The weDownload

The weDownload

Known Malware

by weDownload Ltd

What is The weDownload?

The weDownload is software application developed by weDownload Ltd. It is most commonly found on computers running Windows 7 with nearly 59.74% of installations running this operating system. The weDownload's installer is typically 7.00 MB in size and installs around 17 files. The most common release is 1.34.2.13 with 46.05% of all installations currently using this version.

The weDownload is most popular in the United States with 30.08% of installations residing in this country.

About The weDownload?

WeDownload is a web browser extension and Browser Helper Object (BHO) designed to deliver contextual-based advertising to Internet Explorer. It has the capability to modify the user's browser home and search pages, as well as 'New Tab' pages, in order to push advertising and search results. Additionally, the software may be bundled with potentially unwanted applications from the same publisher and third-party apps.

Multiple virus scanners have detected malware in The weDownload.

utils.exe (MD5: c6ee850aa42eaf0b67e7a2bec46093f0) has been flagged by 35 scanners:
Scanner Software Result
AhnLab-V3 PUP/Win32.MulDrop
Bkav FE HW32.CDB
Malwarebytes PUP.Optional.CrossRider.A
Symantec WS.Reputation
Lavasoft Ad-Aware Adware.Generic.915161
Avira AntiVir Adware/CrossRider.A.2276
Antiy-AVL Trojan/Win32.SGeneric
avast! Win32:Adware-gen [Adw]
Baidu-International Adware.Win32.CrossRider.40
Bitdefender Adware.Generic.915161
Comodo Security ApplicUnwnt
Dr.Web Trojan.Crossrider.7519
Emsisoft Anti-Malware Adware.Generic.915161 (B)
ESET-NOD32 a variant of Win32/Toolbar.CrossRider.AC
Fortinet FortiGate Riskware/Toolbar_CrossRider
F-Secure Adware.Generic.915161
G Data Adware.Generic.915161
K7 AntiVirus Trojan ( 0049590e1 )
K7GW Trojan ( 0049590e1 )
McAfee Artemis!41BDA88949A1
McAfee-GW-Edition Artemis!41BDA88949A1
MicroWorld-eScan Adware.Generic.915161
NANO AntiVirus Trojan.Win32.Crossrider.cyaxwd
Sophos AppRider
Tencent Win32.Risk.Adware.Pcjd
Trend Micro TROJ_GEN.R00JC0OE314
TrendMicro-HouseCall TROJ_GEN.R00JC0OE314
VIPRE Antivirus Crossrider (fs)
AVG Generic5.AMMM
Jiangmin AdWare/Lyckriks.ff
Kaspersky not-a-virus:AdWare.Win32.Lyckriks.mk
Kingsoft AntiVirus Win32.Troj.Lyckriks.mk.(kcloud)
Vba32 AntiVirus AdWare.Lyckriks
Agnitum Outpost PUA.Toolbar.CrossRider!
SUPERAntiSpyware Trojan.Agent/Gen-Crossrider
The weDownload-updater.exe (MD5: 8389ddbb0307681874bbb865d6e29535) has been flagged by 13 scanners:
Scanner Software Result
Agnitum Outpost PUA.Toolbar.CrossRider!
Baidu-International Adware.Win32.CrossRider.X
Dr.Web Trojan.Crossrider.7209
ESET-NOD32 a variant of Win32/Toolbar.CrossRider.X
Fortinet FortiGate Riskware/Toolbar_CrossRider
Malwarebytes PUP.Optional.weDownload.A
McAfee Artemis!8389DDBB0307
McAfee-GW-Edition Artemis!8389DDBB0307
SUPERAntiSpyware Trojan.Agent/Gen-Crossrider
Symantec Adware.Crossid
TrendMicro-HouseCall TROJ_GEN.R0C1H05CR14
VIPRE Antivirus Crossrider (fs)
AVG MultiBundle.V
The weDownload-firefoxinstaller.exe (MD5: 85f1d51a7cb4d948e97e4bbcb7ec9668) has been flagged by 11 scanners:
Scanner Software Result
AVG MultiBundle.V
Baidu-International Adware.Win32.CrossRider.40
Dr.Web Trojan.Crossrider.7210
ESET-NOD32 a variant of Win32/Toolbar.CrossRider.Y
Fortinet FortiGate Riskware/Toolbar_CrossRider
Malwarebytes PUP.Optional.weDownload.A
McAfee Artemis!85F1D51A7CB4
McAfee-GW-Edition Artemis!85F1D51A7CB4
Symantec Adware.Crossid
TrendMicro-HouseCall TROJ_GEN.R0C1H05CR14
VIPRE Antivirus Crossrider (fs)
The weDownload-enabler.exe (MD5: 41bda88949a12d1f348d0669515d6316) has been flagged by 33 scanners:
Scanner Software Result
Lavasoft Ad-Aware Adware.Generic.915161
Avira AntiVir Adware/CrossRider.A.2276
Antiy-AVL Trojan/Win32.SGeneric
avast! Win32:Adware-gen [Adw]
Baidu-International Adware.Win32.CrossRider.40
Bitdefender Adware.Generic.915161
Comodo Security ApplicUnwnt
Dr.Web Trojan.Crossrider.7519
Emsisoft Anti-Malware Adware.Generic.915161 (B)
ESET-NOD32 a variant of Win32/Toolbar.CrossRider.AC
Fortinet FortiGate Riskware/Toolbar_CrossRider
F-Secure Adware.Generic.915161
G Data Adware.Generic.915161
K7 AntiVirus Trojan ( 0049590e1 )
K7GW Trojan ( 0049590e1 )
Malwarebytes PUP.Optional.weDownload.A
McAfee Artemis!41BDA88949A1
McAfee-GW-Edition Artemis!41BDA88949A1
MicroWorld-eScan Adware.Generic.915161
NANO AntiVirus Trojan.Win32.Crossrider.cyaxwd
Sophos AppRider
Symantec Adware.Crossid
Tencent Win32.Risk.Adware.Pcjd
Trend Micro TROJ_GEN.R00JC0OE314
TrendMicro-HouseCall TROJ_GEN.R00JC0OE314
VIPRE Antivirus Crossrider (fs)
AVG Generic5.AMMM
Jiangmin AdWare/Lyckriks.ff
Kaspersky not-a-virus:AdWare.Win32.Lyckriks.mk
Kingsoft AntiVirus Win32.Troj.Lyckriks.mk.(kcloud)
Vba32 AntiVirus AdWare.Lyckriks
Agnitum Outpost PUA.Toolbar.CrossRider!
SUPERAntiSpyware Trojan.Agent/Gen-Crossrider
The weDownload-codedownloader.exe (MD5: 0817a60ddb8122aed06341df102d9540) has been flagged by 27 scanners:
Scanner Software Result
Lavasoft Ad-Aware Adware.Generic.904159
Antiy-AVL Trojan/Win32.SGeneric
Baidu-International Adware.Win32.CrossRider.X
Bitdefender Adware.Generic.904159
Dr.Web Trojan.Crossrider.7193
Emsisoft Anti-Malware Adware.Generic.904159 (B)
ESET-NOD32 a variant of Win32/Toolbar.CrossRider.X
Fortinet FortiGate Riskware/Toolbar_CrossRider
F-Secure Adware.Generic.904159
G Data Adware.Generic.904159
Malwarebytes PUP.Optional.weDownload.A
McAfee Artemis!0817A60DDB81
McAfee-GW-Edition Artemis!0817A60DDB81
MicroWorld-eScan Adware.Generic.904159
Symantec Adware.Crossid
TrendMicro-HouseCall TROJ_GEN.R047H05CJ14
VIPRE Antivirus Crossrider (fs)
AVG Generic5.AMMM
Comodo Security ApplicUnwnt
Jiangmin AdWare/Lyckriks.ff
Kaspersky not-a-virus:AdWare.Win32.Lyckriks.mk
Kingsoft AntiVirus Win32.Troj.Lyckriks.mk.(kcloud)
NANO AntiVirus Riskware.Win32.Lyckriks.ctgwey
Sophos AppRider
Vba32 AntiVirus AdWare.Lyckriks
Agnitum Outpost PUA.Toolbar.CrossRider!
SUPERAntiSpyware Trojan.Agent/Gen-Crossrider

Startup Entries

Startup tasks:
  • The weDownload-updater.exe is automatically launched at startup through a scheduled task named The weDownload-updater.
  • The weDownload-enabler.exe is automatically launched at startup through a scheduled task named The weDownload-enabler.
  • The weDownload-firefoxinstaller.exe is automatically launched at startup through a scheduled task named The weDownload-firefoxinstaller.
  • The weDownload-codedownloader.exe is automatically launched at startup through a scheduled task named The weDownload-codedownloader.
  • The weDownload-chromeinstaller.exe is automatically launched at startup through a scheduled task named The weDownload-chromeinstaller.

Software Details

URL:
https://www.wedownload.com
Support:
–
Installation path:
C:\Program Files\the wedownload
Uninstaller:
C:\Program Files\The weDownload\Uninstall.exe /fromcontrolpanel=1
Size:
7.00 MB
Language:
English

The weDownload Executable Details

Primary executable:
utils.exe
Name:
The weDownload
Path:
C:\Program Files\the wedownload\utils.exe
MD5:
c6ee850aa42eaf0b67e7a2bec46093f0
SHA-1:
–
SHA-256:
–
Files installed by The weDownload
File Type Filename MD5
EXE
17fda6aa05a402f281a5fd7b867a4f1a
EXE
utils.exe
Malware
c6ee850aa42eaf0b67e7a2bec46093f0
XPI
7372537912a40d0798652862b98b81a7
EXE
8389ddbb0307681874bbb865d6e29535
EXE
85f1d51a7cb4d948e97e4bbcb7ec9668
EXE
41bda88949a12d1f348d0669515d6316
EXE
0817a60ddb8122aed06341df102d9540
EXE
efbe2390e882d867d0646f0d0fa019c8
EXE
b32ea279f056e2611b31f3d97d6f5143
EXE
a44700f4d64dc0e4def6b3cb56bb1875