npTNT2.dll

npAPI Plugin

Search.Us.com

This is the Tightrope WebInstall which bundles applications with offers for additional 3rd party software, mostly unwanted adware, and may be installed with minimal consent. The module npTNT2.dll has been detected as adware by 3 anti-malware scanners. The program is a setup application that uses the Tightrope WebInstall installer, however the file is not signed with an authenticode signature from a trusted source. It is installed within the Mozilla Firefox web browser as an extension/plugin as ‘@tightropeinteractive.com/Plugin’. This file is typically installed with the program Search.us.com which is a potentially unwanted software program.
Publisher:
Search.Us.com

Product:
npAPI Plugin

Version:
2.0.0.1534

MD5:
d6b24174cc26eb0ac7f169485528e248

SHA-1:
cd4c4ade0a6c5dc52a0cf869a8bc4e184c3761b7

SHA-256:
c99750bb69de53b00ddc8c3fb58031dea79c4876c3b8300fb71b15f6eb357742

Scanner detections:
3 / 68

Status:
Adware

Description:
This is also known as bundleware, or downloadware, which is an downloader designed to simply deliver ad-supported offers in the setup routine of an otherwise legitimate software.

Analysis date:
11/15/2025 11:28:26 AM UTC  (today)

Scan engine
Detection
Engine version

Boost by Reason
Optional.MozillaPlugin.SearchUs.G
188163

Reason Heuristics
PUP.MozillaPlugin.SearchUs.G
14.2.26.9

Trend Micro House Call
TROJ_GEN.F47V0510
7.2.207

File size:
107.5 KB (110,080 bytes)

Product version:
2.0.0.1534

Copyright:
© Search.Us.com All Rights Reserved

Original file name:
npTNT2.dll

File type:
Dynamic link library (Win32 DLL)

Bundler/Installer:
Tightrope WebInstall

Language:
English (United States)

Common path:
C:\users\{user}\appdata\local\tnt2\2.0.0.1534\nptnt2.dll

File PE Metadata
Compilation timestamp:
3/27/2013 3:24:49 PM

OS version:
5.1

OS bitness:
Win32

Subsystem:
Windows GUI

Linker version:
11.0

CTPH (ssdeep):
1536:ExPLUmxKJJWGzj4ouK1L5lQ5A37IITWEcu4fUsWjcdXYfZzNKeKT9q0POE8:EYpzffkmyY4zXYBhvKT9bPO1

Entry address:
0x60C1

Entry point:
55, 8B, EC, 83, 7D, 0C, 01, 75, 05, E8, 7D, 3A, 00, 00, FF, 75, 10, FF, 75, 0C, FF, 75, 08, E8, 07, 00, 00, 00, 83, C4, 0C, 5D, C2, 0C, 00, 6A, 0C, 68, 10, 4F, 01, 10, E8, 50, 2A, 00, 00, 33, C0, 40, 8B, 75, 0C, 85, F6, 75, 0C, 39, 35, 04, 80, 01, 10, 0F, 84, E4, 00, 00, 00, 83, 65, FC, 00, 83, FE, 01, 74, 05, 83, FE, 02, 75, 35, 8B, 0D, 8C, F2, 00, 10, 85, C9, 74, 0C, FF, 75, 10, 56, FF, 75, 08, FF, D1, 89, 45, E4, 85, C0, 0F, 84, B1, 00, 00, 00, FF, 75, 10, 56, FF, 75, 08, E8, 11, FE, FF, FF, 89, 45, E4...
 
[+]

Code size:
55 KB (56,320 bytes)

Mozilla Plugin
Name:
@tightropeinteractive.com/Plugin


The file npTNT2.dll has been discovered within the following program.

Search.us.com  by Search.us.com
Search.us.com Toolbar a web browser extension and Browser helper Object (for Internet Explorer) that delivers contextual based advertising to the web browser.
www.Search.us.com
82% remove it
 
Powered by Should I Remove It?

Remove npTNT2.dll - Powered by Reason Core Security