Windows Vista Forums
Vista Forums Home Join Vista Forums Tech Publications Windows 7 Forum Vista Tutorials Webcasts Tags

Welcome to Vista Forums we are your forum for Windows Vista help and discussion. Whether you need help or just want to post an idea you have on Vista, this is the forum for you.
Register at Vista forums...the world biggest Windows Vista resource Join Vista Forums Now

Go Back   Vista Forums > Vista Newsgroups > Vista security

Unknown process

Update your Vista Drivers
Reply
 
Thread Tools Display Modes
Old 05-16-2007   #1 (permalink)
caravaggio
Guest


 

Unknown process

I have a process called fdgbeb.exe that runs at start up and connects to
193.37.152.161 port number). It seems to overload my internet connection. I
have no idea how it got on my machine ut it is easily stopped using task
manager.

Can anyone tell me if it is safe to delete this process?

My System SpecsSystem Spec
Old 05-16-2007   #2 (permalink)
Mr. Arnold
Guest


 

Re: Unknown process


"caravaggio" <caravaggio@discussions.microsoft.com> wrote in message
news:8BD5B239-A3BF-42FB-B087-E0C6C7A2E875@microsoft.com...
>I have a process called fdgbeb.exe that runs at start up and connects to
> 193.37.152.161 port number). It seems to overload my internet
> connection. I
> have no idea how it got on my machine ut it is easily stopped using task
> manager.
>
> Can anyone tell me if it is safe to delete this process?


If you don't know what it is, then it shouldn't be running.

If you use Arin Whois to trace the IP, it goes to RIPE and winds up at the
Web Hosting company.

For all you know, it's malware as nothing should taking your Internet
connection like that, unless it's pulling/uploading data from your machine
to the site.


http://www.giga-international.com/ueber.php

My System SpecsSystem Spec
Old 05-16-2007   #3 (permalink)
caravaggio
Guest


 

Re: Unknown process



"Mr. Arnold" wrote:

>
> "caravaggio" <caravaggio@discussions.microsoft.com> wrote in message
> news:8BD5B239-A3BF-42FB-B087-E0C6C7A2E875@microsoft.com...
> >I have a process called fdgbeb.exe that runs at start up and connects to
> > 193.37.152.161 port number). It seems to overload my internet
> > connection. I
> > have no idea how it got on my machine ut it is easily stopped using task
> > manager.
> >
> > Can anyone tell me if it is safe to delete this process?

>
> If you don't know what it is, then it shouldn't be running.
>
> If you use Arin Whois to trace the IP, it goes to RIPE and winds up at the
> Web Hosting company.
>
> For all you know, it's malware as nothing should taking your Internet
> connection like that, unless it's pulling/uploading data from your machine
> to the site.
>
>
> http://www.giga-international.com/ueber.php
>
>


Thanks for that response. I've already mailed the hosting companies abuse
contact and await a reply, however, according to windows defender the process
was installed at manufacture so I am unsure whether it is malware or a
genuine process hi-jacked by malware which is why I am unsure if I should
just delete the process. Google, Microsoft and Symantec all come up blank on
searches for the process.


My System SpecsSystem Spec
Old 05-16-2007   #4 (permalink)
Mr. Arnold
Guest


 

Re: Unknown process


"caravaggio" <caravaggio@discussions.microsoft.com> wrote in message
news:9AA9D3DC-32C8-4AA4-9A01-5243929F1965@microsoft.com...
>
>
> "Mr. Arnold" wrote:
>
>>
>> "caravaggio" <caravaggio@discussions.microsoft.com> wrote in message
>> news:8BD5B239-A3BF-42FB-B087-E0C6C7A2E875@microsoft.com...
>> >I have a process called fdgbeb.exe that runs at start up and connects to
>> > 193.37.152.161 port number). It seems to overload my internet
>> > connection. I
>> > have no idea how it got on my machine ut it is easily stopped using
>> > task
>> > manager.
>> >
>> > Can anyone tell me if it is safe to delete this process?

>>
>> If you don't know what it is, then it shouldn't be running.
>>
>> If you use Arin Whois to trace the IP, it goes to RIPE and winds up at
>> the
>> Web Hosting company.
>>
>> For all you know, it's malware as nothing should taking your Internet
>> connection like that, unless it's pulling/uploading data from your
>> machine
>> to the site.
>>
>>
>> http://www.giga-international.com/ueber.php
>>
>>

>
> Thanks for that response. I've already mailed the hosting companies abuse
> contact and await a reply, however, according to windows defender the
> process
> was installed at manufacture so I am unsure whether it is malware or a
> genuine process hi-jacked by malware which is why I am unsure if I should
> just delete the process. Google, Microsoft and Symantec all come up blank
> on
> searches for the process.
>
>


Then what you should do is with a FW if one is running on the machine is
stop outbound traffic to that IP, until you know something.

My System SpecsSystem Spec
Old 05-17-2007   #5 (permalink)
Rock
Guest


 

Re: Unknown process

"caravaggio" wrote
>I have a process called fdgbeb.exe that runs at start up and connects to
> 193.37.152.161 port number). It seems to overload my internet
> connection. I
> have no idea how it got on my machine ut it is easily stopped using task
> manager.
>
> Can anyone tell me if it is safe to delete this process?


Assuming it's spelled correctly, that Google gives no hits is suspicious and
suggests malware.

--
Rock [MS-MVP User/Shell]

My System SpecsSystem Spec
Old 05-17-2007   #6 (permalink)
caravaggio
Guest


 

Re: Unknown process



"Rock" wrote:

> "caravaggio" wrote
> >I have a process called fdgbeb.exe that runs at start up and connects to
> > 193.37.152.161 port number). It seems to overload my internet
> > connection. I
> > have no idea how it got on my machine ut it is easily stopped using task
> > manager.
> >
> > Can anyone tell me if it is safe to delete this process?

>
> Assuming it's spelled correctly, that Google gives no hits is suspicious and
> suggests malware.
>
> --
> Rock [MS-MVP User/Shell]
>
>


Thanks for the replies. I've found the startup key for this application in
the registry and it is listed as a MS display driver, can someone from MS
confirm this?
My System SpecsSystem Spec
Old 05-17-2007   #7 (permalink)
Mr. Arnold
Guest


 

Re: Unknown process


"caravaggio" <caravaggio@discussions.microsoft.com> wrote in message
news:0E381BA1-358B-4443-BB96-91E69C60DD8D@microsoft.com...
>
>
> "Rock" wrote:
>
>> "caravaggio" wrote
>> >I have a process called fdgbeb.exe that runs at start up and connects to
>> > 193.37.152.161 port number). It seems to overload my internet
>> > connection. I
>> > have no idea how it got on my machine ut it is easily stopped using
>> > task
>> > manager.
>> >
>> > Can anyone tell me if it is safe to delete this process?

>>
>> Assuming it's spelled correctly, that Google gives no hits is suspicious
>> and
>> suggests malware.
>>
>> --
>> Rock [MS-MVP User/Shell]
>>
>>

>
> Thanks for the replies. I've found the startup key for this application in
> the registry and it is listed as a MS display driver, can someone from MS
> confirm this?


Confirm what? That's for you to do. It's your responsibility to know what is
running on your computer. You're the one that needs to make a determination
if the process is legit or not, because after all, its your computer.

Something shows up out of nowhere and is tying up my connection, and I can
stop it from doing it, then that's going to happen.

What would be the need of that program making an Internet connection with
outbound commutations to a remote site?

I had a Linksys wireless card driver that was phoning home to various IP(s).
I needed the driver, but I didn't need it phoning home so I stopped it from
doing it.

Maybe, you should block outbound traffic to that IP period with a firewall,
better yet, stop the exe from running and see what happens. It's just an
exe, use MSconfig and uncheck it in the Start-up, if it's there or go find
it in the Start-up folder and stop it or remove it.

Again what business does that program have in sending outbound traffic to a
remote IP, legit or not legit?

I like CurrPort, because you got to go look for yourself from time to time.
Also Process Explorer is a good tool to look and see what is running on the
machine. You can look inside a process like that exe and see what it's
hosting (hidden processes), that Task Manger cannot show you.

http://www.bestvistadownloads.com/do...-software.html

http://preview.tinyurl.com/klw1

http://www.microsoft.com/technet/sys...s/default.mspx

Active Ports doesn't run on Vista.




My System SpecsSystem Spec
Old 05-17-2007   #8 (permalink)
caravaggio
Guest


 

Re: Unknown process



"Mr. Arnold" wrote:

>
> Confirm what?


Confirm if it is a genuine MS display driver, I thought that was obvious.
And yes it is my computer but I didn't write, design or even install the
software, so I thought I'd ask a MS tech if it is a genuine process because
if it is then I'd rather not delete or otherwise interfere with it and
concentrate on finding out why it's making spurious internet connections.

As soon as I did a netstat -b and found that it was making a connection I
blocked it. At present no software, adaware, windows defender, avg av, norton
online check, spybot find the process a threat or find any other on my
system. I did this before my original post.

If you look back, I didn't ask how to stop it connecting, I didn't ask what
to use to see if it's malware, I asked if anyone knew if it was safe to
delete? So over to someone who knows what they are talking about and is able
to answer a direct question without a know-it-all attitude.


My System SpecsSystem Spec
Old 05-17-2007   #9 (permalink)
Alun Harford
Guest


 

Re: Unknown process

caravaggio wrote:
>
> "Mr. Arnold" wrote:
>
>> "caravaggio" <caravaggio@discussions.microsoft.com> wrote in message
>> news:8BD5B239-A3BF-42FB-B087-E0C6C7A2E875@microsoft.com...
>>> I have a process called fdgbeb.exe that runs at start up and connects to
>>> 193.37.152.161 port number). It seems to overload my internet
>>> connection. I
>>> have no idea how it got on my machine ut it is easily stopped using task
>>> manager.
>>>
>>> Can anyone tell me if it is safe to delete this process?

>> If you don't know what it is, then it shouldn't be running.
>>
>> If you use Arin Whois to trace the IP, it goes to RIPE and winds up at the
>> Web Hosting company.
>>
>> For all you know, it's malware as nothing should taking your Internet
>> connection like that, unless it's pulling/uploading data from your machine
>> to the site.
>>
>>
>> http://www.giga-international.com/ueber.php
>>
>>

>
> Thanks for that response. I've already mailed the hosting companies abuse
> contact and await a reply


So *you're* presumably performing a denial of service attack on a
machine, and now you're emailing their host to complain?

The file is obviously randomly named - I can think of no legitimate
executable that is randomly named.
Device drivers are not user-mode executables, and do not have a .exe
extension.
Very clearly, the file is malicious.

Alun Harford
My System SpecsSystem Spec
Old 05-17-2007   #10 (permalink)
Rock
Guest


 

Re: Unknown process

"caravaggio" wrote>
>
> "Rock" wrote:
>
>> "caravaggio" wrote
>> >I have a process called fdgbeb.exe that runs at start up and connects to
>> > 193.37.152.161 port number). It seems to overload my internet
>> > connection. I
>> > have no idea how it got on my machine ut it is easily stopped using
>> > task
>> > manager.
>> >
>> > Can anyone tell me if it is safe to delete this process?

>>
>> Assuming it's spelled correctly, that Google gives no hits is suspicious
>> and
>> suggests malware.


> Thanks for the replies. I've found the startup key for this application in
> the registry and it is listed as a MS display driver, can someone from MS
> confirm this?


It's not an MS file. By the way you are not talking to MS here. This is a
peer to peer tech support group. If you want to talk to someone from MS you
need to contact tech support through the normal channels.

--
Rock [MS-MVP User/Shell]

My System SpecsSystem Spec
Reply
Update your Vista Drivers

Thread Tools
Display Modes



Similar Threads
Thread Thread Starter Forum Replies Last Post
UNKNOWN ERROR WHEN IT SAY UNKNOWN ERROR HAS OCCURRED CHRISHATFIELD Vista mail 62 09-16-2008 12:28 AM
Unknown Running Process Michael Vista security 6 03-27-2008 07:28 PM
Process count wrong when only one process matches criteria malverson26 PowerShell 3 10-06-2007 04:01 AM
get-process & stop-process by owner Andrew Conrad PowerShell 3 03-03-2007 05:11 PM
Bug? Shouldn't Stop-Process automatically match Id if object is a process? Alex K. Angelopoulos [MVP] PowerShell 3 06-21-2006 06:35 AM


Complimentary Industry Resources

Vista Forums has joined forces with TradePub.com to offer you a new, exciting, and entirely free professional resource. Visit http://vistax64.tradepub.com today to browse our selection of complimentary Industry magazines, white papers, webinars, podcasts, and more across 34 industry sectors. No credit cards, coupons, or promo codes required. Try it today!




Vista Forums is an independent web site and has not been authorized,
sponsored, or otherwise approved by Microsoft Corporation.
"Windows Vista", the Start Orb, and related materials are trademarks of Microsoft Corp.
© Designer Media 2005-2008

1 2 3 4 5 6 7 8 9 10 11 12 13 14 15 16 17 18 19 20 21 22 23 24 25 26 27 28 29 30 31 32 33 34 35 36 37 38 39 40 41 42 43 44 45 46 47 48 49 50 51