Associated Malware Groups
The unsafe files using this name are associated with the malware groups:
- Cloaked Malware
- Malicious Software
File Behavior
BLUETOOTH.EXE has been seen to perform the following behavior:
- The Process is packed and/or encrypted using a software packing process
- Can communicate with other computer systems using HTTP protocols
- Writes to another Process's Virtual Memory (Process Hijacking)
- Executes a Process
- Downloads hidden code from covert web sites
- This process creates other processes on disk
- Checks for the use of debuggers
- Looks at the contents of the autoexec.bat file
- Reads email address and phone book details
- Visits web sites on your PC without you knowing
- Injects code into other processes
- This Process Deletes Other Processes From Disk
- Copies files
BLUETOOTH.EXE has been the subject of the following behavior:
- Created as a process on disk
- Executed as a Process
- Has code inserted into its Virtual Memory space by other programs
- Added as a Registry auto start to load Program on Boot up
- Deleted as a process from disk
- Copied to multiple locations on the system
Country Of Origin
The filename BLUETOOTH.EXE was first seen on Mar 19 2008 in the following geographical regions of the Webroot community:
- Russian Federation on Mar 19 2008
- Netherlands on Aug 8 2008
- Spain on Oct 18 2008
- France on Jun 17 2009
- South Africa on Nov 15 2010
- The United States on May 24 2012
File Name Aliases
BLUETOOTH.EXE can also use the following file names:
- BLUETOOTH[1].EXE
- BLUETOOTH[2].EXE
- USBRUN.EXE
- DOCUMENT.EXE
- SOPHOS ANTIVIRUS UPDATER BYPASS.EXE
- WINDOWS2008 KEYGEN AND ACTIVATOR.EXE
- DVD TOOLS NERO 10.5.6.0.EXE
- G-FORCE PLATINUM V3.7.5.EXE
- RAPIDSHARE AUTO DOWNLOADER 3.8.EXE
- IMAGE SIZE REDUCER PRO V1.0.1.EXE
- ALCOHOL 120 V1.9.7.EXE
- K-LITE MEGA CODEC V5.5.1.EXE
- PDF PASSWORD REMOVER (WORKS WITH ALL ACROBAT READER).EXE
- STARCRAFT2 BATTLE.NET KEY GENERATOR.EXE
- NORTON ANTI-VIRUS 2010 CRACK.EXE
- WINDOWS XP PRO CORP SP3 VALID-KEY GENERATOR.EXE
- MICROSOFT.WINDOWS 7 ULTIMATE FINAL ACTIVATOR+KEYGEN X86.EXE
- PDF-XCHANGE PRO.EXE
- MYSPACE THEME COLLECTION.EXE
- RAPIDSHARE KILLER AIO 2010.EXE
- GOOGLE SKETCHUP 7.1 PRO.EXE
- WINAMP.PRO.V7.33.POWERPACK.PORTABLE+INSTALLER.EXE
- TOTAL COMMANDER7 LICENSE+KEYGEN.EXE
- POWER ISO V4.2 + KEYGEN AXXO.EXE
- DIVX PRO 7 + KEYMAKER.EXE
- WINDOWS 7 ULTIMATE KEYGEN.EXE
- ASHAMPOO SNAP 3.02.EXE
- K-LITE MEGA CODEC V5.6.1 PORTABLE.EXE
- MP3 SPLITTER AND JOINER PRO V3.48.EXE
- ANYDVD HD V.6.3.1.8 BETA INCL CRACK.EXE
- ADOBE ACROBAT READER KEYGEN.EXE
- ADOBE PHOTOSHOP CS5 CRACK.EXE
- NERO 9 9.2.6.0 KEYGEN.EXE
- TROJAN KILLER V2.9.4173.EXE
- WINRAR V3.X KEYGEN RAZOR.EXE
- TUNEUP ULTILITIES 2010.EXE
- AVS VIDEO CONVERTER V6.3.1.365 CRACKED.EXE
- DOWNLOAD BOOST 2.0.EXE
- STARCRAFT2 REGION-UNLOCKER.EXE
- VMWARE KEYGEN.EXE
- ANTI-PORN V13.5.12.29.EXE
- YOUTUBE MUSIC DOWNLOADER 1.0.EXE
- TWITTER FRIENDADDER 2.1.1.EXE
- MAGICISO MAGIC ISO MAKER V5.5.0276 CRACKED.EXE
- GRAND THEFT AUTO EPISODES FROM LIBERTY CITY 2010.EXE
- NORTON INTERNET SECURITY 2010 CRACK.EXE
- BITDEFENDER ANTIVIRUS 2010 KEYGEN.EXE
- LIMEWIRE PRO V4.18.3.EXE
- CLEANMYPC REGISTRY CLEANER V6.02.EXE
- AD-AWARE 2010.EXE
- YOUTUBEGET 5.4.EXE
- SUPER UTILITIES PRO 2009 11.0.EXE
- STARCRAFT2.EXE
- WINDOWS 2008 ENTERPRISE SERVER VMWARE VIRTUAL MACHINE.EXE
- VMWARE 7.0 KEYGEN.EXE
- MCAFEE TOTAL PROTECTION 2010.EXE
- PDF UNLOCKER V2.0.3.EXE
- DAEMON TOOLS PRO 4.50.EXE
- UNIBLUE REGISTRYBOOSTER 2010.EXE
- SONY VEGAS PRO V9.0A INCL CRACK.EXE
- STARCRAFT2 SERVER-CHANGER.EXE
- BLAZE DVD PLAYER PRO V6.52.EXE
- DOWNLOAD ACCELERATOR PLUS V9.EXE
- KASPERSKY ANTIVIRUS 2010 CRACK.EXE
- STARCRAFT2 BATTLE.NET KEYS.TXT.EXE
- INTERNET DOWNLOAD MANAGER V5.EXE
- PDF TO WORD CONVERTER 3.0.EXE
- ADOBE ILLUSTRATOR CS4 CRACK.EXE
- MOTOROLA, NOKIA, ERICSSON MOBIL PHONE TOOLS.EXE
- MS09-067.EXE
Filesizes
The following file size has been seen:
- 241,029 bytes
- 207,872 bytes
- 184,680 bytes
- 275,577 bytes
- 497,152 bytes
- 558,592 bytes
File Type
The filename BLUETOOTH.EXE is used by multiple object types including executable programs,objects.
File Activity
One or more files with the name BLUETOOTH.EXE creates, deletes, copies or moves the following files and folders:
- create folder C:\Program Files\Windows NT\Accessories\en-UK
- Opens/modifes c:\autoexec.bat
- Creates c:\program files\windows nt\accessories\en-uk\id.xt
- Creates c:\program files\windows nt\accessories\en-uk\ArabFox.dll
- Creates c:\program files\windows nt\accessories\en-uk\nklst.xt
- Creates c:\program files\windows nt\accessories\en-uk\whois.xt
- Creates c:\program files\windows nt\accessories\en-uk\zena.xt
- Creates c:\program files\windows nt\accessories\en-uk\System
- create folder C:\Program Files\Windows NT\Accessories\en-UK\logs
- create folder C:\Program Files\Windows NT\Accessories\en-UK\sound
- Deletes c:\program files\windows nt\accessories\en-uk\remote.ini
Network Activity
One or more files with the name BLUETOOTH.EXE performs the following network events:
- DNS Lookup194.68.45.50 RedeMPtIoN.Ix.us.dal.Net
- DNS Lookup68.178.150.35 love.foxshell.Net
- DNS Lookup82.69.127.154 82-69-127-154.dsl.in-addr.zen.co.uk
- DNS Lookup195.50.191.12 aRCoR.de.eu.dal.Net
Website Activity
One or more files with the name BLUETOOTH.EXE interacts with the following web sites and pages. Web addresses have been deliberately modified to prevent unintentional use.
- 68 .178 .151 .95 / ww / id .xt
- 68 .178 .151 .95 / ww / ArabFox .dll
- 68 .178 .151 .95 / ww / nklst .xt
- 68 .178 .151 .95 / ww / whois .xt
- 68 .178 .151 .95 / ww / zena .xt
- 68 .178 .151 .95 / ww / System
- Port 80 IP:68.178.151.95
- TCP:194.68.45.50:6667 Port:16
- TCP:68.178.150.35:8181 Port:16
- TCP:195.50.191.12:7000 Port:16
- TCP:68.178.150.35:8181 Port:16
Help the Webroot Community to fight cyber crime
We are always looking for ways to improve the quality and speed of research to help us protect you from malicious software and cyber crime.
PCMag.com Editors' Choice Award Logo is a trademark of Ziff Davis Publishing Holdings Inc. Used under license.