|
#1
|
|||
|
|||
|
Hi all
Withera.exe a file inside my Windows\system32 folder keeps on asking permission to connect to the web. I always deny it and searching the web for the file gives no results. I run Adaware and Spybot Search & destroy at regular intervals and always keep them up-to-date. Do any of you know withera.exe is and the affect it has having on my PC? TIA Big Dave |
|
#2
|
|||
|
|||
|
Hi
Have you tried the following programs as well: Microsoft AntiSpyware - http://www.microsoft.com/athome/secu...e/default.mspx CWShredder - http://forum.aumha.org/downloads/cwshredder.zip Spy Sweeper - www.webroot.com Try SpyWareBlaster to stop intrusions: http://www.javacoolsoftware.co*m/spywareblaster.html Also see the following links: http://aumha.org/a/parasite.ht*m http://mvps.org/winhelp2002/un*wanted.htm Also virus check your system with the latest definitions for your AV program. -- Will Denny MS MVP Windows Shell/User Please reply to the News Groups "Big Dave" <Dave_le_rave_remove@yahoo.co.uk> wrote in message news:%233WDGuuCGHA.2700@TK2MSFTNGP14.phx.gbl... > Hi all > > Withera.exe a file inside my Windows\system32 folder keeps on asking > permission to connect to the web. I always deny it and searching the web > for the file gives no results. I run Adaware and Spybot Search & destroy > at regular intervals and always keep them up-to-date. > > Do any of you know withera.exe is and the affect it has having on my PC? > > TIA Big Dave > |
|
#3
|
|||
|
|||
|
From: "Big Dave" <Dave_le_rave_remove@yahoo.co.uk>
| Hi all | | Withera.exe a file inside my Windows\system32 folder keeps on asking | permission to connect to the web. I always deny it and searching the web for | the file gives no results. I run Adaware and Spybot Search & destroy at | regular intervals and always keep them up-to-date. | | Do any of you know withera.exe is and the affect it has having on my PC? | | TIA Big Dave | Please submit a sample of "Withera.exe" to Virus Total -- http://www.virustotal.com/flash/index_en.html The submission will then be tested against 18 different AV vendor's scanners. That will give you an idea what it is and who recognizes it. In addition, unless told otherwise, Virus Total will provide the sample to all participating vendors. You can also submit a suspect, one at a time, via the following email URL... mailto:scan@virustotal.com?subject=SCAN When you get the report, please post back the exact results. -- Dave http://www.claymania.com/removal-trojan-adware.html http://www.ik-cs.com/got-a-virus.htm |
|
#4
|
|||
|
|||
|
Results of test
Antivirus Version Update Result AntiVir 6.33.0.70 12.27.2005 no virus found Avast 4.6.695.0 12.27.2005 no virus found AVG 718 12.27.2005 no virus found Avira 6.33.0.70 12.27.2005 no virus found BitDefender 7.2 12.27.2005 no virus found CAT-QuickHeal 8.00 12.27.2005 no virus found ClamAV devel-20051108 12.26.2005 no virus found DrWeb 4.33 12.27.2005 no virus found eTrust-Iris 7.1.194.0 12.26.2005 no virus found eTrust-Vet 12.4.1.0 12.25.2005 no virus found Fortinet 2.54.0.0 12.27.2005 no virus found F-Prot 3.16c 12.26.2005 no virus found Ikarus 0.2.59.0 12.27.2005 no virus found Kaspersky 4.0.2.24 12.27.2005 no virus found McAfee 4660 12.27.2005 no virus found NOD32v2 1.1340 12.26.2005 no virus found Norman 5.70.10 12.27.2005 no virus found Panda 8.02.00 12.27.2005 no virus found Sophos 4.01.0 12.27.2005 no virus found Symantec 8.0 12.27.2005 no virus found TheHacker 5.9.1.062 12.27.2005 no virus found VBA32 3.10.5 12.27.2005 no virus found My own virus checker is on the list. Big Dave "David H. Lipman" <DLipman~nospam~@Verizon.Net> wrote in message news:%231daR1uCGHA.4004@tk2msftngp13.phx.gbl... > From: "Big Dave" <Dave_le_rave_remove@yahoo.co.uk> > > | Hi all > | > | Withera.exe a file inside my Windows\system32 folder keeps on asking > | permission to connect to the web. I always deny it and searching the web > for > | the file gives no results. I run Adaware and Spybot Search & destroy at > | regular intervals and always keep them up-to-date. > | > | Do any of you know withera.exe is and the affect it has having on my PC? > | > | TIA Big Dave > | > > > Please submit a sample of "Withera.exe" to Virus Total -- > http://www.virustotal.com/flash/index_en.html > The submission will then be tested against 18 different AV vendor's > scanners. > That will give you an idea what it is and who recognizes it. In addition, > unless told > otherwise, Virus Total will provide the sample to all participating > vendors. > > You can also submit a suspect, one at a time, via the following email > URL... > mailto:scan@virustotal.com?subject=SCAN > > When you get the report, please post back the exact results. > > -- > Dave > http://www.claymania.com/removal-trojan-adware.html > http://www.ik-cs.com/got-a-virus.htm > > |
|
#5
|
|||
|
|||
|
From: "Big Dave" <Dave_le_rave_remove@yahoo.co.uk>
| Results of test | | Antivirus Version Update Result | AntiVir 6.33.0.70 12.27.2005 no virus found | Avast 4.6.695.0 12.27.2005 no virus found | AVG 718 12.27.2005 no virus found | Avira 6.33.0.70 12.27.2005 no virus found | BitDefender 7.2 12.27.2005 no virus found | CAT-QuickHeal 8.00 12.27.2005 no virus found | ClamAV devel-20051108 12.26.2005 no virus found | DrWeb 4.33 12.27.2005 no virus found | eTrust-Iris 7.1.194.0 12.26.2005 no virus found | eTrust-Vet 12.4.1.0 12.25.2005 no virus found | Fortinet 2.54.0.0 12.27.2005 no virus found | F-Prot 3.16c 12.26.2005 no virus found | Ikarus 0.2.59.0 12.27.2005 no virus found | Kaspersky 4.0.2.24 12.27.2005 no virus found | McAfee 4660 12.27.2005 no virus found | NOD32v2 1.1340 12.26.2005 no virus found | Norman 5.70.10 12.27.2005 no virus found | Panda 8.02.00 12.27.2005 no virus found | Sophos 4.01.0 12.27.2005 no virus found | Symantec 8.0 12.27.2005 no virus found | TheHacker 5.9.1.062 12.27.2005 no virus found | VBA32 3.10.5 12.27.2005 no virus found | | My own virus checker is on the list. | | Big Dave What it is I don't know but it does not appear to be malicious. Right-Click on the file and view its properties. What are they ? -- Dave http://www.claymania.com/removal-trojan-adware.html http://www.ik-cs.com/got-a-virus.htm |
|
#6
|
|||
|
|||
|
Thanks for the swift reply. I have viewed the file's properties and al lthe
information it gives is the size of the file at 188kb. I have opened the file within Wordpad and copied some of the readable text. All of the rest is unreadable.The first line of the file reads "This program cannot be run in DOS mode." MSWHEEL_ROLLMSG .INI .HLP XB X B CFile (9B EA zA @ }A A A A ȁ@ {A {A }A ~A ~A }A N}A s~A ~A S~A }A ~A A x9B 'A @ @ =A rA )Q E> RichEdit Text and Objects Rich Text Format FileNameW FileName Link Source Descriptor Object Descriptor Link Source Embed Source Embedded Object ObjectLink OwnerLink Native :B "A "A "A "A :#A #A $A $A #$A +$A $A $A $A #$A B B CFileException B B COleException P:B A A@ @ οA rA A PB `&B < :B qA A @ 1A 3A 2A 2A 2A 2A 2A 2A B3A 2A <3A A 2A 83A 2A 2A 2A A A A eA A 6A ;B A A A A OA A @B PB COleBusyDialog hB ` @A COleDialog ;B BA A @ 46A WKA 2A 2A 2A 2A 2A W"A B3A 2A <3A 3A 2A 83A 2A 2A 2A ;A _IA hKA ?IA eYA vLA 2A rOA dA dA }VA WA KA @ @ @ 5A hA PA PA KA ;A ZA =A 2A 59A A }<A zVA ]"A t"A ;A %2 %5 %2\CLSID %1 %2\Insertable %2\protocol\StdFileEditing\verb\0 &Edit %2\protocol\StdFileEditing\server %3 CLSID\%1 %5 CLSID\%1\ProgID %2 CLSID\%1\InprocHandler32 ole32.dll CLSID\%1\LocalServer32 %3 CLSID\%1\Verb\0 &Edit,0,2 CLSID\%1\Verb\1 &Open,0,2 CLSID\%1\Insertable CLSID\%1\AuxUserType\2 %4 CLSID\%1\AuxUserType\3 %6 CLSID\%1\DefaultIcon %3,%7 CLSID\%1\MiscStatus 32 CLSID\%1\InProcServer32 %3 CLSID\%1\DocObject 0 %2\DocObject 0 CLSID\%1\Printable CLSID\%1\DefaultExtension %9, %8 HB \B lB B B 8B TB lB B B HB \B lB B B TB lB B B HB \B lB B B 8B TB lB B B B B B PB B B B B B PB B B B B HB B PB B B B B HB B PB B B B PB B B PB B B B B B 0B TB B B B B B 8B DB B hB TB B B B B B 8B XB B hB ;B QA `A B S * y"A @@ T@ 0<B і@ @ @ @ =@ csm @ /@ ֦@ Q@ @ T@ ?H:mm:ss dddd, MMMM dd, yyyy M/d/yy PM AM December November October September August July June April March February January Dec Nov Oct Sep Aug Jul Jun May Apr Mar Feb Jan Saturday Friday Thursday Wednesday Tuesday Monday Sunday Sat Fri Thu Wed Tue Mon Sun C@ M@ ҽ@ @ @ @ @ j@ s@ @ @ @ l@ X@ \@ __GLOBAL_HEAP_SELECTED __MSVCRT_HEAP_SELECT runtime error TLOSS error SING error DOMAIN error R6028 - unable to initialize heap R6027 - not enough space for lowio initialization R6026 - not enough space for stdio initialization R6025 - pure virtual function call R6024 - not enough space for _onexit/atexit table R6019 - unable to open console device R6018 - unexpected heap error R6017 - unexpected multithread lock error R6016 - not enough space for thread data abnormal program termination R6009 - not enough space for environment R6008 - not enough space for arguments R6002 - floating point not loaded Microsoft Visual C++ Runtime Library Runtime Error! Program: ... <program name unknown> H@ @ @ @ z@ ~@ .@ 2@ ~PA GAIsProcessorFeaturePresent KERNEL32 e+000 _yn _y1 _y0 frexp fmod _hypot _cabs ldexp modf fabs floor ceil tan cos sin sqrt atan2 atan acos asin tanh cosh sinh log10 log pow exp SunMonTueWedThuFriSat JanFebMarAprMayJunJulAugSepOctNovDec TZ EEE50 P (8PX 700WP `h```` ppxxxx ( n u l l ) (null) GetLastActivePopup GetActiveWindow MessageBoxA user32.dll timeGetTime WINMM.dll } ExitProcess Sleep J CreateThread XGetSystemDefaultLangID GetCurrentThreadId GetCurrentThread lstrcmpiA lstrcmpA GlobalDeleteAtom GlobalAlloc GlobalLock $GetModuleFileNameA CloseHandle LoadResource FindResourceA LockResource GlobalFree GlobalUnlock >GetProcAddress &GetModuleHandleA lstrcpyA GlobalFindAtomA GlobalAddAtomA GlobalGetAtomNameA lstrcatA tGetVersion FreeLibrary LoadLibraryA *InterlockedDecrement hGetThreadLocale MultiByteToWideChar lstrlenA InterlockedIncrement qSetLastError MulDiv WideCharToMultiByte LocalAlloc LocalFree InitializeCriticalSection TlsAlloc U DeleteCriticalSection GlobalHandle TlsFree LeaveCriticalSection GlobalReAlloc f EnterCriticalSection TlsSetValue LocalReAlloc TlsGetValue lstrcpynA GlobalFlags WritePrivateProfileStringA GetLastError EGetProcessVersion GetCPInfo 1GetOEMCP dSetErrorMode c DuplicateHandle GetCurrentProcess 4 CreateFileA ReadFile WriteFile jSetFilePointer FlushFileBuffers LockFile UnlockFile aSetEndOfFile FindClose FindFirstFileA wGetVolumeInformationA GetFullPathNameA FileTimeToSystemTime FileTimeToLocalFileTime mGetTickCount GetFileAttributesA GetFileSize GetFileTime FormatMessageA /RtlUnwind PGetStartupInfoA GetCommandLineA TerminateProcess HeapFree HeapAlloc RaiseException HeapReAlloc HeapSize GetACP pGetTimeZoneInformation *UnhandledExceptionFilter FreeEnvironmentStringsA FreeEnvironmentStringsW GetEnvironmentStrings GetEnvironmentStringsW mSetHandleCount RGetStdHandle GetFileType GetEnvironmentVariableA uGetVersionExA HeapDestroy HeapCreate VirtualFree VirtualAlloc IsBadWritePtr SetUnhandledExceptionFilter SGetStringTypeA VGetStringTypeW LCMapStringA LCMapStringW IsBadReadPtr IsBadCodePtr |SetStdHandle ! CompareStringA " CompareStringW bSetEnvironmentVariableA KERNEL32.dll PostMessageA RGetWindow FindWindowExA LoadIconA SendMessageA DrawIcon GetClientRect FGetSystemMetrics IsIconic EnableWindow PostQuitMessage &SetCursor MessageBoxA VGetWindowLongA IsWindowEnabled GetLastActivePopup 5GetParent bSetWindowsHookExA GetCursorPos PeekMessageA IsWindowVisible ValidateRect CallNextHookEx GetKeyState GetActiveWindow DispatchMessageA TranslateMessage *GetMessageA 3GetNextDlgTabItem GetFocus EnableMenuItem 4 CheckMenuItem 9SetMenuItemBitmaps ModifyMenuA 'GetMenuState LoadBitmapA GetMenuCheckMarkDimensions GetDlgItem DestroyWindow L CreateDialogIndirectParamA IsWindow SetActiveWindow EndDialog WSetWindowContextHelpId [SetWindowPos MapDialogRect \GetWindowRect [GetWindowPlacement qSystemParametersInfoA OffsetRect RegisterWindowMessageA XSetWindowLongA 0SetForegroundWindow GetForegroundWindow ,GetMessagePos -GetMessageTime DefWindowProcA RemovePropA CallWindowProcA :GetPropA UnhookWindowsHookEx BSetPropA GetClassLongA Y CreateWindowExA GetDlgCtrlID ^GetWindowTextA ZSetWindowPlacement #GetMenuItemID BGetSubMenu "GetMenuItemCount GetMenu RegisterClassA GetClassInfoA wsprintfA WinHelpA GetCapture IsChild LGetTopWindow D CopyRect AdjustWindowRectEx /SetFocus CGetSysColor MapWindowPoints SendDlgItemMessageA UpdateWindow IsDialogMessageA ^SetWindowTextA MoveWindow jShowWindow % CharNextA : ClientToScreen GetDC ReleaseDC TGetWindowDC BeginPaint EndPaint sTabbedTextOutA DrawTextA dGrayStringA LoadCursorA GetDesktopWindow GetClassNameA PtInRect DGetSysColorBrush LoadStringA @ CopyAcceleratorTableA DSetRect 2GetNextDlgGroupItem MessageBeep DestroyMenu / CharUpperA RegisterClipboardFormatA PostThreadMessageA USER32.dll $ CreateBitmap GetClipBox SetTextColor SetBkColor OGetObjectA iGetTextColor GetBkColor %GetDeviceCaps _GetStockObject P DeleteDC SaveDC RestoreDC SelectObject SetMapMode SetViewportOrgEx OffsetViewportOrgEx SetViewportExtEx ScaleViewportExtEx SetWindowExtEx ScaleWindowExtEx S DeleteObject xGetViewportExtEx {GetWindowExtEx PtVisible RectVisible TextOutA ExtTextOutA Escape N DPtoLP LPtoDP GGetMapMode GDI32.dll GetFileTitleA comdlg32.dll ClosePrinter G DocumentPropertiesA | OpenPrinterA WINSPOOL.DRV [RegCloseKey _RegCreateKeyExA rRegOpenKeyExA RegSetValueExA ADVAPI32.dll SHELL32.dll COMCTL32.dll oledlg.dll CLSIDFromProgID CLSIDFromString CoGetClassObject StgOpenStorageOnILockBytes StgCreateDocfileOnILockBytes ` CreateILockBytesOnHGlobal O CoTaskMemFree N CoTaskMemAlloc OleInitialize OleUninitialize CoFreeUnusedLibraries @ CoRegisterMessageFilter G CoRevokeClassObject OleFlushClipboard OleIsCurrentClipboard ole32.dll OLEPRO32.DLL OLEAUT32.dll UnregisterClassA O p e n S a v e A s A l l F i l e s ( * . * ) U n t i t l e d a n u n n a m e d f i l e & H i d e N o e r r o r m e s s a g e i s a v a i l a b l e . ' A n u n s u p p o r t e d o p e r a t i o n w a s a t t e m p t e d . $ A r e q u i r e d r e s o u r c e w a s u n a v a i l a b l e . O u t o f m e m o r y . A n u n k n o w n e r r o r h a s o c c u r r e d . I n v a l i d f i l e n a m e . F a i l e d t o o p e n d o c u m e n t . F a i l e d t o s a v e d o c u m e n t . S a v e c h a n g e s t o % 1 ? F a i l e d t o c r e a t e e m p t y d o c u m e n t . T h e f i l e i s t o o l a r g e t o o p e n . C o u l d n o t s t a r t p r i n t j o b . F a i l e d t o l a u n c h h e l p . I n t e r n a l a p p l i c a t i o n e r r o r . C o m m a n d f a i l e d . ) I n s u f f i c i e n t m e m o r y t o p e r f o r m o p e r a t i o n . P S y s t e m r e g i s t r y e n t r i e s h a v e b e e n r e m o v e d a n d t h e I N I f i l e ( i f a n y ) w a s d e l e t e d . B N o t a l l o f t h e s y s t e m r e g i s t r y e n t r i e s ( o r I N I f i l e ) w e r e r e m o v e d . F T h i s p r o g r a m r e q u i r e s t h e f i l e % s , w h i c h w a s n o t f o u n d o n t h i s s y s t e m . t T h i s p r o g r a m i s l i n k e d t o t h e m i s s i n g e x p o r t % s i n t h e f i l e % s . T h i s m a c h i n e m a y h a v e a n i n c o m p a t i b l e v e r s i o n o f % s . # U n a b l e t o r e a d w r i t e - o n l y p r o p e r t y . # U n a b l e t o w r i t e r e a d - o n l y p r o p e r t y . U n e x p e c t e d f i l e f o r m a t . V % 1 C a n n o t f i n d t h i s f i l e . P l e a s e v e r i f y t h a t t h e c o r r e c t p a t h a n d f i l e n a m e a r e g i v e n . D e s t i n a t i o n d i s k d r i v e i s f u l l . 5 U n a b l e t o r e a d f r o m % 1 , i t i s o p e n e d b y s o m e o n e e l s e . A U n a b l e t o w r i t e t o % 1 , i t i s r e a d - o n l y o r o p e n e d b y s o m e o n e e l s e . . A n u n e x p e c t e d e r r o r o c c u r r e d w h i l e r e a d i n g % 1 . . A n u n e x p e c t e d e r r o r o c c u r r e d w h i l e w r i t i n g % 1 . P l e a s e e n t e r a n i n t e g e r . P l e a s e e n t e r a n u m b e r . * P l e a s e e n t e r a n i n t e g e r b e t w e e n % 1 a n d % 2 . ( P l e a s e e n t e r a n u m b e r b e t w e e n % 1 a n d % 2 . ( P l e a s e e n t e r n o m o r e t h a n % 1 c h a r a c t e r s . P l e a s e s e l e c t a b u t t o n . * P l e a s e e n t e r a n i n t e g e r b e t w e e n 0 a n d 2 5 5 . P l e a s e e n t e r a p o s i t i v e i n t e g e r . P l e a s e e n t e r a d a t e a n d / o r t i m e . P l e a s e e n t e r a c u r r e n c y .. N o e r r o r o c c u r r e d . - A n u n k n o w n e r r o r o c c u r r e d w h i l e a c c e s s i n g % 1 . % 1 w a s n o t f o u n d . % 1 c o n t a i n s a n i n v a l i d p a t h . = % 1 c o u l d n o t b e o p e n e d b e c a u s e t h e r e a r e t o o m a n y o p e n f i l e s . A c c e s s t o % 1 w a s d e n i e d . . A n i n v a l i d f i l e h a n d l e w a s a s s o c i a t e d w i t h % 1 . < % 1 c o u l d n o t b e r e m o v e d b e c a u s e i t i s t h e c u r r e n t d i r e c t o r y . 6 % 1 c o u l d n o t b e c r e a t e d b e c a u s e t h e d i r e c t o r y i s f u l l . S e e k f a i l e d o n % 1 5 A h a r d w a r e I / O e r r o r w a s r e p o r t e d w h i l e a c c e s s i n g % 1 . 0 A s h a r i n g v i o l a t i o n o c c u r r e d w h i l e a c c e s s i n g % 1 . 0 A l o c k i n g v i o l a t i o n o c c u r r e d w h i l e a c c e s s i n g % 1 . D i s k f u l l w h i l e a c c e s s i n g % 1 . . A n a t t e m p t w a s m a d e t o a c c e s s % 1 p a s t i t s e n d . N o e r r o r o c c u r r e d . - A n u n k n o w n e r r o r o c c u r r e d w h i l e a c c e s s i n g % 1 . / A n a t t e m p t w a s m a d e t o w r i t e t o t h e r e a d i n g % 1 . . A n a t t e m p t w a s m a d e t o a c c e s s % 1 p a s t i t s e n d . 0 A n a t t e m p t w a s m a d e t o r e a d f r o m t h e w r i t i n g % 1 . % 1 h a s a b a d f o r m a t . " % 1 c o n t a i n e d a n u n e x p e c t e d o b j e c t . % 1 c o n t a i n s a n i n c o r r e c t s c h e m a . # U n a b l e t o l o a d m a i l s y s t e m s u p p o r t . M a i l s y s t e m D L L i s i n v a l i d . ! S e n d M a i l f a i l e d t o s e n d m e s s a g e .. p i x e l s Thanks Big Dave "David H. Lipman" <DLipman~nospam~@Verizon.Net> wrote in message news:%230ZXanwCGHA.2596@TK2MSFTNGP10.phx.gbl... > From: "Big Dave" <Dave_le_rave_remove@yahoo.co.uk> > > | Results of test > | > | Antivirus Version Update Result > | AntiVir 6.33.0.70 12.27.2005 no virus found > | Avast 4.6.695.0 12.27.2005 no virus found > | AVG 718 12.27.2005 no virus found > | Avira 6.33.0.70 12.27.2005 no virus found > | BitDefender 7.2 12.27.2005 no virus found > | CAT-QuickHeal 8.00 12.27.2005 no virus found > | ClamAV devel-20051108 12.26.2005 no virus found > | DrWeb 4.33 12.27.2005 no virus found > | eTrust-Iris 7.1.194.0 12.26.2005 no virus found > | eTrust-Vet 12.4.1.0 12.25.2005 no virus found > | Fortinet 2.54.0.0 12.27.2005 no virus found > | F-Prot 3.16c 12.26.2005 no virus found > | Ikarus 0.2.59.0 12.27.2005 no virus found > | Kaspersky 4.0.2.24 12.27.2005 no virus found > | McAfee 4660 12.27.2005 no virus found > | NOD32v2 1.1340 12.26.2005 no virus found > | Norman 5.70.10 12.27.2005 no virus found > | Panda 8.02.00 12.27.2005 no virus found > | Sophos 4.01.0 12.27.2005 no virus found > | Symantec 8.0 12.27.2005 no virus found > | TheHacker 5.9.1.062 12.27.2005 no virus found > | VBA32 3.10.5 12.27.2005 no virus found > | > | My own virus checker is on the list. > | > | Big Dave > > What it is I don't know but it does not appear to be malicious. > > Right-Click on the file and view its properties. What are they ? > > -- > Dave > http://www.claymania.com/removal-trojan-adware.html > http://www.ik-cs.com/got-a-virus.htm > > |
|
#7
|
|||
|
|||
|
http://www.thegreatwar.nl/pages/deit...ty/withera.php
Withera is a "True Neutral" however I wouldn't trust that description. Personally, I'd send a copy to your favourite Virus Research Lab. or For instructions on submitting a sample to AVERT please see: http://vil.nai.com/vil/submit-sample.asp "Big Dave" <Dave_le_rave_remove@yahoo.co.uk> wrote in message news:%233WDGuuCGHA.2700@TK2MSFTNGP14.phx.gbl... | Hi all | | Withera.exe a file inside my Windows\system32 folder keeps on asking | permission to connect to the web. I always deny it and searching the web for | the file gives no results. I run Adaware and Spybot Search & destroy at | regular intervals and always keep them up-to-date. | | Do any of you know withera.exe is and the affect it has having on my PC? | | TIA Big Dave | | |
![]() |
| Thread Tools | Search this Thread |
| Display Modes | |
|