TNT2User.exe

Search.us.com

This is the Tightrope WebInstall which bundles applications with offers for additional 3rd party software, mostly unwanted adware, and may be installed with minimal consent. The application TNT2User.exe by Search.us.com has been detected as adware by 3 anti-malware scanners. The program is a setup application that uses the Tightrope WebInstall installer.
Publisher:
Search.us.com  (signed and verified)

Version:
2.0.0.1918

MD5:
9f783a935c63193b08e6c7cb2af36f2d

SHA-1:
8a560c955afbaf06de168c8e69643c2aa49bf892

SHA-256:
8160af7111c4c0069c777aab7a0dfbd075099f9efba6772119aec62a87a9329e

Scanner detections:
3 / 68

Status:
Adware

Description:
This 'download manager' is also considered bundleware, a utility designed to download software (possibly legitimate or opensource) and bundle it with a number of optional offers including ad-supported utilities, toolbars, shopping comparison tools and browser extensions.

Analysis date:
4/25/2024 10:55:01 PM UTC  (today)

Scan engine
Detection
Engine version

ESET NOD32
Win32/Toolbar.TNT2 (variant)
9.10994

Reason Heuristics
PUP.Searchus.I
15.1.14.18

VIPRE Antivirus
Trojan.Win32.Generic
37558

File size:
638.8 KB (654,096 bytes)

Product version:
2.0.0.1918

Copyright:
© Search.Us.com All Rights Reserved

Original file name:
TNT2User.exe

File type:
Executable application (Win32 EXE)

Bundler/Installer:
Tightrope WebInstall

Language:
English (United States)

Common path:
C:\users\{user}\appdata\local\tnt2\2.0.0.1918\tnt2user.exe

Digital Signature
Signed by:

Authority:
VeriSign, Inc.

Valid from:
3/20/2013 2:00:00 AM

Valid to:
3/20/2016 1:59:59 AM

Subject:
CN=Search.us.com, OU=Digital ID Class 3 - Microsoft Software Validation v2, O=Search.us.com, L=SAN FRANCISCO, S=California, C=US

Issuer:
CN=VeriSign Class 3 Code Signing 2010 CA, OU=Terms of use at https://www.verisign.com/rpa (c)10, OU=VeriSign Trust Network, O="VeriSign, Inc.", C=US

Serial number:
53391509B5D4A87249DD2CCE767F64A2

File PE Metadata
Compilation timestamp:
12/19/2014 12:19:28 AM

OS version:
5.1

OS bitness:
Win32

Subsystem:
Windows GUI

Linker version:
11.0

CTPH (ssdeep):
6144:VYs0GUkicOBqu5/AozQjS7EopDKAT9hW5envITnrZhif19MRrJWreqk163:RUUOBXRJzDh0QAT9U1qg/k16

Entry address:
0x39B2B

Entry point:
E8, 2C, 9D, 00, 00, E9, 7F, FE, FF, FF, 55, 8B, EC, 81, EC, 28, 03, 00, 00, A1, 70, 08, 47, 00, 33, C5, 89, 45, FC, 83, 7D, 08, FF, 57, 74, 09, FF, 75, 08, E8, 21, 62, 00, 00, 59, 83, A5, E0, FC, FF, FF, 00, 6A, 4C, 8D, 85, E4, FC, FF, FF, 6A, 00, 50, E8, 01, DA, FF, FF, 8D, 85, E0, FC, FF, FF, 89, 85, D8, FC, FF, FF, 8D, 85, 30, FD, FF, FF, 83, C4, 0C, 89, 85, DC, FC, FF, FF, 89, 85, E0, FD, FF, FF, 89, 8D, DC, FD, FF, FF, 89, 95, D8, FD, FF, FF, 89, 9D, D4, FD, FF, FF, 89, B5, D0, FD, FF, FF, 89, BD, CC...
 
[+]

Code size:
332.5 KB (340,480 bytes)

Remove TNT2User.exe - Powered by Reason Core Security