CostMin

CostMin

Known Adware

by Engaging Apps

What is CostMin?

CostMin is software application developed by Engaging Apps. It is most commonly found on computers running Windows 7 with nearly 62.29% of installations running this operating system. CostMin's installer is typically 569.00 KB in size and installs around 198 files. The most common release is 2.1.0.1310 with 19.06% of all installations currently using this version.

CostMin is most popular in the United States with 25.99% of installations residing in this country.

About CostMin?

CostMin is a web browser extension that functions as adware, redirecting web searches and injecting advertising. When used on Internet Explorer, the program operates as a Browser Helper Object. The add-in is capable of hijacking advertising on unrelated websites, as well as inserting its own advertising in the form of contextual link ads, banner ads, popups, and pop-overs, including on established ad serving sites. The malware is commonly distributed alongside unwanted third-party applications and through web browser vulnerabilities. While the program is equipped with an uninstaller and can be found in the Windows Add/Remove Programs, complete removal may prove challenging and may require the use of an anti-malware product. The Plugin is supported by third-party advertising, and upon downloading it, users will encounter various types of advertisements while browsing the internet, including sponsored links, traditional display advertisements (such as banner ads, "pop-unders," and interstitial ads), coupons, and video targeted ads. Additionally, the plugin may display sponsored links in the form of in-text advertising, and in response to keyword searches made through search engines like Google, Bing, and others.

Multiple virus scanners have detected malware in CostMin.

dMVT.dll (MD5: e9b27306a18f18b88945cdf066de2fc9) has been flagged by 21 scanners:
Scanner Software Result
avast! Win32:BHO-AML [Spy]
AVG Generic5.AFXS
Bkav FE HW32.Laneul.tesi
Comodo Security ApplicUnwnt
Dr.Web Trojan.Crossrider.3
ESET-NOD32 a variant of Win32/Adware.MultiPlug.I
K7 AntiVirus Riskware
K7GW Riskware
Kingsoft AntiVirus Win32.Troj.Generic.a.(kcloud)
Malwarebytes PUP.Optional.MultiPlug.A
McAfee Artemis!E9B27306A18F
McAfee-GW-Edition Artemis!E9B27306A18F
VIPRE Antivirus Trojan.Win32.Generic!BT
AhnLab-V3 Dropper/Win32.Preloader
Baidu-International Adware.Win32.MultiPlug.T
TrendMicro-HouseCall TROJ_GEN.F47V0417
Antiy-AVL Trojan/Win32.TGeneric
Symantec WS.Reputation.1
Sophos FastSave
Vba32 AntiVirus BScope.Adware.MegaSearch
ViRobot Adware.Agent.695808
51d15c58d70ab.dll (MD5: 05234975b085632d70d89c2f420c5107) has been flagged by 15 scanners:
Scanner Software Result
AhnLab-V3 Adware/Win32.MegaSearch
Comodo Security ApplicUnwnt
ESET-NOD32 a variant of Win32/Adware.MultiPlug.I
Kingsoft AntiVirus Win32.Troj.MultiPlug.I.(kcloud)
Sophos FastSave
Vba32 AntiVirus BScope.Adware.MegaSearch
VIPRE Antivirus Trojan.Win32.Generic!BT
AVG Generic5.AVNH
Baidu-International Adware.Win32.BHO.45
McAfee-GW-Edition Heuristic.BehavesLike.Win32.Suspicious.H
Symantec WS.Reputation.1
avast! Win32:MultiPlug-AD [PUP]
Malwarebytes PUP.Optional.MultiPlug.A
ViRobot Adware.Agent.695808
TrendMicro-HouseCall TROJ_GEN.F47V0519
WUoUq2uCsc.exe (MD5: 028c1a42ac6ff8fc1798d94718ed480f) has been flagged by 25 scanners:
Scanner Software Result
Lavasoft Ad-Aware Application.Generic.621135
AhnLab-V3 Dropper/Win32.Preloader
avast! Win32:MultiPlug-AD [PUP]
AVG Generic_r.JW
Baidu-International Adware.Win32.MultiPlug.45
Bitdefender Application.Generic.621135
Comodo Security ApplicUnwnt
ESET-NOD32 a variant of Win32/AdWare.MultiPlug.T
G Data Application.Generic.621135
K7GW Adware ( 004976341 )
Malwarebytes PUP.Optional.MultiPlug.A
MicroWorld-eScan Application.Generic.621135
TrendMicro-HouseCall TROJ_GEN.F47V0416
VIPRE Antivirus Trojan.Win32.Generic!BT
Bkav FE HW32.Laneul.tesi
Dr.Web Trojan.Crossrider.3
K7 AntiVirus Riskware
Kingsoft AntiVirus Win32.Troj.Generic.a.(kcloud)
McAfee Artemis!E9B27306A18F
McAfee-GW-Edition Artemis!E9B27306A18F
Antiy-AVL Trojan/Win32.TGeneric
Symantec WS.Reputation.1
Sophos FastSave
Vba32 AntiVirus BScope.Adware.MegaSearch
ViRobot Adware.Agent.695808
6pM.exe (MD5: 0920b67a31662468e9eafdb6d9bc0f72) has been flagged by 18 scanners:
Scanner Software Result
AhnLab-V3 Dropper/Win32.Preloader
avast! Win32:MultiPlug-AD [PUP]
AVG Generic_r.JW
Baidu-International Adware.Win32.MultiPlug.T
Comodo Security Application.Win32.MultiPlug.SJ
ESET-NOD32 a variant of Win32/AdWare.MultiPlug.T
K7GW Adware ( 004976341 )
Malwarebytes PUP.Optional.MultiPlug.A
McAfee Artemis!0920B67A3166
McAfee-GW-Edition Heuristic.BehavesLike.Win32.Suspicious.H
TrendMicro-HouseCall TROJ_GEN.F47V0417
VIPRE Antivirus Trojan.Win32.Generic!BT
Antiy-AVL Trojan/Win32.TGeneric
Symantec WS.Reputation.1
Kingsoft AntiVirus Win32.Troj.MultiPlug.I.(kcloud)
Sophos FastSave
Vba32 AntiVirus BScope.Adware.MegaSearch
ViRobot Adware.Agent.695808
WfHRqId.exe (MD5: 074fdbec16dcf4bc211b27f64c3512ae) has been flagged by 17 scanners:
Scanner Software Result
AhnLab-V3 Dropper/Win32.Preloader
Antiy-AVL Trojan/Win32.TGeneric
avast! Win32:MultiPlug-BC [PUP]
AVG Generic5.AVSA
Baidu-International Adware.Win32.BHO.77
ESET-NOD32 a variant of Win32/AdWare.MultiPlug.Y
Malwarebytes PUP.Optional.MultiPlug.A
McAfee Artemis!074FDBEC16DC
McAfee-GW-Edition Heuristic.BehavesLike.Win32.Suspicious.H
TrendMicro-HouseCall Suspicious_GEN.F47V0610
Comodo Security ApplicUnwnt
Symantec WS.Reputation.1
VIPRE Antivirus Trojan.Win32.Generic!BT
Kingsoft AntiVirus Win32.Troj.MultiPlug.I.(kcloud)
Sophos FastSave
Vba32 AntiVirus BScope.Adware.MegaSearch
ViRobot Adware.Agent.695808

Software Details

URL:
https://costmin.info
Support:
https://advertising-support.com
Installation path:
C:\Documents and Settings\user\Application data\costmin
Uninstaller:
"C:\Documents and Settings\user\Application Data\CostMin\2fsUX.exe" /s /n /C:"ExecuteCommands;UninstallCommands" ""
Size:
569.00 KB
Language:
English

CostMin Executable Details

Primary executable:
2fsUX.exe
Name:
CostMin
Path:
C:\Documents and Settings\user\Application data\costmin\2fsUX.exe
MD5:
8300c91b40229b42301aebc6d8859907
SHA-1:
–
SHA-256:
–
Files installed by CostMin
File Type Filename MD5
EXE
15f67f067cc9df510882bf68bc1df4d7
EXE
3235a5142bce167c8be580ce72d55378
EXE
fa7f2aaa16e87adaec0ada64fe123548
EXE
fa7f2aaa16e87adaec0ada64fe123548
EXE
fa7f2aaa16e87adaec0ada64fe123548
EXE
1dc7c3ef6eea8c9d6f3e5fc8055a42d3
EXE
RuOG.exe
Malware
246e7d6913dd2800f7b9da0a23e7b588
EXE
96b478bf6e702e5a185f0c64497beeb3
EXE
2fsUX.exe
Malware
8300c91b40229b42301aebc6d8859907
EXE
ec23e83d367281290af0228ffa7eada8