CostMin

CostMin

Known Adware

by Engaging Apps

What is CostMin?

CostMin is software application developed by Engaging Apps. It is most commonly found on computers running Windows 7 with nearly 62.29% of installations running this operating system. CostMin's installer is typically 569.00 KB in size and installs around 198 files. The most common release is 2.1.0.1310 with 19.06% of all installations currently using this version.

CostMin is most popular in the United States with 25.99% of installations residing in this country.

About CostMin?

CostMin is a web browser extension that functions as adware, redirecting web searches and injecting advertising. When used on Internet Explorer, the program operates as a Browser Helper Object. The add-in is capable of hijacking advertising on unrelated websites, as well as inserting its own advertising in the form of contextual link ads, banner ads, popups, and pop-overs, including on established ad serving sites. The malware is commonly distributed alongside unwanted third-party applications and through web browser vulnerabilities. While the program is equipped with an uninstaller and can be found in the Windows Add/Remove Programs, complete removal may prove challenging and may require the use of an anti-malware product. The Plugin is supported by third-party advertising, and upon downloading it, users will encounter various types of advertisements while browsing the internet, including sponsored links, traditional display advertisements (such as banner ads, "pop-unders," and interstitial ads), coupons, and video targeted ads. Additionally, the plugin may display sponsored links in the form of in-text advertising, and in response to keyword searches made through search engines like Google, Bing, and others.

Multiple virus scanners have detected malware in CostMin.

dMVT.dll (MD5: e9b27306a18f18b88945cdf066de2fc9) has been flagged by 21 scanners:
Scanner Software Result
avast! Win32:BHO-AML [Spy]
AVG Generic5.AFXS
Bkav FE HW32.Laneul.tesi
Comodo Security ApplicUnwnt
Dr.Web Trojan.Crossrider.3
ESET-NOD32 a variant of Win32/Adware.MultiPlug.I
K7 AntiVirus Riskware
K7GW Riskware
Kingsoft AntiVirus Win32.Troj.Generic.a.(kcloud)
Malwarebytes PUP.Optional.MultiPlug.A
McAfee Artemis!E9B27306A18F
McAfee-GW-Edition Artemis!E9B27306A18F
VIPRE Antivirus Trojan.Win32.Generic!BT
AhnLab-V3 Dropper/Win32.Preloader
Baidu-International Adware.Win32.MultiPlug.T
TrendMicro-HouseCall TROJ_GEN.F47V0417
Antiy-AVL Trojan/Win32.TGeneric
Symantec WS.Reputation.1
Sophos FastSave
Vba32 AntiVirus BScope.Adware.MegaSearch
ViRobot Adware.Agent.695808
51d15c58d70ab.dll (MD5: 05234975b085632d70d89c2f420c5107) has been flagged by 15 scanners:
Scanner Software Result
AhnLab-V3 Adware/Win32.MegaSearch
Comodo Security ApplicUnwnt
ESET-NOD32 a variant of Win32/Adware.MultiPlug.I
Kingsoft AntiVirus Win32.Troj.MultiPlug.I.(kcloud)
Sophos FastSave
Vba32 AntiVirus BScope.Adware.MegaSearch
VIPRE Antivirus Trojan.Win32.Generic!BT
AVG Generic5.AVNH
Baidu-International Adware.Win32.BHO.45
McAfee-GW-Edition Heuristic.BehavesLike.Win32.Suspicious.H
Symantec WS.Reputation.1
avast! Win32:MultiPlug-AD [PUP]
Malwarebytes PUP.Optional.MultiPlug.A
ViRobot Adware.Agent.695808
TrendMicro-HouseCall TROJ_GEN.F47V0519
WUoUq2uCsc.exe (MD5: 028c1a42ac6ff8fc1798d94718ed480f) has been flagged by 25 scanners:
Scanner Software Result
Lavasoft Ad-Aware Application.Generic.621135
AhnLab-V3 Dropper/Win32.Preloader
avast! Win32:MultiPlug-AD [PUP]
AVG Generic_r.JW
Baidu-International Adware.Win32.MultiPlug.45
Bitdefender Application.Generic.621135
Comodo Security ApplicUnwnt
ESET-NOD32 a variant of Win32/AdWare.MultiPlug.T
G Data Application.Generic.621135
K7GW Adware ( 004976341 )
Malwarebytes PUP.Optional.MultiPlug.A
MicroWorld-eScan Application.Generic.621135
TrendMicro-HouseCall TROJ_GEN.F47V0416
VIPRE Antivirus Trojan.Win32.Generic!BT
Bkav FE HW32.Laneul.tesi
Dr.Web Trojan.Crossrider.3
K7 AntiVirus Riskware
Kingsoft AntiVirus Win32.Troj.Generic.a.(kcloud)
McAfee Artemis!E9B27306A18F
McAfee-GW-Edition Artemis!E9B27306A18F
Antiy-AVL Trojan/Win32.TGeneric
Symantec WS.Reputation.1
Sophos FastSave
Vba32 AntiVirus BScope.Adware.MegaSearch
ViRobot Adware.Agent.695808
6pM.exe (MD5: 0920b67a31662468e9eafdb6d9bc0f72) has been flagged by 18 scanners:
Scanner Software Result
AhnLab-V3 Dropper/Win32.Preloader
avast! Win32:MultiPlug-AD [PUP]
AVG Generic_r.JW
Baidu-International Adware.Win32.MultiPlug.T
Comodo Security Application.Win32.MultiPlug.SJ
ESET-NOD32 a variant of Win32/AdWare.MultiPlug.T
K7GW Adware ( 004976341 )
Malwarebytes PUP.Optional.MultiPlug.A
McAfee Artemis!0920B67A3166
McAfee-GW-Edition Heuristic.BehavesLike.Win32.Suspicious.H
TrendMicro-HouseCall TROJ_GEN.F47V0417
VIPRE Antivirus Trojan.Win32.Generic!BT
Antiy-AVL Trojan/Win32.TGeneric
Symantec WS.Reputation.1
Kingsoft AntiVirus Win32.Troj.MultiPlug.I.(kcloud)
Sophos FastSave
Vba32 AntiVirus BScope.Adware.MegaSearch
ViRobot Adware.Agent.695808
WfHRqId.exe (MD5: 074fdbec16dcf4bc211b27f64c3512ae) has been flagged by 17 scanners:
Scanner Software Result
AhnLab-V3 Dropper/Win32.Preloader
Antiy-AVL Trojan/Win32.TGeneric
avast! Win32:MultiPlug-BC [PUP]
AVG Generic5.AVSA
Baidu-International Adware.Win32.BHO.77
ESET-NOD32 a variant of Win32/AdWare.MultiPlug.Y
Malwarebytes PUP.Optional.MultiPlug.A
McAfee Artemis!074FDBEC16DC
McAfee-GW-Edition Heuristic.BehavesLike.Win32.Suspicious.H
TrendMicro-HouseCall Suspicious_GEN.F47V0610
Comodo Security ApplicUnwnt
Symantec WS.Reputation.1
VIPRE Antivirus Trojan.Win32.Generic!BT
Kingsoft AntiVirus Win32.Troj.MultiPlug.I.(kcloud)
Sophos FastSave
Vba32 AntiVirus BScope.Adware.MegaSearch
ViRobot Adware.Agent.695808

Software Details

URL:
https://costmin.info
Support:
https://advertising-support.com
Installation path:
C:\Documents and Settings\user\Application data\costmin
Uninstaller:
"C:\Documents and Settings\user\Application Data\CostMin\2fsUX.exe" /s /n /C:"ExecuteCommands;UninstallCommands" ""
Size:
569.00 KB
Language:
English

CostMin Executable Details

Primary executable:
2fsUX.exe
Name:
CostMin
Path:
C:\Documents and Settings\user\Application data\costmin\2fsUX.exe
MD5:
8300c91b40229b42301aebc6d8859907
SHA-1:
–
SHA-256:
–
Files installed by CostMin
File Type Filename MD5
EXE
02b9d570d3c99a2d1f16adf6ca44795e
EXE
603ecbd3f98e4bb7253f37f7c0b0de89
EXE
a3d277146b9e827ce18cfbeee43d9082
EXE
12d09033620aafd6dcb358ee7cd4eb76
EXE
c7065706ad64ef83e254b416c9b8a3da
EXE
7b0bbeb4560d9468623007712add29a0
EXE
d311efb8cb76813946f56817a4414eac
EXE
a822d62c945fb61f46d3f4350f22deba
EXE
cbf63647e11251712c90e3fda5675e12
EXE
5165c4baaaf6dd174f993abb5a3deb4b