tnt2userps.dll

Search.us.com

This is the Tightrope WebInstall which bundles applications with offers for additional 3rd party software, mostly unwanted adware, and may be installed with minimal consent. The module tnt2userps.dll by Search.us.com has been detected as adware by 4 anti-malware scanners. The program is a setup application that uses the Tightrope WebInstall installer.
Publisher:
Search.us.com  (signed and verified)

MD5:
8c0b08d09a288735b1f960891d8b79a6

SHA-1:
fbbdbc9fa8b8266d43a821ec62d06ec8f20e1bc5

SHA-256:
80eb68a2962d3aa8eb0f34d07e8013f4ace70593e348922d3790baa57713a2ec

Scanner detections:
4 / 68

Status:
Adware

Description:
This 'download manager' is also considered bundleware, a utility designed to download software (possibly legitimate or opensource) and bundle it with a number of optional offers including ad-supported utilities, toolbars, shopping comparison tools and browser extensions.

Analysis date:
5/7/2024 12:09:49 PM UTC  (today)

Scan engine
Detection
Engine version

Avira AntiVirus
TR/Trash.Gen
8.3.1.6

Kaspersky
Packed.Win32.Krap
14.0.0.1879

Reason Heuristics
PUP.Tightrope.Searchus
15.1.22.16

VIPRE Antivirus
Threat.4729122
40830

File size:
83.8 KB (85,776 bytes)

File type:
Dynamic link library (Win32 DLL)

Bundler/Installer:
Tightrope WebInstall

Common path:
C:\users\{user}\appdata\local\tnt2\2.0.0.1928\tnt2userps.dll

Digital Signature
Signed by:

Authority:
VeriSign, Inc.

Valid from:
3/20/2013 1:00:00 AM

Valid to:
3/20/2016 12:59:59 AM

Subject:
CN=Search.us.com, OU=Digital ID Class 3 - Microsoft Software Validation v2, O=Search.us.com, L=SAN FRANCISCO, S=California, C=US

Issuer:
CN=VeriSign Class 3 Code Signing 2010 CA, OU=Terms of use at https://www.verisign.com/rpa (c)10, OU=VeriSign Trust Network, O="VeriSign, Inc.", C=US

Serial number:
53391509B5D4A87249DD2CCE767F64A2

File PE Metadata
Compilation timestamp:
1/10/2015 1:18:37 AM

OS version:
6.0

OS bitness:
Win32

Subsystem:
Windows GUI

Linker version:
11.0

CTPH (ssdeep):
1536:5LUsuPjpWQI20kqqQcdNmusWjcdvCbgRT9Ut:5i1Xp04TIqb2Be

Entry address:
0x2A9E

Entry point:
55, 8B, EC, 83, 7D, 0C, 01, 75, 05, E8, 3D, 10, 00, 00, FF, 75, 10, FF, 75, 0C, FF, 75, 08, E8, 07, 00, 00, 00, 83, C4, 0C, 5D, C2, 0C, 00, 6A, 0C, 68, F0, 12, 01, 10, E8, 93, 15, 00, 00, 33, C0, 40, 8B, 75, 0C, 85, F6, 75, 0C, 39, 35, D4, 46, 01, 10, 0F, 84, E4, 00, 00, 00, 83, 65, FC, 00, 83, FE, 01, 74, 05, 83, FE, 02, 75, 35, 8B, 0D, 74, D7, 00, 10, 85, C9, 74, 0C, FF, 75, 10, 56, FF, 75, 08, FF, D1, 89, 45, E4, 85, C0, 0F, 84, B1, 00, 00, 00, FF, 75, 10, 56, FF, 75, 08, E8, 11, FE, FF, FF, 89, 45, E4...
 
[+]

Developed / compiled with:
Microsoft Visual C++

Code size:
31.5 KB (32,256 bytes)

Remove tnt2userps.dll - Powered by Reason Core Security