Microsoft Windows Vista Community Forums - Vistaheads
Recommended Download - Clean, repair and optimize your system



Welcome to the Microsoft Windows Vista Community Forums - Vistaheads, YOUR Largest Resource for Windows Vista related information.

You are currently viewing our boards as a guest which gives you limited access to view most discussions and access our other features. By joining our free community you will have access to post topics, communicate privately with other members (PM), respond to polls, upload content and access many other special features. Registration is fast, simple and absolutely free so , join our community today!

If you have any problems with the registration process or your account login, please contact us.

Driver Scanner 2009 - Free Scan Now

Unknown process

microsoft.public.windows.vista.security




Recommended Fix - Fix Vista Errors and Optimize Performance

Click On Your Flag for Translation
Simplified Chinese French Spanish Italian Portugeuse Japanese German Dutch
Driver Scanner 2009 - Free Scan Now
Reply
  #1 (permalink)  
Old 05-16-2007
caravaggio
 

Posts: n/a
Unknown process
I have a process called fdgbeb.exe that runs at start up and connects to
193.37.152.161 port number). It seems to overload my internet connection. I
have no idea how it got on my machine ut it is easily stopped using task
manager.

Can anyone tell me if it is safe to delete this process?
Digg this Post!Add Post to del.icio.usBookmark Post in TechnoratiFurl this Post!
Reply With Quote
Sponsored Links
  #2 (permalink)  
Old 05-17-2007
Mr. Arnold
 

Posts: n/a
Re: Unknown process

"caravaggio" <caravaggio@discussions.microsoft.com> wrote in message
news:8BD5B239-A3BF-42FB-B087-E0C6C7A2E875@microsoft.com...
>I have a process called fdgbeb.exe that runs at start up and connects to
> 193.37.152.161 port number). It seems to overload my internet
> connection. I
> have no idea how it got on my machine ut it is easily stopped using task
> manager.
>
> Can anyone tell me if it is safe to delete this process?


If you don't know what it is, then it shouldn't be running.

If you use Arin Whois to trace the IP, it goes to RIPE and winds up at the
Web Hosting company.

For all you know, it's malware as nothing should taking your Internet
connection like that, unless it's pulling/uploading data from your machine
to the site.


http://www.giga-international.com/ueber.php

Digg this Post!Add Post to del.icio.usBookmark Post in TechnoratiFurl this Post!
Reply With Quote
  #3 (permalink)  
Old 05-17-2007
caravaggio
 

Posts: n/a
Re: Unknown process


"Mr. Arnold" wrote:

>
> "caravaggio" <caravaggio@discussions.microsoft.com> wrote in message
> news:8BD5B239-A3BF-42FB-B087-E0C6C7A2E875@microsoft.com...
> >I have a process called fdgbeb.exe that runs at start up and connects to
> > 193.37.152.161 port number). It seems to overload my internet
> > connection. I
> > have no idea how it got on my machine ut it is easily stopped using task
> > manager.
> >
> > Can anyone tell me if it is safe to delete this process?

>
> If you don't know what it is, then it shouldn't be running.
>
> If you use Arin Whois to trace the IP, it goes to RIPE and winds up at the
> Web Hosting company.
>
> For all you know, it's malware as nothing should taking your Internet
> connection like that, unless it's pulling/uploading data from your machine
> to the site.
>
>
> http://www.giga-international.com/ueber.php
>
>


Thanks for that response. I've already mailed the hosting companies abuse
contact and await a reply, however, according to windows defender the process
was installed at manufacture so I am unsure whether it is malware or a
genuine process hi-jacked by malware which is why I am unsure if I should
just delete the process. Google, Microsoft and Symantec all come up blank on
searches for the process.


Digg this Post!Add Post to del.icio.usBookmark Post in TechnoratiFurl this Post!
Reply With Quote
  #4 (permalink)  
Old 05-17-2007
Mr. Arnold
 

Posts: n/a
Re: Unknown process

"caravaggio" <caravaggio@discussions.microsoft.com> wrote in message
news:9AA9D3DC-32C8-4AA4-9A01-5243929F1965@microsoft.com...
>
>
> "Mr. Arnold" wrote:
>
>>
>> "caravaggio" <caravaggio@discussions.microsoft.com> wrote in message
>> news:8BD5B239-A3BF-42FB-B087-E0C6C7A2E875@microsoft.com...
>> >I have a process called fdgbeb.exe that runs at start up and connects to
>> > 193.37.152.161 port number). It seems to overload my internet
>> > connection. I
>> > have no idea how it got on my machine ut it is easily stopped using
>> > task
>> > manager.
>> >
>> > Can anyone tell me if it is safe to delete this process?

>>
>> If you don't know what it is, then it shouldn't be running.
>>
>> If you use Arin Whois to trace the IP, it goes to RIPE and winds up at
>> the
>> Web Hosting company.
>>
>> For all you know, it's malware as nothing should taking your Internet
>> connection like that, unless it's pulling/uploading data from your
>> machine
>> to the site.
>>
>>
>> http://www.giga-international.com/ueber.php
>>
>>

>
> Thanks for that response. I've already mailed the hosting companies abuse
> contact and await a reply, however, according to windows defender the
> process
> was installed at manufacture so I am unsure whether it is malware or a
> genuine process hi-jacked by malware which is why I am unsure if I should
> just delete the process. Google, Microsoft and Symantec all come up blank
> on
> searches for the process.
>
>


Then what you should do is with a FW if one is running on the machine is
stop outbound traffic to that IP, until you know something.

Digg this Post!Add Post to del.icio.usBookmark Post in TechnoratiFurl this Post!
Reply With Quote
  #5 (permalink)  
Old 05-17-2007
Rock
 

Posts: n/a
Re: Unknown process
"caravaggio" wrote
>I have a process called fdgbeb.exe that runs at start up and connects to
> 193.37.152.161 port number). It seems to overload my internet
> connection. I
> have no idea how it got on my machine ut it is easily stopped using task
> manager.
>
> Can anyone tell me if it is safe to delete this process?


Assuming it's spelled correctly, that Google gives no hits is suspicious and
suggests malware.

--
Rock [MS-MVP User/Shell]

Digg this Post!Add Post to del.icio.usBookmark Post in TechnoratiFurl this Post!
Reply With Quote
  #6 (permalink)  
Old 05-17-2007
caravaggio
 

Posts: n/a
Re: Unknown process


"Rock" wrote:

> "caravaggio" wrote
> >I have a process called fdgbeb.exe that runs at start up and connects to
> > 193.37.152.161 port number). It seems to overload my internet
> > connection. I
> > have no idea how it got on my machine ut it is easily stopped using task
> > manager.
> >
> > Can anyone tell me if it is safe to delete this process?

>
> Assuming it's spelled correctly, that Google gives no hits is suspicious and
> suggests malware.
>
> --
> Rock [MS-MVP User/Shell]
>
>


Thanks for the replies. I've found the startup key for this application in
the registry and it is listed as a MS display driver, can someone from MS
confirm this?
Digg this Post!Add Post to del.icio.usBookmark Post in TechnoratiFurl this Post!
Reply With Quote
  #7 (permalink)  
Old 05-17-2007
Mr. Arnold
 

Posts: n/a
Re: Unknown process

"caravaggio" <caravaggio@discussions.microsoft.com> wrote in message
news:0E381BA1-358B-4443-BB96-91E69C60DD8D@microsoft.com...
>
>
> "Rock" wrote:
>
>> "caravaggio" wrote
>> >I have a process called fdgbeb.exe that runs at start up and connects to
>> > 193.37.152.161 port number). It seems to overload my internet
>> > connection. I
>> > have no idea how it got on my machine ut it is easily stopped using
>> > task
>> > manager.
>> >
>> > Can anyone tell me if it is safe to delete this process?

>>
>> Assuming it's spelled correctly, that Google gives no hits is suspicious
>> and
>> suggests malware.
>>
>> --
>> Rock [MS-MVP User/Shell]
>>
>>

>
> Thanks for the replies. I've found the startup key for this application in
> the registry and it is listed as a MS display driver, can someone from MS
> confirm this?


Confirm what? That's for you to do. It's your responsibility to know what is
running on your computer. You're the one that needs to make a determination
if the process is legit or not, because after all, its your computer.

Something shows up out of nowhere and is tying up my connection, and I can
stop it from doing it, then that's going to happen.

What would be the need of that program making an Internet connection with
outbound commutations to a remote site?

I had a Linksys wireless card driver that was phoning home to various IP(s).
I needed the driver, but I didn't need it phoning home so I stopped it from
doing it.

Maybe, you should block outbound traffic to that IP period with a firewall,
better yet, stop the exe from running and see what happens. It's just an
exe, use MSconfig and uncheck it in the Start-up, if it's there or go find
it in the Start-up folder and stop it or remove it.

Again what business does that program have in sending outbound traffic to a
remote IP, legit or not legit?

I like CurrPort, because you got to go look for yourself from time to time.
Also Process Explorer is a good tool to look and see what is running on the
machine. You can look inside a process like that exe and see what it's
hosting (hidden processes), that Task Manger cannot show you.

http://www.bestvistadownloads.com/do...-software.html

http://preview.tinyurl.com/klw1

http://www.microsoft.com/technet/sys...s/default.mspx

Active Ports doesn't run on Vista.




Digg this Post!Add Post to del.icio.usBookmark Post in TechnoratiFurl this Post!
Reply With Quote
  #8 (permalink)  
Old 05-17-2007
caravaggio
 

Posts: n/a
Re: Unknown process


"Mr. Arnold" wrote:

>
> Confirm what?


Confirm if it is a genuine MS display driver, I thought that was obvious.
And yes it is my computer but I didn't write, design or even install the
software, so I thought I'd ask a MS tech if it is a genuine process because
if it is then I'd rather not delete or otherwise interfere with it and
concentrate on finding out why it's making spurious internet connections.

As soon as I did a netstat -b and found that it was making a connection I
blocked it. At present no software, adaware, windows defender, avg av, norton
online check, spybot find the process a threat or find any other on my
system. I did this before my original post.

If you look back, I didn't ask how to stop it connecting, I didn't ask what
to use to see if it's malware, I asked if anyone knew if it was safe to
delete? So over to someone who knows what they are talking about and is able
to answer a direct question without a know-it-all attitude.


Digg this Post!Add Post to del.icio.usBookmark Post in TechnoratiFurl this Post!
Reply With Quote
  #9 (permalink)  
Old 05-17-2007
Alun Harford
 

Posts: n/a
Re: Unknown process
caravaggio wrote:
>
> "Mr. Arnold" wrote:
>
>> "caravaggio" <caravaggio@discussions.microsoft.com> wrote in message
>> news:8BD5B239-A3BF-42FB-B087-E0C6C7A2E875@microsoft.com...
>>> I have a process called fdgbeb.exe that runs at start up and connects to
>>> 193.37.152.161 port number). It seems to overload my internet
>>> connection. I
>>> have no idea how it got on my machine ut it is easily stopped using task
>>> manager.
>>>
>>> Can anyone tell me if it is safe to delete this process?

>> If you don't know what it is, then it shouldn't be running.
>>
>> If you use Arin Whois to trace the IP, it goes to RIPE and winds up at the
>> Web Hosting company.
>>
>> For all you know, it's malware as nothing should taking your Internet
>> connection like that, unless it's pulling/uploading data from your machine
>> to the site.
>>
>>
>> http://www.giga-international.com/ueber.php
>>
>>

>
> Thanks for that response. I've already mailed the hosting companies abuse
> contact and await a reply


So *you're* presumably performing a denial of service attack on a
machine, and now you're emailing their host to complain?

The file is obviously randomly named - I can think of no legitimate
executable that is randomly named.
Device drivers are not user-mode executables, and do not have a .exe
extension.
Very clearly, the file is malicious.

Alun Harford
Digg this Post!Add Post to del.icio.usBookmark Post in TechnoratiFurl this Post!
Reply With Quote
  #10 (permalink)  
Old 05-17-2007
Rock
 

Posts: n/a
Re: Unknown process
"caravaggio" wrote>
>
> "Rock" wrote:
>
>> "caravaggio" wrote
>> >I have a process called fdgbeb.exe that runs at start up and connects to
>> > 193.37.152.161 port number). It seems to overload my internet
>> > connection. I
>> > have no idea how it got on my machine ut it is easily stopped using
>> > task
>> > manager.
>> >
>> > Can anyone tell me if it is safe to delete this process?

>>
>> Assuming it's spelled correctly, that Google gives no hits is suspicious
>> and
>> suggests malware.


> Thanks for the replies. I've found the startup key for this application in
> the registry and it is listed as a MS display driver, can someone from MS
> confirm this?


It's not an MS file. By the way you are not talking to MS here. This is a
peer to peer tech support group. If you want to talk to someone from MS you
need to contact tech support through the normal channels.

--
Rock [MS-MVP User/Shell]

Digg this Post!Add Post to del.icio.usBookmark Post in TechnoratiFurl this Post!
Reply With Quote
Reply


Thread Tools
Display Modes

Posting Rules
You may not post new threads
You may not post replies
You may not post attachments
You may not edit your posts

vB code is On
Smilies are On
[IMG] code is On
HTML code is Off
Trackbacks are On
Pingbacks are On
Refbacks are Off

Similar Threads
Thread Thread Starter Forum Replies Last Post
Reauthentification Process Jim microsoft.public.windows.vista.general 2 05-16-2007 16:08
EF Process Manager 4.30 VistaUtils Vista Utilities Feed 0 04-19-2007 06:13
Process Viewer 1.0 VistaUtils Vista Utilities Feed 0 04-10-2007 10:49
Security Is in the Process Steve Security News 0 03-12-2007 23:39
Install process hangs churin microsoft.public.windows.vista.installation setup 7 03-11-2007 16:44




All times are GMT +1. The time now is 16:45.




Driver Scanner - Free Scan Now

Vistaheads.com is part of the Heads Network. See also XPHeads.com and Win7Heads.com.


Funny Commercials to make you laugh :-)

Design by Vjacheslav Trushkin for phpBBStyles.com.
Powered by vBulletin® Version 3.6.7
Copyright ©2000 - 2009, Jelsoft Enterprises Ltd.
Search Engine Optimization by vBSEO 3.3.2

1 2 3 4 5 6 7 8 9 10 11 12 13 14 15 16 17 18 19 20 21 22 23 24 25 26 27 28 29 30 31 32 33 34 35 36 37 38 39 40 41 42 43 44 45 46 47 48 49 50 51 52 53 54 55 56 57 58 59 60 61 62 63 64 65 66 67 68 69 70 71 72 73 74 75 76 77 78 79 80 81 82 83 84 85 86 87 88 89 90 91 92 93 94 95 96 97 98 99 100 101 102 103 104 105 106 107 108 109 110 111 112 113 114 115 116 117 118 119