ciuninstall.exe

Compete Inc

The application ciuninstall.exe by Compete Inc has been detected as a potentially unwanted program by 1 anti-malware scanner with very strong indications that the file is a potential threat. The program is a setup application that uses the NSIS (Nullsoft Scriptable Install System) installer. This is the uninstaller utility registered in the Windows Control Panel for the program Consumer Input (remove only) by Compete Inc..
Publisher:
Compete Inc  (signed and verified)

Version:
3.2.3.3014

MD5:
cbadbf6f8fd37af29e218861788f430f

SHA-1:
81b6cabc41e73f8082554c71477bf965e7866204

SHA-256:
3366d1ea7ece9c17d4d9a7809284e72b8a9ae3e4928e48f7e16a8c9fb7cc191b

Scanner detections:
1 / 68

Status:
Potentially unwanted

Note:
Our current pool of anti-malware engines have not currently detected this file, however based on our own detection heuristics we feel that this file is unwanted.

Analysis date:
12/24/2024 12:05:34 PM UTC  (today)

Scan engine
Detection
Engine version

Reason Heuristics
PUP.Compete (M)
16.8.12.9

File size:
120.2 KB (123,064 bytes)

Product version:
3.2.3.3014

File type:
Executable application (Win32 EXE)

Installer:
NSIS (Nullsoft Scriptable Install System)

Language:
Language Neutral

Common path:
C:\Program Files\consumer input\ciuninstall.exe

Digital Signature
Signed by:

Authority:
VeriSign, Inc.

Valid from:
2/6/2012 7:00:00 PM

Valid to:
1/10/2015 6:59:59 PM

Subject:
CN=Compete Inc, OU=operations, OU=Digital ID Class 3 - Microsoft Software Validation v2, O=Compete Inc, L=Boston, S=Massachusetts, C=US

Issuer:
CN=VeriSign Class 3 Code Signing 2010 CA, OU=Terms of use at https://www.verisign.com/rpa (c)10, OU=VeriSign Trust Network, O="VeriSign, Inc.", C=US

Serial number:
4A4ACAE072F8065D9C03E2A2240975B0

File PE Metadata
Compilation timestamp:
12/5/2009 5:53:24 PM

OS version:
4.0

OS bitness:
Win32

Subsystem:
Windows GUI

Linker version:
6.0

CTPH (ssdeep):
3072:QCuFP2lXIHDgXJFud3JrQtQp1GPt9eQQ2dg1dO8:Q183Kd3JrQI1GPu52d2db

Entry address:
0x355E

Entry point:
81, EC, 80, 01, 00, 00, 53, 55, 56, 33, DB, 57, 89, 5C, 24, 18, C7, 44, 24, 10, B8, A7, 40, 00, 33, F6, C6, 44, 24, 14, 20, FF, 15, 30, 80, 40, 00, 68, 01, 80, 00, 00, FF, 15, B0, 80, 40, 00, 53, FF, 15, 88, 82, 40, 00, 6A, 08, A3, 98, 10, 43, 00, E8, D6, 2E, 00, 00, A3, E4, 0F, 43, 00, 53, 8D, 44, 24, 34, 68, 60, 01, 00, 00, 50, 53, 68, E8, A7, 42, 00, FF, 15, 58, 81, 40, 00, 68, AC, A7, 40, 00, 68, E0, 07, 43, 00, E8, DC, 29, 00, 00, FF, 15, AC, 80, 40, 00, BF, 00, 70, 43, 00, 50, 57, E8, CA, 29, 00, 00...
 
[+]

Entropy:
7.3193

Packer / compiler:
Nullsoft install system v2.x

Code size:
25 KB (25,600 bytes)

Program Uninstaller
Program name:
Consumer Input (remove only)

Display publisher:
Compete Inc.

Uninstall string:
"C:\Program Files (x86)\Consumer Input\CIuninstall.exe"


Remove ciuninstall.exe - Powered by Reason Core Security