The weDownload

The weDownload

Known Malware

by weDownload Ltd

What is The weDownload?

The weDownload is software application developed by weDownload Ltd. It is most commonly found on computers running Windows 7 with nearly 59.74% of installations running this operating system. The weDownload's installer is typically 7.00 MB in size and installs around 17 files. The most common release is 1.34.2.13 with 46.05% of all installations currently using this version.

The weDownload is most popular in the United States with 30.08% of installations residing in this country.

About The weDownload?

WeDownload is a web browser extension and Browser Helper Object (BHO) designed to deliver contextual-based advertising to Internet Explorer. It has the capability to modify the user's browser home and search pages, as well as 'New Tab' pages, in order to push advertising and search results. Additionally, the software may be bundled with potentially unwanted applications from the same publisher and third-party apps.

Multiple virus scanners have detected malware in The weDownload.

utils.exe (MD5: c6ee850aa42eaf0b67e7a2bec46093f0) has been flagged by 35 scanners:
Scanner Software Result
AhnLab-V3 PUP/Win32.MulDrop
Bkav FE HW32.CDB
Malwarebytes PUP.Optional.CrossRider.A
Symantec WS.Reputation
Lavasoft Ad-Aware Adware.Generic.915161
Avira AntiVir Adware/CrossRider.A.2276
Antiy-AVL Trojan/Win32.SGeneric
avast! Win32:Adware-gen [Adw]
Baidu-International Adware.Win32.CrossRider.40
Bitdefender Adware.Generic.915161
Comodo Security ApplicUnwnt
Dr.Web Trojan.Crossrider.7519
Emsisoft Anti-Malware Adware.Generic.915161 (B)
ESET-NOD32 a variant of Win32/Toolbar.CrossRider.AC
Fortinet FortiGate Riskware/Toolbar_CrossRider
F-Secure Adware.Generic.915161
G Data Adware.Generic.915161
K7 AntiVirus Trojan ( 0049590e1 )
K7GW Trojan ( 0049590e1 )
McAfee Artemis!41BDA88949A1
McAfee-GW-Edition Artemis!41BDA88949A1
MicroWorld-eScan Adware.Generic.915161
NANO AntiVirus Trojan.Win32.Crossrider.cyaxwd
Sophos AppRider
Tencent Win32.Risk.Adware.Pcjd
Trend Micro TROJ_GEN.R00JC0OE314
TrendMicro-HouseCall TROJ_GEN.R00JC0OE314
VIPRE Antivirus Crossrider (fs)
AVG Generic5.AMMM
Jiangmin AdWare/Lyckriks.ff
Kaspersky not-a-virus:AdWare.Win32.Lyckriks.mk
Kingsoft AntiVirus Win32.Troj.Lyckriks.mk.(kcloud)
Vba32 AntiVirus AdWare.Lyckriks
Agnitum Outpost PUA.Toolbar.CrossRider!
SUPERAntiSpyware Trojan.Agent/Gen-Crossrider
The weDownload-updater.exe (MD5: 8389ddbb0307681874bbb865d6e29535) has been flagged by 13 scanners:
Scanner Software Result
Agnitum Outpost PUA.Toolbar.CrossRider!
Baidu-International Adware.Win32.CrossRider.X
Dr.Web Trojan.Crossrider.7209
ESET-NOD32 a variant of Win32/Toolbar.CrossRider.X
Fortinet FortiGate Riskware/Toolbar_CrossRider
Malwarebytes PUP.Optional.weDownload.A
McAfee Artemis!8389DDBB0307
McAfee-GW-Edition Artemis!8389DDBB0307
SUPERAntiSpyware Trojan.Agent/Gen-Crossrider
Symantec Adware.Crossid
TrendMicro-HouseCall TROJ_GEN.R0C1H05CR14
VIPRE Antivirus Crossrider (fs)
AVG MultiBundle.V
The weDownload-firefoxinstaller.exe (MD5: 85f1d51a7cb4d948e97e4bbcb7ec9668) has been flagged by 11 scanners:
Scanner Software Result
AVG MultiBundle.V
Baidu-International Adware.Win32.CrossRider.40
Dr.Web Trojan.Crossrider.7210
ESET-NOD32 a variant of Win32/Toolbar.CrossRider.Y
Fortinet FortiGate Riskware/Toolbar_CrossRider
Malwarebytes PUP.Optional.weDownload.A
McAfee Artemis!85F1D51A7CB4
McAfee-GW-Edition Artemis!85F1D51A7CB4
Symantec Adware.Crossid
TrendMicro-HouseCall TROJ_GEN.R0C1H05CR14
VIPRE Antivirus Crossrider (fs)
The weDownload-enabler.exe (MD5: 41bda88949a12d1f348d0669515d6316) has been flagged by 33 scanners:
Scanner Software Result
Lavasoft Ad-Aware Adware.Generic.915161
Avira AntiVir Adware/CrossRider.A.2276
Antiy-AVL Trojan/Win32.SGeneric
avast! Win32:Adware-gen [Adw]
Baidu-International Adware.Win32.CrossRider.40
Bitdefender Adware.Generic.915161
Comodo Security ApplicUnwnt
Dr.Web Trojan.Crossrider.7519
Emsisoft Anti-Malware Adware.Generic.915161 (B)
ESET-NOD32 a variant of Win32/Toolbar.CrossRider.AC
Fortinet FortiGate Riskware/Toolbar_CrossRider
F-Secure Adware.Generic.915161
G Data Adware.Generic.915161
K7 AntiVirus Trojan ( 0049590e1 )
K7GW Trojan ( 0049590e1 )
Malwarebytes PUP.Optional.weDownload.A
McAfee Artemis!41BDA88949A1
McAfee-GW-Edition Artemis!41BDA88949A1
MicroWorld-eScan Adware.Generic.915161
NANO AntiVirus Trojan.Win32.Crossrider.cyaxwd
Sophos AppRider
Symantec Adware.Crossid
Tencent Win32.Risk.Adware.Pcjd
Trend Micro TROJ_GEN.R00JC0OE314
TrendMicro-HouseCall TROJ_GEN.R00JC0OE314
VIPRE Antivirus Crossrider (fs)
AVG Generic5.AMMM
Jiangmin AdWare/Lyckriks.ff
Kaspersky not-a-virus:AdWare.Win32.Lyckriks.mk
Kingsoft AntiVirus Win32.Troj.Lyckriks.mk.(kcloud)
Vba32 AntiVirus AdWare.Lyckriks
Agnitum Outpost PUA.Toolbar.CrossRider!
SUPERAntiSpyware Trojan.Agent/Gen-Crossrider
The weDownload-codedownloader.exe (MD5: 0817a60ddb8122aed06341df102d9540) has been flagged by 27 scanners:
Scanner Software Result
Lavasoft Ad-Aware Adware.Generic.904159
Antiy-AVL Trojan/Win32.SGeneric
Baidu-International Adware.Win32.CrossRider.X
Bitdefender Adware.Generic.904159
Dr.Web Trojan.Crossrider.7193
Emsisoft Anti-Malware Adware.Generic.904159 (B)
ESET-NOD32 a variant of Win32/Toolbar.CrossRider.X
Fortinet FortiGate Riskware/Toolbar_CrossRider
F-Secure Adware.Generic.904159
G Data Adware.Generic.904159
Malwarebytes PUP.Optional.weDownload.A
McAfee Artemis!0817A60DDB81
McAfee-GW-Edition Artemis!0817A60DDB81
MicroWorld-eScan Adware.Generic.904159
Symantec Adware.Crossid
TrendMicro-HouseCall TROJ_GEN.R047H05CJ14
VIPRE Antivirus Crossrider (fs)
AVG Generic5.AMMM
Comodo Security ApplicUnwnt
Jiangmin AdWare/Lyckriks.ff
Kaspersky not-a-virus:AdWare.Win32.Lyckriks.mk
Kingsoft AntiVirus Win32.Troj.Lyckriks.mk.(kcloud)
NANO AntiVirus Riskware.Win32.Lyckriks.ctgwey
Sophos AppRider
Vba32 AntiVirus AdWare.Lyckriks
Agnitum Outpost PUA.Toolbar.CrossRider!
SUPERAntiSpyware Trojan.Agent/Gen-Crossrider

Startup Entries

Startup tasks:
  • The weDownload-updater.exe is automatically launched at startup through a scheduled task named The weDownload-updater.
  • The weDownload-enabler.exe is automatically launched at startup through a scheduled task named The weDownload-enabler.
  • The weDownload-firefoxinstaller.exe is automatically launched at startup through a scheduled task named The weDownload-firefoxinstaller.
  • The weDownload-codedownloader.exe is automatically launched at startup through a scheduled task named The weDownload-codedownloader.
  • The weDownload-chromeinstaller.exe is automatically launched at startup through a scheduled task named The weDownload-chromeinstaller.

Software Details

URL:
https://www.wedownload.com
Support:
–
Installation path:
C:\Program Files\the wedownload
Uninstaller:
C:\Program Files\The weDownload\Uninstall.exe /fromcontrolpanel=1
Size:
7.00 MB
Language:
English

The weDownload Executable Details

Primary executable:
utils.exe
Name:
The weDownload
Path:
C:\Program Files\the wedownload\utils.exe
MD5:
c6ee850aa42eaf0b67e7a2bec46093f0
SHA-1:
–
SHA-256:
–
Files installed by The weDownload
File Type Filename MD5
DLL
e48fac65f468b29795843b4bea2d0b80
DLL
acc117b55ebecd9b2119ac9a7dce3ed8
EXE
c9c625acd777e55fc5739e9a428b1dce
DLL
c1b7379b3f39046dc1344ce803062300
DLL
e558b0e3fe8c65873f10487241134d99
EXE
41cb5842874eb9351c169aa64a516d75
CRX
9eabc12955a611170fe2e4982d628c82