Home Malware Programs Potentially Unwanted Programs (PUPs) Consumer Input

Consumer Input

Posted: July 3, 2014

Threat Metric

Ranking: 5,144
Threat Level: 1/10
Infected PCs: 137,992
First Seen: July 3, 2014
Last Seen: March 7, 2025
OS(es) Affected: Windows

PUP.Consumer Input is a Web traffic-analyzing utility that monitors your website-browsing habits without attempting to collect information (passwords, e-mail addresses, et cetera). Because this behavior doesn't benefit your PC, and because PUP.Consumer Input has some traits in common with Potentially Unwanted Program, deleting PUP.Consumer Input and other PUPs usually is best for your PC, and can be done through most of the usual security tools.

The Add-On that Wants Your Input on Website Popularity

PUP.Consumer Input is a toolbar that may be found in different versions of Chrome, Internet Explorer and Firefox. PUP.Consumer Input may be bundled with the Yahoo Software Update, an update manager that may be part of the Yahoo Toolbar. Some incidents also have been identified where PUP.Consumer Input was installed automatically, although there isn't any evidence that would associate PUP.Consumer Input to threat attacks or other kinds of threatening software practices.

PUP.Consumer Input may monitor the sites that you visit without trying to gather any legally-protected information that would make this add-on equivalent to spyware, ostensibly for the purpose of ranking websites according to their number of visitors. However, although PUP.Consumer Input confines its functions to legal behavior, PUP.Consumer Input does not have any known advantages for its use, and only should be considered for long-term installation for PC users who don't mind giving companies non-personal information for its own sake. In cases where PUP.Consumer Input interferes with your browser's performance or simply is unwanted, uninstalling PUP.Consumer Input is the response that malware researchers would advise.

Keeping Your Own Input on Your Browser's Add-Ons from Being Ignored

Besides, fundamentally, being a program without benefits to its users, PUP.Consumer Input also has a history of being installed improperly. Some of the most recent PUP.Consumer Input installations even exploit system permission settings to block their deletion, a widespread behavior amongst both other PUPs and threats. While malware experts have not yet confirmed how widespread this problem is, it does place additional evidence on the likelihood of removing PUP.Consumer Input being a good idea for your PC's performance and safety.

If you experience any problems with deleting PUP.Consumer Input or side effects after an incomplete deletion, using dedicated PC security software can assure that your computer no longer is being used to funnel traffic information to a third-party company. As usual for any PUP, deleting the browser that happens to be affected by PUP.Consumer Input explicitly is discouraged by malware analysts, who find little to gain from such actions. The removal of PUP.Consumer Input should include actions that target this software as a specific program, rather than 'cures' that circumvent PUP.Consumer Input by removing your Web browser or changing the browser's superficial settings.

Aliases

PUA.Compete [Ikarus]Win32.Application.Agent.VGHEAB [GData]Artemis!PUP [McAfee-GW-Edition]Adware.Compete.1 [DrWeb]Generic PUA OJ (PUA) [Sophos]Win32:Malware-gen [Avast]Artemis!A9C69837EC78 [McAfee]Artemis!42E77A08ED9B [McAfee]Generic.381 [AVG]BehavesLike.Win32.BadFile.th [McAfee-GW-Edition]Artemis!0F3433C84718 [McAfee]Infostealer.Consmiper [Symantec]

Technical Details

File System Modifications

Tutorials: If you wish to learn how to remove malware components manually, you can read the tutorials on how to find malware, kill unwanted processes, remove malicious DLLs and delete other harmful files. Always be sure to back up your PC before making any changes.

The following files were created in the system:



C:\Program Files\Consumer Input\Update\ConsumerInputUpdate.exe File name: ConsumerInputUpdate.exe
Size: 105.94 KB (105944 bytes)
MD5: 7b110c27e90217ff3bd49cef739a2e1d
Detection count: 853
File type: Executable File
Mime Type: unknown/exe
Path: C:\Program Files\Consumer Input\Update\ConsumerInputUpdate.exe
Group: Malware file
Last Updated: August 21, 2023
C:\Program Files (x86)\Consumer Input\InternetExplorer\x64\dca-bho.dll File name: dca-bho.dll
Size: 1.17 MB (1174544 bytes)
MD5: 6a967ae8da20832f3d3c959181deda83
Detection count: 244
File type: Dynamic link library
Mime Type: unknown/dll
Path: C:\Program Files (x86)\Consumer Input\InternetExplorer\x64\dca-bho.dll
Group: Malware file
Last Updated: October 25, 2022
C:\Program Files (x86)\YourHelper\cinput.exe File name: cinput.exe
Size: 1.89 MB (1897800 bytes)
MD5: bc308733568e737020e57b7b1f728cd2
Detection count: 157
File type: Executable File
Mime Type: unknown/exe
Path: C:\Program Files (x86)\YourHelper\cinput.exe
Group: Malware file
Last Updated: May 27, 2022
%TEMP%\is-CGV9J.tmp\c10w.exe File name: c10w.exe
Size: 145.4 KB (145408 bytes)
MD5: c761c275bac28f9e02d638cf3d372864
Detection count: 59
File type: Executable File
Mime Type: unknown/exe
Path: %TEMP%\is-CGV9J.tmp
Group: Malware file
Last Updated: October 22, 2020
%TEMP%\compete.exe File name: compete.exe
Size: 1.91 MB (1915232 bytes)
MD5: a9c69837ec78126315335e6814781730
Detection count: 7
File type: Executable File
Mime Type: unknown/exe
Path: %TEMP%
Group: Malware file
Last Updated: March 24, 2020

More files

Registry Modifications

The following newly produced Registry Values are:

CLSID{0492079D-0CB5-424C-A3A5-F965B84E82D9}{06306AA5-80A1-4260-A9A3-A8E10F6AA8B7}{0C6D49F4-6E41-4632-BE86-F210D5D894BA}{0DC6DC6C-048E-4B03-8F2D-7D6B90571172}{0E02C3DE-FDA9-4381-99E6-7ED76A518504}{15527BF5-9729-49DC-889C-9F956983154C}{1AB0B6A3-9BC5-419B-B86D-40FA2998A131}{1E218D71-6C28-46EE-AC6A-20C95989D566}{268205B6-13E6-4FA2-A1EF-84E4E59F3F1B}{294BC5A4-7157-4131-AB81-1DEC393D0F0A}{2A142934-F3E4-4D68-A360-3FE35783E849}{37EB1FA3-2181-4EED-8C9F-363068501901}{3A40DF53-EB22-49FE-9246-8084403424E7}{3DBBAB3C-4077-4EC4-BF2C-E89C7784846A}{41E3E6E6-3E50-4F6E-A1F8-1E24440BC6F8}{4F3440C0-EB6A-46F2-94D8-2D74A0D21C5D}{52C0A3BA-1DE8-477D-91F4-F82D3824C304}{55D12CB4-DA12-43D6-8100-90174ABBB84F}{58AC6DE8-F15B-4C6A-91D7-B8FA6A2F4169}{592DA852-5C4E-49F8-88BC-EA0A893180C6}{5A43377F-504A-4FC4-8575-9C98997788BF}{5CF02202-6278-47EE-9947-C2D0A057EABD}{5E8F3A92-7544-482D-9D34-FFD702697D16}{60260024-AA48-4A2F-84DA-2C2DCB24AAD0}{65BF611F-85CD-4E7F-966C-853573462C14}{7096D298-02B5-4AE9-94E1-C16E27553D17}{7BAB653D-88FB-4F60-AFC2-8E6FD59FAFF3}{7D87094D-49E1-4C72-8C9E-3D937A119BE5}{82025773-B1B0-497b-B942-0171A2E42C3C}{837641EA-9158-43EE-B2A1-9CEDC5CBD98F}{87A125E5-B663-496F-954E-488A82FAC012}{8AF9C44C-E497-4776-A7EF-F6455F982825}{9147B929-DCC3-4187-B1BE-5B12DDAB7D20}{95C8DE84-989C-4235-A5B1-84E8B6A4384A}{977ED000-4ECA-454D-AEA2-11824E57A043}{A57F7191-1E7F-4852-BAAF-F80A43E2687A}{AC992757-3DEC-43C4-8D9D-AA82F8A857E4}{B49699FC-1665-4414-A1CB-C4A2A4A13EEC}{C015D269-0F4E-4B52-A91F-721F6DAC9437}{C59D48E5-082B-4BB6-9838-BA261C4FBD5C}{CB21D37D-1DD1-444A-AB6A-AE623DF7B4E4}{CCE83B2E-3794-41FC-8179-46BFEA22148A}{D2A19E15-4D23-41F5-8035-E2D730DA691C}{D4F484EE-BF68-4B61-AB83-C1E0EF88D876}{D5FA0C65-08BE-4F86-B30F-2E285694863A}{D8F06F2A-FDCE-4F12-8D2A-7A97A752CF1A}{DD05B915-F77B-474A-9D42-9FEEAF5475C4}{DD7C44CC-0F60-4FD9-A38F-5CF30D698AC2}{E3B8A2CD-70B5-49A4-BFD6-0180BE487A4C}{E3EBCC2D-D239-4CA9-BF77-8DC68381D6CA}{E98F6ADA-0655-45F4-9141-9F7A18C5B46B}{F90B8F59-792D-4F5A-97AD-06E83284F9AB}{FA326D8A-B632-4BCE-858E-12271ABAF613}{FB3B0E75-E48E-47C4-BA52-57B7F6E38510}{FD20C151-A061-4097-955D-682F317A7035}{FFA4D25D-8411-40F8-919D-3C4CD94FBD29}File name without pathhttps_www.consumerinput.com_0.localstoragehttps_www.consumerinput.com_0.localstorage-journalwww.consumerinput[1].xmlRegexp file mask%HOMEDRIVE%\compete-header-long2.bmp%temp%\ConsumerInputSetup.exe%WINDIR%\System32\Tasks\CIMT_[RANDOM CHARACTERS]%WINDIR%\System32\Tasks\ConsumerInputUpdateTaskMachineCore%WINDIR%\System32\Tasks\ConsumerInputUpdateTaskMachineUA%WINDIR%\Tasks\CIMT_[RANDOM CHARACTERS]%WINDIR%\Tasks\ConsumerInputUpdateTaskMachineCore.job%WINDIR%\Tasks\ConsumerInputUpdateTaskMachineUA.jobHKEY..\..\..\..{RegistryKeys}Software\AppDataLow\Software\CompeteSOFTWARE\Classes\AppID\ConsumerInputUpdate.exeSOFTWARE\Classes\AppID\CptUrlPassthru.DLLSOFTWARE\Classes\AppID\dca-bho.DLLSOFTWARE\Classes\AppID\dca-host.exeSOFTWARE\Classes\CptUrlPassthru.HttpHeadersSOFTWARE\Classes\CptUrlPassthru.HttpMonitorSOFTWARE\Classes\dcabho.DcaSOFTWARE\Classes\dcabho.Dca.1SOFTWARE\Classes\DcaHost.DcaHostSOFTWARE\Classes\DcaHost.DcaHost.1SOFTWARE\Classes\Wow6432Node\AppID\ConsumerInputUpdate.exeSOFTWARE\Classes\Wow6432Node\AppID\dca-bho.DLLSOFTWARE\Classes\Wow6432Node\AppID\dca-host.exeSoftware\CompeteSOFTWARE\CompeteIncSoftware\ConsumerInputSOFTWARE\Google\Chrome\NativeMessagingHosts\com.compete.cinmSoftware\Microsoft\Internet Explorer\Approved Extensions\{B49699FC-1665-4414-A1CB-C4A2A4A13EEC}Software\Microsoft\Internet Explorer\DOMStorage\consumerinput.comSoftware\Microsoft\Internet Explorer\DOMStorage\www.consumerinput.comSOFTWARE\Microsoft\Internet Explorer\Low Rights\ElevationPolicy\{7D87094D-49E1-4C72-8C9E-3D937A119BE5}SOFTWARE\Microsoft\Internet Explorer\Low Rights\ElevationPolicy\{F90B8F59-792D-4F5A-97AD-06E83284F9AB}Software\Microsoft\Internet Explorer\New Windows\Allow\www.consumerinput.comSOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\ConsumerInputUpdate.exeSOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\CompatibilityAdapter\Signatures\ConsumerInputUpdateTaskMachineCore.jobSOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\CompatibilityAdapter\Signatures\ConsumerInputUpdateTaskMachineCore.job.fpSOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\CompatibilityAdapter\Signatures\ConsumerInputUpdateTaskMachineUA.jobSOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\CompatibilityAdapter\Signatures\ConsumerInputUpdateTaskMachineUA.job.fpSOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tree\ConsumerInputUpdateTaskMachineCoreSOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tree\ConsumerInputUpdateTaskMachineUASOFTWARE\Microsoft\Windows\CurrentVersion\explorer\Browser Helper Objects\{B49699FC-1665-4414-A1CB-C4A2A4A13EEC}Software\Mozilla\Firefox\Extensions\ConsumerInput@CompeteSOFTWARE\Wow6432Node\Classes\AppID\ConsumerInputUpdate.exeSOFTWARE\Wow6432Node\Classes\AppID\CptUrlPassthru.DLLSOFTWARE\Wow6432Node\Classes\AppID\dca-bho.DLLSOFTWARE\Wow6432Node\Classes\AppID\dca-host.exeSOFTWARE\Wow6432Node\CompeteIncSOFTWARE\Wow6432Node\ConsumerInputSOFTWARE\Wow6432Node\Google\Chrome\NativeMessagingHosts\com.compete.cinmSOFTWARE\Wow6432Node\Microsoft\Internet Explorer\Low Rights\ElevationPolicy\{7D87094D-49E1-4C72-8C9E-3D937A119BE5}SOFTWARE\Wow6432Node\Microsoft\Internet Explorer\Low Rights\ElevationPolicy\{F90B8F59-792D-4F5A-97AD-06E83284F9AB}SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\explorer\Browser Helper Objects\{B49699FC-1665-4414-A1CB-C4A2A4A13EEC}SYSTEM\ControlSet001\services\consumerinput_updateSYSTEM\ControlSet001\services\consumerinput_updatemSYSTEM\ControlSet002\services\consumerinput_updateSYSTEM\ControlSet002\services\consumerinput_updatemSYSTEM\CurrentControlSet\services\consumerinput_updateSYSTEM\CurrentControlSet\services\consumerinput_updatemHKEY_LOCAL_MACHINE\Software\[APPLICATION]\Microsoft\Windows\CurrentVersion\Uninstall..{Uninstaller}Consumer Input InstallerSetup Support for Consumer InputSetup Support for Consumer Input DH

Additional Information

The following directories were created:
%LOCALAPPDATA%\Consumer Input%PROGRAMFILES%\Consumer Input%PROGRAMFILES%\Setup Support for Consumer Input%PROGRAMFILES%\Setup Support for Consumer Input DH%PROGRAMFILES(X86)%\Consumer Input%PROGRAMFILES(X86)%\Setup Support for Consumer Input%PROGRAMFILES(X86)%\Setup Support for Consumer Input DH%UserProfile%\Local Settings\Application Data\Consumer Input%appdata%\Compete\Consumer Input
Loading...