Csr Harmony Bluetooth Software Stack
I was quite surprised as I saw too very suspicious root certificates in my CA store. These were installed by a Bluetooth driver from CSR.
Csr Harmony Bluetooth Stack Download
Csr Harmony Bluetooth Software
Obviously this enables interception of HTTPS connections if the private key is found. Additionally it injected certs into the 'trusted publisher store', which means it can also fake digital signatures. The worst thing are the certificates itself - they are 1024bit RSA certificates, which are very insecure, so that it may be possible to crack the public key and get out the private key. More information here: And here you can see how it injects it.