CostMin

CostMin

Known Adware

by Engaging Apps

What is CostMin?

CostMin is software application developed by Engaging Apps. It is most commonly found on computers running Windows 7 with nearly 62.29% of installations running this operating system. CostMin's installer is typically 569.00 KB in size and installs around 198 files. The most common release is 2.1.0.1310 with 19.06% of all installations currently using this version.

CostMin is most popular in the United States with 25.99% of installations residing in this country.

About CostMin?

CostMin is a web browser extension that functions as adware, redirecting web searches and injecting advertising. When used on Internet Explorer, the program operates as a Browser Helper Object. The add-in is capable of hijacking advertising on unrelated websites, as well as inserting its own advertising in the form of contextual link ads, banner ads, popups, and pop-overs, including on established ad serving sites. The malware is commonly distributed alongside unwanted third-party applications and through web browser vulnerabilities. While the program is equipped with an uninstaller and can be found in the Windows Add/Remove Programs, complete removal may prove challenging and may require the use of an anti-malware product. The Plugin is supported by third-party advertising, and upon downloading it, users will encounter various types of advertisements while browsing the internet, including sponsored links, traditional display advertisements (such as banner ads, "pop-unders," and interstitial ads), coupons, and video targeted ads. Additionally, the plugin may display sponsored links in the form of in-text advertising, and in response to keyword searches made through search engines like Google, Bing, and others.

Multiple virus scanners have detected malware in CostMin.

dMVT.dll (MD5: e9b27306a18f18b88945cdf066de2fc9) has been flagged by 21 scanners:
Scanner Software Result
avast! Win32:BHO-AML [Spy]
AVG Generic5.AFXS
Bkav FE HW32.Laneul.tesi
Comodo Security ApplicUnwnt
Dr.Web Trojan.Crossrider.3
ESET-NOD32 a variant of Win32/Adware.MultiPlug.I
K7 AntiVirus Riskware
K7GW Riskware
Kingsoft AntiVirus Win32.Troj.Generic.a.(kcloud)
Malwarebytes PUP.Optional.MultiPlug.A
McAfee Artemis!E9B27306A18F
McAfee-GW-Edition Artemis!E9B27306A18F
VIPRE Antivirus Trojan.Win32.Generic!BT
AhnLab-V3 Dropper/Win32.Preloader
Baidu-International Adware.Win32.MultiPlug.T
TrendMicro-HouseCall TROJ_GEN.F47V0417
Antiy-AVL Trojan/Win32.TGeneric
Symantec WS.Reputation.1
Sophos FastSave
Vba32 AntiVirus BScope.Adware.MegaSearch
ViRobot Adware.Agent.695808
51d15c58d70ab.dll (MD5: 05234975b085632d70d89c2f420c5107) has been flagged by 15 scanners:
Scanner Software Result
AhnLab-V3 Adware/Win32.MegaSearch
Comodo Security ApplicUnwnt
ESET-NOD32 a variant of Win32/Adware.MultiPlug.I
Kingsoft AntiVirus Win32.Troj.MultiPlug.I.(kcloud)
Sophos FastSave
Vba32 AntiVirus BScope.Adware.MegaSearch
VIPRE Antivirus Trojan.Win32.Generic!BT
AVG Generic5.AVNH
Baidu-International Adware.Win32.BHO.45
McAfee-GW-Edition Heuristic.BehavesLike.Win32.Suspicious.H
Symantec WS.Reputation.1
avast! Win32:MultiPlug-AD [PUP]
Malwarebytes PUP.Optional.MultiPlug.A
ViRobot Adware.Agent.695808
TrendMicro-HouseCall TROJ_GEN.F47V0519
WUoUq2uCsc.exe (MD5: 028c1a42ac6ff8fc1798d94718ed480f) has been flagged by 25 scanners:
Scanner Software Result
Lavasoft Ad-Aware Application.Generic.621135
AhnLab-V3 Dropper/Win32.Preloader
avast! Win32:MultiPlug-AD [PUP]
AVG Generic_r.JW
Baidu-International Adware.Win32.MultiPlug.45
Bitdefender Application.Generic.621135
Comodo Security ApplicUnwnt
ESET-NOD32 a variant of Win32/AdWare.MultiPlug.T
G Data Application.Generic.621135
K7GW Adware ( 004976341 )
Malwarebytes PUP.Optional.MultiPlug.A
MicroWorld-eScan Application.Generic.621135
TrendMicro-HouseCall TROJ_GEN.F47V0416
VIPRE Antivirus Trojan.Win32.Generic!BT
Bkav FE HW32.Laneul.tesi
Dr.Web Trojan.Crossrider.3
K7 AntiVirus Riskware
Kingsoft AntiVirus Win32.Troj.Generic.a.(kcloud)
McAfee Artemis!E9B27306A18F
McAfee-GW-Edition Artemis!E9B27306A18F
Antiy-AVL Trojan/Win32.TGeneric
Symantec WS.Reputation.1
Sophos FastSave
Vba32 AntiVirus BScope.Adware.MegaSearch
ViRobot Adware.Agent.695808
6pM.exe (MD5: 0920b67a31662468e9eafdb6d9bc0f72) has been flagged by 18 scanners:
Scanner Software Result
AhnLab-V3 Dropper/Win32.Preloader
avast! Win32:MultiPlug-AD [PUP]
AVG Generic_r.JW
Baidu-International Adware.Win32.MultiPlug.T
Comodo Security Application.Win32.MultiPlug.SJ
ESET-NOD32 a variant of Win32/AdWare.MultiPlug.T
K7GW Adware ( 004976341 )
Malwarebytes PUP.Optional.MultiPlug.A
McAfee Artemis!0920B67A3166
McAfee-GW-Edition Heuristic.BehavesLike.Win32.Suspicious.H
TrendMicro-HouseCall TROJ_GEN.F47V0417
VIPRE Antivirus Trojan.Win32.Generic!BT
Antiy-AVL Trojan/Win32.TGeneric
Symantec WS.Reputation.1
Kingsoft AntiVirus Win32.Troj.MultiPlug.I.(kcloud)
Sophos FastSave
Vba32 AntiVirus BScope.Adware.MegaSearch
ViRobot Adware.Agent.695808
WfHRqId.exe (MD5: 074fdbec16dcf4bc211b27f64c3512ae) has been flagged by 17 scanners:
Scanner Software Result
AhnLab-V3 Dropper/Win32.Preloader
Antiy-AVL Trojan/Win32.TGeneric
avast! Win32:MultiPlug-BC [PUP]
AVG Generic5.AVSA
Baidu-International Adware.Win32.BHO.77
ESET-NOD32 a variant of Win32/AdWare.MultiPlug.Y
Malwarebytes PUP.Optional.MultiPlug.A
McAfee Artemis!074FDBEC16DC
McAfee-GW-Edition Heuristic.BehavesLike.Win32.Suspicious.H
TrendMicro-HouseCall Suspicious_GEN.F47V0610
Comodo Security ApplicUnwnt
Symantec WS.Reputation.1
VIPRE Antivirus Trojan.Win32.Generic!BT
Kingsoft AntiVirus Win32.Troj.MultiPlug.I.(kcloud)
Sophos FastSave
Vba32 AntiVirus BScope.Adware.MegaSearch
ViRobot Adware.Agent.695808

Software Details

URL:
https://costmin.info
Support:
https://advertising-support.com
Installation path:
C:\Documents and Settings\user\Application data\costmin
Uninstaller:
"C:\Documents and Settings\user\Application Data\CostMin\2fsUX.exe" /s /n /C:"ExecuteCommands;UninstallCommands" ""
Size:
569.00 KB
Language:
English

CostMin Executable Details

Primary executable:
2fsUX.exe
Name:
CostMin
Path:
C:\Documents and Settings\user\Application data\costmin\2fsUX.exe
MD5:
8300c91b40229b42301aebc6d8859907
SHA-1:
–
SHA-256:
–
Files installed by CostMin
File Type Filename MD5
EXE
6b42b90360ec3c62b9595fa4b8b4f865
EXE
065304393f1dd01ca86d5aeed8fa6609
EXE
1fe4ddeeb4611fa449a62623ba21ead6
EXE
2c28bb7908a09a40a4a53c73da4c4387
EXE
9392d64a6fa51e94ea5c84741aea74c4
DLL
dMVT.dll
Adware
e9b27306a18f18b88945cdf066de2fc9
DLL
05234975b085632d70d89c2f420c5107
EXE
028c1a42ac6ff8fc1798d94718ed480f
EXE
6pM.exe
Adware
0920b67a31662468e9eafdb6d9bc0f72
EXE
074fdbec16dcf4bc211b27f64c3512ae