tidynetwork009.exe

TidyNetwork

This is part of the Tidy Network web browser add-in that will inject double underline text-link ads in the browser (may be identified by 'Tidy Network advertisements'). The application tidynetwork009.exe by TidyNetwork has been detected as adware by 3 anti-malware scanners. This file is typically installed with the program TidyNetwork.com which is a potentially unwanted software program. While running, it connects to the Internet address files.tidynetwork.com on port 80 using the HTTP protocol.
Publisher:
Tidy Network  (signed by TidyNetwork)

Version:
4.1412

MD5:
86b9422d221c6ae9ebdd4cc6af34bc49

SHA-1:
36b8ce5030b1d41ae479afa7b9e1943061fd8fd3

SHA-256:
2c894573a7ca74330d4b2572ff7afe1b7c2827bffdb1d3905cf852c91a09823e

Scanner detections:
3 / 68

Status:
Adware

Explanation:
Injects in-text advertising within the web browser.

Analysis date:
7/18/2025 8:30:07 AM UTC  (today)

Scan engine
Detection
Engine version

Comodo Security
Heur.Suspicious
17259

Reason Heuristics
PUP.TidyNetwork.O
14.8.29.20

Sophos
Tidy Network
4.94

File size:
359.3 KB (367,912 bytes)

Product version:
4.1412

Copyright:
Copyright (C) 2012 Tidy Network

Original file name:
tidynetw.exe

File type:
Executable application (Win32 EXE)

Language:
English (United States)

Common path:
C:\users\{user}\appdata\local\tidynetwork.com\tidynetwork009.exe

Digital Signature
Signed by:

Authority:
VeriSign, Inc.

Valid from:
4/1/2012 7:00:00 PM

Valid to:
4/3/2013 6:59:59 PM

Subject:
CN=TidyNetwork, OU=Digital ID Class 3 - Microsoft Software Validation v2, O=TidyNetwork, L=San Francisco, S=California, C=US

Issuer:
CN=VeriSign Class 3 Code Signing 2010 CA, OU=Terms of use at https://www.verisign.com/rpa (c)10, OU=VeriSign Trust Network, O="VeriSign, Inc.", C=US

Serial number:
73BCDD4C3C34A0BE5932E4A0E110E394

File PE Metadata
Compilation timestamp:
1/24/2013 1:05:52 PM

OS version:
5.1

OS bitness:
Win32

Subsystem:
Windows GUI

Linker version:
10.0

CTPH (ssdeep):
6144:BA5BXGvD6eHuVxk3IoBEFEsRobRbS5oupLf4u+PtF7qXpl:BWG76eOzk3aE8YR3upbBiuXD

Entry address:
0xFC6C

Entry point:
E8, 07, 7B, 00, 00, E9, 89, FE, FF, FF, 6A, 0C, 68, 00, 38, 42, 00, E8, 6E, 65, 00, 00, 6A, 0E, E8, 04, 7D, 00, 00, 59, 83, 65, FC, 00, 8B, 75, 08, 8B, 4E, 04, 85, C9, 74, 2F, A1, 24, 66, 42, 00, BA, 20, 66, 42, 00, 89, 45, E4, 85, C0, 74, 11, 39, 08, 75, 2C, 8B, 48, 04, 89, 4A, 04, 50, E8, C6, F2, FF, FF, 59, FF, 76, 04, E8, BD, F2, FF, FF, 59, 83, 66, 04, 00, C7, 45, FC, FE, FF, FF, FF, E8, 0A, 00, 00, 00, E8, 5D, 65, 00, 00, C3, 8B, D0, EB, C5, 6A, 0E, E8, D0, 7B, 00, 00, 59, C3, CC, CC, CC, CC, CC, CC...
 
[+]

Entropy:
7.5249

Code size:
115 KB (117,760 bytes)

The file tidynetwork009.exe has been discovered within the following program.

TidyNetwork.com  by TidyNetwork.com
From the Terms of Service - "By accessing the Sites and downloading the Software, you hereby grant the Company permission to display promotional information, advertisements, and offers for third-party products, offers or services (collectively “Advertisements”) from Company’s advertising partners (collectively “Partners”).
www.tidynetwork.com
83% remove it
 
Powered by Should I Remove It?

The executing file has been seen to make the following network communications in live environments.

TCP (HTTP):
Connects to services.tidynetwork.com  (96.126.104.111:80)

 
http://services.tidynetwork.com/general/ping.php?tidyaction=tidyinstallbegin&tidyversion=5&tidyos=NT-Platform&tidyguid={...}&tidysourcetype=tidy&tidycompany=TidyNetwork.com&tidysourceid=

TCP (HTTP):
Connects to files.tidynetwork.com  (69.16.175.10:80)

Remove tidynetwork009.exe - Powered by Reason Core Security