Skype device third party software security issue. skyu2m.exe

deadfish

Distinguished
Aug 5, 2009
10
0
18,570
Purchased a hand held Skype cellphone device, Its literally just a cellphone looking speaker/ microphone combo with a color display that shows your contacts and history etc... which all was made possible by installing the software that came with it: Connected by a cord... not so practical, but I had money to burn in the shop and it was only $8.

I didn't need to use skype today, so I completely exited out of the program. About 15 minutes later..

The exe file skyu2m.exe associated with this device, and accepted by skype as a third party vendor.
According to malware bytes started on its own and was trying to contact this ip address: 69.172.201.208

That IP address is driving me nuts... because a simple /whois gave up a laundry list of random IP addresses across the globe.

Like this for example from DNSstuff.com
http://www.dnsstuff.com/tools#ipInformation|type=ipv4&&value=69.172.201.208

Im glad that malwarebytes is blocking it... and the software is literally just a driver for this device.. there are no options like "uncheck check for updates." available.

I really want to find out what this software is trying to do... and why this weird IP address.

 
Solution
download and install Comodo Autoruns Analyzer...........you will find where in the registry the program is being started, and can shut it down permanently if you wish, as long as they did not elevate it's priority too high. (For instance, I can't seem to shut off nanosvc.exe from running as a service with either MSconfig, or ProcessExplorer, Autoruns, KillSwitch, et al.....)

deadfish

Distinguished
Aug 5, 2009
10
0
18,570
I have wireshark... I am going to watch it again tonight, see what port, etc. It might just be calling home for updates.. or it could be dropping all my contacts info remotely. Dont like it.
 

mdd1963

Distinguished
download and install Comodo Autoruns Analyzer...........you will find where in the registry the program is being started, and can shut it down permanently if you wish, as long as they did not elevate it's priority too high. (For instance, I can't seem to shut off nanosvc.exe from running as a service with either MSconfig, or ProcessExplorer, Autoruns, KillSwitch, et al.....)
 
Solution

deadfish

Distinguished
Aug 5, 2009
10
0
18,570


that app is no longer available on their website. I just cancel the exe from starting up, instead.