tidy2networkydlus01.exe

TidyNetwork

This is part of the Tidy Network web browser add-in that will inject double underline text-link ads in the browser (may be identified by 'Tidy Network advertisements'). The application tidy2networkydlus01.exe by TidyNetwork has been detected as adware by 5 anti-malware scanners. This file is typically installed with the program TidyNetwork.com which is a potentially unwanted software program. While running, it connects to the Internet address files.tidynetwork.com on port 80 using the HTTP protocol.
Publisher:
Tidy Network  (signed by TidyNetwork)

Version:
4.1500

MD5:
277a9a2c8aa684c8fa21862dc84738c6

SHA-1:
83751aa46c5a9a31d737b7e28720e23eaed9e14e

SHA-256:
f14c192034db49d875a98c989b6423ef9a6447dacbb24df3d3dd51379584d645

Scanner detections:
5 / 68

Status:
Adware

Explanation:
Injects in-text advertising within the web browser.

Analysis date:
4/26/2024 9:08:23 AM UTC  (today)

Scan engine
Detection
Engine version

Comodo Security
Heur.Suspicious
17640

Reason Heuristics
PUP.TidyNetwork.T
14.6.29.13

Sophos
Tidy Network
4.96

Trend Micro House Call
ADW_TIDYNET
7.2.180

Trend Micro
ADW_TIDYNET
10.465.29

File size:
369.8 KB (378,664 bytes)

Product version:
4.1500

Copyright:
Copyright (C) 2012 Tidy Network

Original file name:
tidynetw.exe

File type:
Executable application (Win32 EXE)

Language:
English (United States)

Common path:
C:\users\{user}\appdata\local\tidynetwork.com\tidy2networkydlus01.exe

Digital Signature
Signed by:

Authority:
VeriSign, Inc.

Valid from:
4/2/2012 12:00:00 AM

Valid to:
4/3/2013 11:59:59 PM

Subject:
CN=TidyNetwork, OU=Digital ID Class 3 - Microsoft Software Validation v2, O=TidyNetwork, L=San Francisco, S=California, C=US

Issuer:
CN=VeriSign Class 3 Code Signing 2010 CA, OU=Terms of use at https://www.verisign.com/rpa (c)10, OU=VeriSign Trust Network, O="VeriSign, Inc.", C=US

Serial number:
73BCDD4C3C34A0BE5932E4A0E110E394

File PE Metadata
Compilation timestamp:
3/5/2013 12:31:18 AM

OS version:
5.1

OS bitness:
Win32

Subsystem:
Windows GUI

Linker version:
10.0

CTPH (ssdeep):
6144:YaOdQT0d8x5BzraO0IScVA7c/ITEsRGbRHS5oPpLf4u+PyFDqX:YXY0d8dGIScVAdE8aRDPpbBiDX

Entry address:
0x11884

Entry point:
E8, FF, 7A, 00, 00, E9, 89, FE, FF, FF, 6A, 0C, 68, E8, 5E, 42, 00, E8, 66, 65, 00, 00, 6A, 0E, E8, FC, 7C, 00, 00, 59, 83, 65, FC, 00, 8B, 75, 08, 8B, 4E, 04, 85, C9, 74, 2F, A1, 7C, 96, 42, 00, BA, 78, 96, 42, 00, 89, 45, E4, 85, C0, 74, 11, 39, 08, 75, 2C, 8B, 48, 04, 89, 4A, 04, 50, E8, 9E, F3, FF, FF, 59, FF, 76, 04, E8, 95, F3, FF, FF, 59, 83, 66, 04, 00, C7, 45, FC, FE, FF, FF, FF, E8, 0A, 00, 00, 00, E8, 55, 65, 00, 00, C3, 8B, D0, EB, C5, 6A, 0E, E8, C8, 7B, 00, 00, 59, C3, CC, CC, 8B, 54, 24, 04...
 
[+]

Entropy:
7.4927

Code size:
123 KB (125,952 bytes)

The file tidy2networkydlus01.exe has been discovered within the following program.

TidyNetwork.com  by TidyNetwork.com
From the Terms of Service - "By accessing the Sites and downloading the Software, you hereby grant the Company permission to display promotional information, advertisements, and offers for third-party products, offers or services (collectively “Advertisements”) from Company’s advertising partners (collectively “Partners”).
www.tidynetwork.com
83% remove it
 
Powered by Should I Remove It?

The executing file has been seen to make the following network communications in live environments.

TCP (HTTP):
Connects to services.tidynetwork.com  (96.126.104.111:80)

 
http://services.tidynetwork.com/general/ping.php?tidyaction=tidyinstallbegin&tidyversion=5&tidyos=NT-Platform&tidyguid={...}&tidysourcetype=tidy&tidycompany=TidyNetwork.com&tidysourceid=

TCP (HTTP):
Connects to files.tidynetwork.com  (69.16.175.10:80)

Remove tidy2networkydlus01.exe - Powered by Reason Core Security