CostMin

CostMin

Known Adware

by Engaging Apps

What is CostMin?

CostMin is software application developed by Engaging Apps. It is most commonly found on computers running Windows 7 with nearly 62.29% of installations running this operating system. CostMin's installer is typically 569.00 KB in size and installs around 198 files. The most common release is 2.1.0.1310 with 19.06% of all installations currently using this version.

CostMin is most popular in the United States with 25.99% of installations residing in this country.

About CostMin?

CostMin is a web browser extension that functions as adware, redirecting web searches and injecting advertising. When used on Internet Explorer, the program operates as a Browser Helper Object. The add-in is capable of hijacking advertising on unrelated websites, as well as inserting its own advertising in the form of contextual link ads, banner ads, popups, and pop-overs, including on established ad serving sites. The malware is commonly distributed alongside unwanted third-party applications and through web browser vulnerabilities. While the program is equipped with an uninstaller and can be found in the Windows Add/Remove Programs, complete removal may prove challenging and may require the use of an anti-malware product. The Plugin is supported by third-party advertising, and upon downloading it, users will encounter various types of advertisements while browsing the internet, including sponsored links, traditional display advertisements (such as banner ads, "pop-unders," and interstitial ads), coupons, and video targeted ads. Additionally, the plugin may display sponsored links in the form of in-text advertising, and in response to keyword searches made through search engines like Google, Bing, and others.

Multiple virus scanners have detected malware in CostMin.

dMVT.dll (MD5: e9b27306a18f18b88945cdf066de2fc9) has been flagged by 21 scanners:
Scanner Software Result
avast! Win32:BHO-AML [Spy]
AVG Generic5.AFXS
Bkav FE HW32.Laneul.tesi
Comodo Security ApplicUnwnt
Dr.Web Trojan.Crossrider.3
ESET-NOD32 a variant of Win32/Adware.MultiPlug.I
K7 AntiVirus Riskware
K7GW Riskware
Kingsoft AntiVirus Win32.Troj.Generic.a.(kcloud)
Malwarebytes PUP.Optional.MultiPlug.A
McAfee Artemis!E9B27306A18F
McAfee-GW-Edition Artemis!E9B27306A18F
VIPRE Antivirus Trojan.Win32.Generic!BT
AhnLab-V3 Dropper/Win32.Preloader
Baidu-International Adware.Win32.MultiPlug.T
TrendMicro-HouseCall TROJ_GEN.F47V0417
Antiy-AVL Trojan/Win32.TGeneric
Symantec WS.Reputation.1
Sophos FastSave
Vba32 AntiVirus BScope.Adware.MegaSearch
ViRobot Adware.Agent.695808
51d15c58d70ab.dll (MD5: 05234975b085632d70d89c2f420c5107) has been flagged by 15 scanners:
Scanner Software Result
AhnLab-V3 Adware/Win32.MegaSearch
Comodo Security ApplicUnwnt
ESET-NOD32 a variant of Win32/Adware.MultiPlug.I
Kingsoft AntiVirus Win32.Troj.MultiPlug.I.(kcloud)
Sophos FastSave
Vba32 AntiVirus BScope.Adware.MegaSearch
VIPRE Antivirus Trojan.Win32.Generic!BT
AVG Generic5.AVNH
Baidu-International Adware.Win32.BHO.45
McAfee-GW-Edition Heuristic.BehavesLike.Win32.Suspicious.H
Symantec WS.Reputation.1
avast! Win32:MultiPlug-AD [PUP]
Malwarebytes PUP.Optional.MultiPlug.A
ViRobot Adware.Agent.695808
TrendMicro-HouseCall TROJ_GEN.F47V0519
WUoUq2uCsc.exe (MD5: 028c1a42ac6ff8fc1798d94718ed480f) has been flagged by 25 scanners:
Scanner Software Result
Lavasoft Ad-Aware Application.Generic.621135
AhnLab-V3 Dropper/Win32.Preloader
avast! Win32:MultiPlug-AD [PUP]
AVG Generic_r.JW
Baidu-International Adware.Win32.MultiPlug.45
Bitdefender Application.Generic.621135
Comodo Security ApplicUnwnt
ESET-NOD32 a variant of Win32/AdWare.MultiPlug.T
G Data Application.Generic.621135
K7GW Adware ( 004976341 )
Malwarebytes PUP.Optional.MultiPlug.A
MicroWorld-eScan Application.Generic.621135
TrendMicro-HouseCall TROJ_GEN.F47V0416
VIPRE Antivirus Trojan.Win32.Generic!BT
Bkav FE HW32.Laneul.tesi
Dr.Web Trojan.Crossrider.3
K7 AntiVirus Riskware
Kingsoft AntiVirus Win32.Troj.Generic.a.(kcloud)
McAfee Artemis!E9B27306A18F
McAfee-GW-Edition Artemis!E9B27306A18F
Antiy-AVL Trojan/Win32.TGeneric
Symantec WS.Reputation.1
Sophos FastSave
Vba32 AntiVirus BScope.Adware.MegaSearch
ViRobot Adware.Agent.695808
6pM.exe (MD5: 0920b67a31662468e9eafdb6d9bc0f72) has been flagged by 18 scanners:
Scanner Software Result
AhnLab-V3 Dropper/Win32.Preloader
avast! Win32:MultiPlug-AD [PUP]
AVG Generic_r.JW
Baidu-International Adware.Win32.MultiPlug.T
Comodo Security Application.Win32.MultiPlug.SJ
ESET-NOD32 a variant of Win32/AdWare.MultiPlug.T
K7GW Adware ( 004976341 )
Malwarebytes PUP.Optional.MultiPlug.A
McAfee Artemis!0920B67A3166
McAfee-GW-Edition Heuristic.BehavesLike.Win32.Suspicious.H
TrendMicro-HouseCall TROJ_GEN.F47V0417
VIPRE Antivirus Trojan.Win32.Generic!BT
Antiy-AVL Trojan/Win32.TGeneric
Symantec WS.Reputation.1
Kingsoft AntiVirus Win32.Troj.MultiPlug.I.(kcloud)
Sophos FastSave
Vba32 AntiVirus BScope.Adware.MegaSearch
ViRobot Adware.Agent.695808
WfHRqId.exe (MD5: 074fdbec16dcf4bc211b27f64c3512ae) has been flagged by 17 scanners:
Scanner Software Result
AhnLab-V3 Dropper/Win32.Preloader
Antiy-AVL Trojan/Win32.TGeneric
avast! Win32:MultiPlug-BC [PUP]
AVG Generic5.AVSA
Baidu-International Adware.Win32.BHO.77
ESET-NOD32 a variant of Win32/AdWare.MultiPlug.Y
Malwarebytes PUP.Optional.MultiPlug.A
McAfee Artemis!074FDBEC16DC
McAfee-GW-Edition Heuristic.BehavesLike.Win32.Suspicious.H
TrendMicro-HouseCall Suspicious_GEN.F47V0610
Comodo Security ApplicUnwnt
Symantec WS.Reputation.1
VIPRE Antivirus Trojan.Win32.Generic!BT
Kingsoft AntiVirus Win32.Troj.MultiPlug.I.(kcloud)
Sophos FastSave
Vba32 AntiVirus BScope.Adware.MegaSearch
ViRobot Adware.Agent.695808

Software Details

URL:
https://costmin.info
Support:
https://advertising-support.com
Installation path:
C:\Documents and Settings\user\Application data\costmin
Uninstaller:
"C:\Documents and Settings\user\Application Data\CostMin\2fsUX.exe" /s /n /C:"ExecuteCommands;UninstallCommands" ""
Size:
569.00 KB
Language:
English

CostMin Executable Details

Primary executable:
2fsUX.exe
Name:
CostMin
Path:
C:\Documents and Settings\user\Application data\costmin\2fsUX.exe
MD5:
8300c91b40229b42301aebc6d8859907
SHA-1:
–
SHA-256:
–
Files installed by CostMin
File Type Filename MD5
EXE
cd96bce629519e02130fccabed82e34d
EXE
2dd98c60fd16fbc5f483f1f07f459419
EXE
337bc5dafed0202a03e92dc521f18f09
EXE
5b91c901260f18fa051e5afb427a9028
EXE
499942c1bea81097cfe869be98ec3c01
EXE
6c480b6b249f21d2e8dd4488cb07242a
EXE
0c94d800bf8df25b08d7b4532824720b
EXE
eec2ef5ff7152ab0155d8a119b50d995
EXE
28148ba4d49308339ebb580daf3204fb
EXE
4880f52ed118d0e25ad7616ab1695452