tnt2userps64.dll

Search.us.com

This is a component of the Tightrope WebInstall, a setup program that bundles applications with offers for additional 3rd party software, mostly unwanted adware, and may be installed with minimal consent. The module tnt2userps64.dll by Search.us.com has been detected as adware by 1 anti-malware scanner with very strong indications that the file is a potential threat. Additionally, the file is typically installed by a number of programs including Search.us.com by Freshy and FindWide.com by FindWide, both potentially unwanted software.
Publisher:
Search.us.com  (signed and verified)

MD5:
1bf1287f6aa2a3e8b05bd5fb99d36a78

SHA-1:
72d5049870e20ff9c1269f0015dc4e754698e708

SHA-256:
a2fb85209d7aa65a348a4925fde8d7206a0fd6fc88c33c984a5d5e339e1e37d4

Scanner detections:
1 / 68

Status:
Adware

Note:
Our current pool of anti-malware engines have not currently detected this file, however based on our own detection heuristics we feel that this file is unwanted.

Analysis date:
12/28/2024 1:17:53 PM UTC  (today)

Scan engine
Detection
Engine version

Reason Heuristics
PUP.Tightrope.Searchus (M)
16.1.6.10

File size:
65.9 KB (67,520 bytes)

File type:
Dynamic link library (Win64 DLL)

Common path:
C:\users\{user}\appdata\local\tnt2\2.0.0.1378\tnt2userps64.dll

Digital Signature
Signed by:

Authority:
VeriSign, Inc.

Valid from:
8/21/2012 5:00:00 PM

Valid to:
8/22/2013 4:59:59 PM

Subject:
CN=Search.us.com, OU=Digital ID Class 3 - Microsoft Software Validation v2, O=Search.us.com, L=San Francisco, S=California, C=US

Issuer:
CN=VeriSign Class 3 Code Signing 2010 CA, OU=Terms of use at https://www.verisign.com/rpa (c)10, OU=VeriSign Trust Network, O="VeriSign, Inc.", C=US

Serial number:
43D8A91FFBCF0895F68EACA5DF5C03A8

Registration
CLSID:
{DD260902-9420-4055-A956-9152EB4F3E6A}

COM registered:
Yes

File PE Metadata
Compilation timestamp:
12/17/2012 9:48:18 AM

OS version:
5.2

OS bitness:
Win64

Subsystem:
Windows GUI

Linker version:
10.0

CTPH (ssdeep):
768:CV0sE6ToQr+vATF3qTz08ElsBb3nX8Uk3YZTzpGHjT/FyVD8Pe60XjkD/4gy1Ji0:CVx6iIATo0Y3Xe3YZf4LFyVItK194ZC

Entry address:
0x1508

Entry point:
48, 89, 5C, 24, 08, 48, 89, 74, 24, 10, 57, 48, 83, EC, 20, 49, 8B, F8, 8B, DA, 48, 8B, F1, 83, FA, 01, 75, 05, E8, 1F, 16, 00, 00, 4C, 8B, C7, 8B, D3, 48, 8B, CE, 48, 8B, 5C, 24, 30, 48, 8B, 74, 24, 38, 48, 83, C4, 20, 5F, E9, A7, FE, FF, FF, CC, CC, CC, 4C, 8B, DC, 49, 89, 5B, 08, 49, 89, 6B, 18, 49, 89, 73, 20, 49, 89, 53, 10, 57, 41, 54, 41, 55, 41, 56, 41, 57, 48, 83, EC, 40, 4D, 8B, 79, 08, 4D, 8B, 31, 8B, 41, 04, 49, 8B, 79, 38, 4D, 2B, F7, 4D, 8B, E1, 4C, 8B, EA, 48, 8B, E9, A8, 66, 0F, 85, ED, 00...
 
[+]

Entropy:
5.5658

Code size:
21 KB (21,504 bytes)

The file tnt2userps64.dll has been discovered within the following programs.

FindWide.com  by FindWide
FindWide is a potentially unwanted application that runs in the web browser as a toolbar and web extension.
search.findwide.com
67% remove it
Search.us.com  by Freshy
The Search.US Toolbar (My.Search.Us) is a Freshy powered toolbar for Intenet Explorer and Firefox.
search.us.com
85% remove it
 
Powered by Should I Remove It?

Remove tnt2userps64.dll - Powered by Reason Core Security