Home Malware Programs Adware Adware CostMin

Adware CostMin

Posted: October 1, 2013

Threat Metric

Ranking: 6,076
Threat Level: 2/10
Infected PCs: 26,414
First Seen: October 1, 2013
Last Seen: October 16, 2023
OS(es) Affected: Windows

CostMin is a browser add-on that shows advertising content while you browse the Web. Like most adware, CostMin may be installed by a secondary, bundle-based installer, which may misrepresent itself or try to hide its files on your hard drive. Although malware researchers don't rate CostMin as a high-level threat, removing CostMin with proper anti-adware software continues to be advisable for keeping your browser's performance and safety at optimal levels.

The Cost of Downloading Software Carelessly

In the majority of cases, adware programs aren't intentionally threatening; however, they may exploit untrustworthy installation practices. Frequently, these practices allow products like CostMin to affect your browser without any warning. Malware experts most usually found CostMin installed via websites including costmin.info, saveclickersoft.info and installcollection.com, with its installer mislabeled with random file names. The original installer also tends to be placed in the Windows Temp directory, making it easy to overlook.

In its promotional materials, CostMin makes claims towards providing online shopping assistance. As usual for products making such claims, however, CostMin only displays pop-up advertisements. This content does not include labels to identify them as originating from CostMin, and most versions of CostMin show no additional components that would let PC users know where the advertisements came from – or how to remove them.

CostMin advertisements specialize in promoting alternative, relatively safe online retailers, but adware advertisements also may be sources of attacks against your computer. Malware researchers recommend avoiding any unneeded contact with affiliates of CostMin or similar adware products until you can uninstall them from your Web browser.

The Bare Minimum for Uninstalling CostMin Adware

CostMin's use of deliberately-concealed installers and components for all three top Windows-based browsers complicates its deletion. In such circumstances, anti-adware tools should be trusted to delete CostMin and remove its adverse effects on your Web browser. Reinstalling your browser or switching to an unaffected browser may successfully avert the symptoms of a CostMin installation, but will not delete CostMin software, which lets CostMin persist as a minor security risk.

CostMin's classification is a Potentially Unwanted Program, and PUPs may install themselves through bundles with other programs. By a good deal, the elementary way to maintain your PC clean of PUPs is to avoid download sources that distribute them commonly, such as free software sites with poor histories for security. Nonetheless, malware experts also can recommend using standard PC security tools to scan installers, which should make the detection of a CostMin bundle a trivial affair.

There are no identified CostMin incidents for browsers dominant in Mac OS X, Linux or other alternatives to the Windows operating system. However, OSes running Chrome, Internet Explorer or Firefox, regardless of which version is being used, all are at risk for CostMin advertisements.

Aliases

Skodna.Generic.ALR [AVG]Adware/Win32.MegaSearch [AhnLab-V3]Win32:MultiPlug-Y [PUP] [Avast]Adware.Popuppers [Symantec]Riskware [K7AntiVirus]

Technical Details

File System Modifications

Tutorials: If you wish to learn how to remove malware components manually, you can read the tutorials on how to find malware, kill unwanted processes, remove malicious DLLs and delete other harmful files. Always be sure to back up your PC before making any changes.

The following files were created in the system:



%ALLUSERSPROFILE%\safee save\51e7c8673f01d.dll File name: 51e7c8673f01d.dll
Size: 118.78 KB (118784 bytes)
MD5: 05234975b085632d70d89c2f420c5107
Detection count: 1,157
File type: Dynamic link library
Mime Type: unknown/dll
Path: %ALLUSERSPROFILE%\safee save\51e7c8673f01d.dll
Group: Malware file
Last Updated: February 10, 2023
%ALLUSERSPROFILE%\costmin\epbobadpdjhmhnnokljfjbmjbjkkamic.crx File name: epbobadpdjhmhnnokljfjbmjbjkkamic.crx
Size: 8.44 KB (8443 bytes)
MD5: 942a18653d728b8fb133a91eb9cbc811
Detection count: 71
Mime Type: unknown/crx
Path: %ALLUSERSPROFILE%\costmin
Group: Malware file
Last Updated: October 1, 2013
%PROGRAMFILES%\NexttCooUip\O7TNCz.dll File name: O7TNCz.dll
Size: 332.8 KB (332800 bytes)
MD5: dd786875d69cca863d57ef587d1cec39
Detection count: 13
File type: Dynamic link library
Mime Type: unknown/dll
Path: %PROGRAMFILES%\NexttCooUip
Group: Malware file
Last Updated: September 1, 2014
costmin-setup.exe File name: costmin-setup.exe
Size: 256.16 KB (256162 bytes)
MD5: 9ad4c78dbfbf21ec2171d3bed89f2064
Detection count: 5
File type: Executable File
Mime Type: unknown/exe
Group: Malware file
Last Updated: August 17, 2022

Registry Modifications

The following newly produced Registry Values are:

HKEY..\..\..\..{RegistryKeys}SOFTWARE\Classes\cosstminn.cosstminnSOFTWARE\Classes\cosstminn.cosstminn.2.0SOFTWARE\Classes\CostMin.CostMinSOFTWARE\Classes\CostMin.CostMin.2.2Software\Microsoft\Internet Explorer\Approved Extensions\{E3D96270-3848-E9D2-BB32-2211E57D4845}Software\Microsoft\Internet Explorer\Approved Extensions\{E571864A-162D-550E-53BC-27325263C500}SOFTWARE\Microsoft\Windows\CurrentVersion\Policies\Ext\CLSID\{1465BEC8-B8B8-E4C7-E8D6-CB7E7BD4B63E}SOFTWARE\Microsoft\Windows\CurrentVersion\Policies\Ext\CLSID\{41A77D0F-5250-66E1-513B-7249E6678B73}SOFTWARE\Microsoft\Windows\CurrentVersion\Policies\Ext\CLSID\{425BE9EF-F7AE-66A0-B8EE-57925882049D}SOFTWARE\Microsoft\Windows\CurrentVersion\Policies\Ext\CLSID\{606D560D-93E6-4876-2FF8-D3A48F748F87}SOFTWARE\Microsoft\Windows\CurrentVersion\Policies\Ext\CLSID\{99AD76D0-5849-28B9-7C80-A1B8AA0D817F}SOFTWARE\Microsoft\Windows\CurrentVersion\Policies\Ext\CLSID\{9FCD5E96-8743-BD52-37CD-FEF09086CBE0}SOFTWARE\Microsoft\Windows\CurrentVersion\Policies\Ext\CLSID\{D33D8FDB-000E-9280-70AD-F4CF7F308B9D}SOFTWARE\Microsoft\Windows\CurrentVersion\Policies\Ext\CLSID\{E3D96270-3848-E9D2-BB32-2211E57D4845}SOFTWARE\Microsoft\Windows\CurrentVersion\Policies\Ext\CLSID\{E571864A-162D-550E-53BC-27325263C500}SOFTWARE\Microsoft\Windows\CurrentVersion\Policies\Ext\CLSID\{FB171468-26F8-5C21-5D75-807F895D9317}HKEY_LOCAL_MACHINE\Software\[APPLICATION]\Microsoft\Windows\CurrentVersion\Uninstall..{Uninstaller}{2F5F003B-C71B-72E3-42B4-DE51AB079EB2}{5F189DF5-2D05-472B-9091-84D9848AE48B}{be0fb33b}{CE681A67-9477-CBE6-EB9D-FE534875F98D}

Additional Information

The following directories were created:
%ALLUSERSPROFILE%\Application Data\cosstminn%ALLUSERSPROFILE%\Application Data\costmin%ALLUSERSPROFILE%\cosstminn%ALLUSERSPROFILE%\costmin%LOCALAPPDATA%\Packages\windows_ie_ac_001\AC\{1465BEC8-B8B8-E4C7-E8D6-CB7E7BD4B63E}%PROGRAMFILES%\CostMin%PROGRAMFILES%\cosstminn%PROGRAMFILES(X86)%\cosstminn%PROGRAMFILES(x86)%\CostMin%Temp%\costmin%appdata%\{E3D96270-3848-E9D2-BB32-2211E57D4845}
The following URL's were detected:
cosstminncostmin
Loading...