j7bqszme.exe

Bluetooth Driver Installer

Bluetooth I

The file j7bqszme.exe, “Bluetooth Driver Installer Setup ” has been detected as a potentially unwanted program by 1 anti-malware scanner with very strong indications that the file is a potential threat. The program is a setup application that uses the Inno Setup installer, however the file is not signed with an authenticode signature from a trusted source. The setup program uses the InstallCore engine which may bundle additional software offers including toolbars and browser extensions.
Publisher:
Bluetooth I

Product:
Bluetooth Driver Installer

Description:
Bluetooth Driver Installer Setup

Version:
1.0

MD5:
6878c3aee222caff700600dac62ab514

SHA-1:
213cd8a7d54dffb23aa5f9a27b8fcfbe27d96ded

SHA-256:
02bc9e303d8971e0903c2f92d117ec0d10abad8cb6107a76a8afbb3314f8553c

Scanner detections:
1 / 68

Status:
Potentially unwanted

Explanation:
Uses the InstallCore download manager to install additional potentially unwanted software which may include extensions such as DealPly and various toolbars.

Analysis date:
5/16/2024 3:34:15 PM UTC  (today)

Scan engine
Detection
Engine version

Reason Heuristics
PUP.InstallCore.RE48 (M)
16.5.25.1

File size:
3.2 MB (3,383,841 bytes)

Product version:
1.0

Installer:
Inno Setup

Common path:
C:\users\{user}\appdata\local\temp\j7bqszme.exe.part

File PE Metadata
Compilation timestamp:
6/20/1992 12:22:17 AM

OS version:
1.0

OS bitness:
Win32

Subsystem:
Windows GUI

Linker version:
2.25

CTPH (ssdeep):
98304:3Exa2o5SqpWJv2ZPp90hK4zKAAAe672gZ:+VMsIiKV56J

Entry address:
0xA5F8

Entry point:
55, 8B, EC, 83, C4, C4, 53, 56, 57, 33, C0, 89, 45, F0, 89, 45, DC, E8, CE, 8A, FF, FF, E8, D5, 9C, FF, FF, E8, 64, 9F, FF, FF, E8, 07, A0, FF, FF, E8, A6, BF, FF, FF, E8, 11, E9, FF, FF, E8, 78, EA, FF, FF, 33, C0, 55, 68, C9, AC, 40, 00, 64, FF, 30, 64, 89, 20, 33, D2, 55, 68, 92, AC, 40, 00, 64, FF, 32, 64, 89, 22, A1, 14, C0, 40, 00, E8, 26, F5, FF, FF, E8, 11, F1, FF, FF, 80, 3D, 34, B2, 40, 00, 00, 74, 0C, E8, 23, F6, FF, FF, 33, C0, E8, C4, 97, FF, FF, 8D, 55, F0, 33, C0, E8, B6, C5, FF, FF, 8B, 55...
 
[+]

Packer / compiler:
Inno Setup v5.x - Installer Maker

Code size:
39.5 KB (40,448 bytes)

The file j7bqszme.exe has been seen being distributed by the following 21 URLs.

http://bluetooth-driver-installer.ar.softonic.com/.../3tjQyeLV3cjDp-Hw3sCixsiGa5-fmqSQoKCmmpg=

http://bluetooth-driver-installer.ar.softonic.com/.../3tjQyeLV3cjDp-Hw3sCixsiGa5-fmqWOnqKmlZk=

http://bluetooth-driver-installer.ar.softonic.com/.../3tjQyeLV3cjDp-Hw3sCixsiGa5-fmqSKp5-ikpc=

http://bluetooth-driver.downloadcontent.org/cdn-cgi/.../chk_captcha?id=2c255f91213d25ec&g-recaptcha-response=03AHJ_VuuEU13qInGaD2tfgbGuzGrpyyOmH2NlwCIfy5DuoJwLWCgz5OzS9RpWxX_aBGIFMlFH2NhL5aIzQCa9Jq9MNLSafclZrqJp-rDVqp4iDb7WIdKyWRalXIlBobfpV6XSI2KYSBJ46TSlU2o8idfbxCAxpnI8REG7rmcWX03IpwHP3YFznAyszWouOUp5kRb6WLc8WKZiaEjttvOhe5EG2vK2CRcNUVRpVGGhX6gl0e4qL0MZRGIZqgxOO6cUd2JiFV_kVT1b9-uy8ZzD7UCxle02DTAF3TdVERfJ70zUT8AAcqFyPTH5hfC6BikyoUKiKQx6No1eZDf4Juejkpsa_-5VlmZh-NAuJZdkkXO6HjTTutI80rT-vURxyu_CSIZYvo1aqn90hGqvxS70yL1VqOuDnc2UaUHmxjAy1dIM5ShAM1v_N3zHEY7c6WuqDG4pa2l4SmcVo8F6KgzjTm45QNdfyrLtTdxKz9XF_1AW8Og3z12kmeK2e3CwM7JC60tNPE8Zp-KiJC_qQvpa40wI_V2qpE1wHsnaYhTvn5e07Cu842sdwcQk3oZxsGUqWOQi0NVEcGeIPDQoqhLV5dqcz1JPi4E6SFe8UxPJO3-8A6KcFM9Bj_ankNf7Kg-g3m-I4EHSyb2aq9a9o7shcuWs_-XRvjf7EF3bIXExyR0dr7Vs3GxtWKJQ2meCDHLSPKut8eVepm_2m65GoBxkt7kVfS4lW8O_aFb9sNrnMMbWu24qbn9TH2tVuiDLH-fj2NQb1bQajKya-qguddw9WWmTa1IzbMVScAJBnAcKOcc8jdDUN7WNUvYxFZ_abnD0z4mAFqJP5vPv5rRWqlw8O-pxbwKcuIgIlyEgvPk8qTlEBhdWs42VHWhqt_u

http://bluetooth-driver-installer.th.softonic.com/.../3tjQyeLV3cjDp-Hw3sCixsiGa5-fmqePoqOgl5U=

http://bluetooth-driver-installer.ar.softonic.com/.../3tjQyeLV3cjDp-Hw3sCixsiGa5-fmqONp6WlkZc=

Remove j7bqszme.exe - Powered by Reason Core Security