p i x e l s

Thanks Big Dave


"David H. Lipman" <DLipman~nospam~@Verizon.Net> wrote in message
news:%230ZXanwCGHA.2596@TK2MSFTNGP10.phx.gbl...
> From: "Big Dave" <Dave_le_rave_remove@yahoo.co.uk>
>
> | Results of test
> |
> | Antivirus Version Update Result
> | AntiVir 6.33.0.70 12.27.2005 no virus found
> | Avast 4.6.695.0 12.27.2005 no virus found
> | AVG 718 12.27.2005 no virus found
> | Avira 6.33.0.70 12.27.2005 no virus found
> | BitDefender 7.2 12.27.2005 no virus found
> | CAT-QuickHeal 8.00 12.27.2005 no virus found
> | ClamAV devel-20051108 12.26.2005 no virus found
> | DrWeb 4.33 12.27.2005 no virus found
> | eTrust-Iris 7.1.194.0 12.26.2005 no virus found
> | eTrust-Vet 12.4.1.0 12.25.2005 no virus found
> | Fortinet 2.54.0.0 12.27.2005 no virus found
> | F-Prot 3.16c 12.26.2005 no virus found
> | Ikarus 0.2.59.0 12.27.2005 no virus found
> | Kaspersky 4.0.2.24 12.27.2005 no virus found
> | McAfee 4660 12.27.2005 no virus found
> | NOD32v2 1.1340 12.26.2005 no virus found
> | Norman 5.70.10 12.27.2005 no virus found
> | Panda 8.02.00 12.27.2005 no virus found
> | Sophos 4.01.0 12.27.2005 no virus found
> | Symantec 8.0 12.27.2005 no virus found
> | TheHacker 5.9.1.062 12.27.2005 no virus found
> | VBA32 3.10.5 12.27.2005 no virus found
> |
> | My own virus checker is on the list.
> |
> | Big Dave
>
> What it is I don't know but it does not appear to be malicious.
>
> Right-Click on the file and view its properties. What are they ?
>
> --
> Dave
> http://www.claymania.com/removal-trojan-adware.html
> http://www.ik-cs.com/got-a-virus.htm
>
>



Reply With Quote
  #7  
Old 01-05-2006, 02:44 AM
Mungo Bulge
 
Posts: n/a
Default Re: Withera.exe keeps asking to coonect to the web?

http://www.thegreatwar.nl/pages/deit...ty/withera.php
Withera is a "True Neutral" however I wouldn't trust that description.
Personally, I'd send a copy to your favourite Virus Research Lab.
or
For instructions on submitting a sample to AVERT please see:
http://vil.nai.com/vil/submit-sample.asp


"Big Dave" <Dave_le_rave_remove@yahoo.co.uk> wrote in message
news:%233WDGuuCGHA.2700@TK2MSFTNGP14.phx.gbl...
| Hi all
|
| Withera.exe a file inside my Windows\system32 folder keeps on asking
| permission to connect to the web. I always deny it and searching the
web for
| the file gives no results. I run Adaware and Spybot Search & destroy
at
| regular intervals and always keep them up-to-date.
|
| Do any of you know withera.exe is and the affect it has having on my
PC?
|
| TIA Big Dave
|
|


Reply With Quote
Reply


Thread Tools Search this Thread
Search this Thread:

Advanced Search
Display Modes

Forum Jump


All times are GMT. The time now is 01:40 AM.


Powered by vBulletin Version 3.5.2
Copyright ©2000 - 2008, Jelsoft Enterprises Ltd. SEO by vBSEO 2.3.2 © 2005, Crawlability, Inc.

Withera.exe keeps asking to coonect to the web?