WeDownload Manager

WeDownload Manager Description


WeDownload Manager is a potentially unwanted application that affects all Internet browsers that are installed on the targeted computer system. WeDownload Manager may keep track of the target computer user’s browsing activity, show annoying pop-up ads and cause unwanted redirects to dubious advertising websites. WeDownload Manager may make affected PC users visit affiliated websites and show pop-up ads that carry sponsored links. WeDownload Manager does not ask a permission to enter the vulnerable computer. WeDownload Manager usually comes bundled together with freeware and shareware programs that web users can download from the net. WeDownload Manager may make changes on the targeted computer that may additionally lead to unwanted browser redirects to tricky websites and slow downs of the computer system.
DOWNLOAD NOW

» Learn more about SpyHunter's Spyware Detection Tool
and steps to uninstall SpyHunter.


WeDownload Manager Automatic Detection Tool (Recommended)


Is your PC infected with WeDownload Manager? To safely & quickly detect WeDownload Manager we highly recommend you run the malware scanner listed below.



Technical Details

Registry Modifications

Tutorial: To edit and delete registry entries manually, read the tutorial on how to remove malicious registry entries.

Tip & Warning: Editing and removing the wrong registry keys can severely damage your PC, so remember to backup your Windows Registry! To optimize your Windows Registry and speed up your PC, download RegHunter's registry cleaner.
  • The following newly produced Registry Values are:
    HKEY_LOCAL_MACHINE\Software\[APPLICATION]\Microsoft\Windows\CurrentVersion\Uninstall..{Uninstaller}The weDownloadThe weDownload ManagerHKEY..\..\..\..{RegistryKeys}CrossriderApp0045820.BHOCrossriderApp0045820.BHO.1CrossriderApp0045820.SandboxCrossriderApp0045820.Sandbox.1CrossriderApp0049072.BHOCrossriderApp0049072.BHO.1CrossriderApp0049072.SandboxCrossriderApp0049072.Sandbox.1CrossriderApp0049074.BHOCrossriderApp0049074.BHO.1CrossriderApp0049074.SandboxCrossriderApp0049074.Sandbox.1Local Settings\Software\Microsoft\Windows\CurrentVersion\AppContainer\Storage\windows_ie_ac_001\Software\The weDownloadLocal Settings\Software\Microsoft\Windows\CurrentVersion\AppContainer\Storage\windows_ie_ac_001\Software\The weDownload ManagerLocal Settings\Software\Microsoft\Windows\CurrentVersion\AppContainer\Storage\windows_ie_ac_001\Software\weDownloadSoftware\AppDataLow\Software\Crossrider\onBeforeNavigate, value: 49072Software\AppDataLow\Software\Crossrider\onRequest, value: 49072Software\AppDataLow\Software\weDownloadSOFTWARE\Classes\CrossriderApp0045820.Sandbox.1SOFTWARE\Classes\CrossriderApp0049072.BHOSOFTWARE\Classes\CrossriderApp0049074.BHOSOFTWARE\Classes\CrossriderApp0049074.BHO.1SOFTWARE\Classes\CrossriderApp0049074.SandboxSOFTWARE\Classes\CrossriderApp0049074.Sandbox.1Software\Classes\Local Settings\Software\Microsoft\Windows\CurrentVersion\AppContainer\Storage\windows_ie_ac_001\Software\The weDownload ManagerSoftware\InstalledBrowserExtensions\weDownloadSoftware\Microsoft\Internet Explorer\Approved Extensions, value: {11111111-1111-1111-1111-110411901172}SOFTWARE\Microsoft\Internet Explorer\Low Rights\ElevationPolicy\{08cb9b4e-1cca-4e21-a44b-cd4a7d7177ff}Software\Microsoft\Internet Explorer\Low Rights\ElevationPolicy\{08cb9b4e-1cca-4e21-a44b-cd4a7d7177ff}Software\Microsoft\Internet Explorer\Low Rights\ElevationPolicy\{0b89ac14-55d3-4267-afd6-0645a40d92b8}Software\Microsoft\Internet Explorer\Low Rights\ElevationPolicy\{156B9B44-6203-4AF7-BD34-531E8F397A8C}Software\Microsoft\Internet Explorer\Low Rights\ElevationPolicy\{16BE2A1C-2351-4092-9DF6-45386EA29FC0}Software\Microsoft\Internet Explorer\Low Rights\ElevationPolicy\{173AC77D-5D8F-4DD5-96E7-FFA2D1B6CB68}Software\Microsoft\Internet Explorer\Low Rights\ElevationPolicy\{4295812A-10EC-4480-A982-8AE8D1D2D43E}Software\Microsoft\Internet Explorer\Low Rights\ElevationPolicy\{45EFA2A9-2398-4EE0-B7BB-7070B0662AC1}Software\Microsoft\Internet Explorer\Low Rights\ElevationPolicy\{53CA519B-E1AE-47A6-B198-9B8DF059EF84}Software\Microsoft\Internet Explorer\Low Rights\ElevationPolicy\{572A1C2A-F61F-42BA-A662-9027712CC3C1}Software\Microsoft\Internet Explorer\Low Rights\ElevationPolicy\{611E0B20-8793-4066-9256-368428D49F26}SOFTWARE\Microsoft\Internet Explorer\Low Rights\ElevationPolicy\{61d12012-d3af-42f1-b0f7-ed6feffa463d}Software\Microsoft\Internet Explorer\Low Rights\ElevationPolicy\{61d12012-d3af-42f1-b0f7-ed6feffa463d}Software\Microsoft\Internet Explorer\Low Rights\ElevationPolicy\{8ACB51EA-B593-46F9-ACB9-9DC82EB3ED37}Software\Microsoft\Internet Explorer\Low Rights\ElevationPolicy\{95D103C8-44-409A-BBBB-CA8D75D6C78D}Software\Microsoft\Internet Explorer\Low Rights\ElevationPolicy\{A679DBFD-A346-41E5-AF17-B3FFE8DAB281}Software\Microsoft\Internet Explorer\Low Rights\ElevationPolicy\{C13AF94A-CBDA-4E16-A537-F87E034B2B2}Software\Microsoft\Internet Explorer\Low Rights\ElevationPolicy\{cc4fd57f-8174-4f55-9f24-0b4e330d2eb5}Software\Microsoft\Internet Explorer\Low Rights\ElevationPolicy\{cee7aa14-1e25-478f-b7cf-1e3996a492f5}Software\Microsoft\Internet Explorer\Low Rights\ElevationPolicy\{CFD0B20E-F05D-44E2-BB59-93CE9484B31}Software\Microsoft\Internet Explorer\Low Rights\ElevationPolicy\{D36CE1D9-FB79-4C9C-B32F-E87CCDAA97DA}Software\Microsoft\Internet Explorer\Low Rights\ElevationPolicy\{D5ED6EAF-4065-43F3-9DA3-3522ADC3CF}Software\Microsoft\Internet Explorer\Low Rights\ElevationPolicy\{D6EBE8E1-E998-4868-9F17-93B89EA3370}SOFTWARE\Microsoft\Tracing\DownloadManager_RASAPI32SOFTWARE\Microsoft\Tracing\DownloadManager_RASMANCSSOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Logon\{001BFCEE-FDD6-4163-AB6D-3FAEAE05CA9F}SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Logon\{505D68FE-DD60-40C5-B6E8-7C331FE8D429}SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tasks\{001BFCEE-FDD6-4163-AB6D-3FAEAE05CA9F}SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tasks\{09A03EBD-4E28-48CB-8217-913A35888FBE}SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tasks\{0BB5DB57-92AC-4045-B615-60D10E35F178}SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tasks\{0CCF4FD2-29CD-4F8A-8637-878EE7144297}SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tasks\{505D68FE-DD60-40C5-B6E8-7C331FE8D429}SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tree\The weDownload-codedownloaderSOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tree\The weDownload-enablerSOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tree\The weDownload-firefoxinstallerSOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tree\The weDownload-updaterSOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tree\weDownload-chromeinstallerSOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tree\weDownload-updaterSOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{11111111-1111-1111-1111-110411901172}SOFTWARE\Microsoft\Windows\CurrentVersion\Ext\PreApproved\{11111111-1111-1111-1111-110411901174}Software\Microsoft\Windows\CurrentVersion\Ext\Settings\{11111111-1111-1111-1111-110411581120}Software\Microsoft\Windows\CurrentVersion\Ext\Settings\{11111111-1111-1111-1111-110411901172}Software\Microsoft\Windows\CurrentVersion\Ext\Stats\{11111111-1111-1111-1111-110411581120}Software\Microsoft\Windows\CurrentVersion\Ext\Stats\{11111111-1111-1111-1111-110411901172}SOFTWARE\Microsoft\Windows\CurrentVersion\Policies\Ext\CLSID, value: {11111111-1111-1111-1111-110411901174}SOFTWARE\Microsoft\Windows\CurrentVersion\Policies\Ext\CLSID\, value: {11111111-1111-1111-1111-110411901172}SOFTWARE\The weDownloadSOFTWARE\The weDownload ManagerSoftware\WeDlMngrSoftware\weDownload LtdSOFTWARE\Wow6432Node\InstalledBrowserExtensions\21501SOFTWARE\Wow6432Node\Microsoft\Internet Explorer\Low Rights\ElevationPolicy\{05b276ea-b7a3-42dc-b13a-e2c7ff1528cf}SOFTWARE\Wow6432Node\Microsoft\Internet Explorer\Low Rights\ElevationPolicy\{0b89ac14-55d3-4267-afd6-0645a40d92b8}SOFTWARE\Wow6432Node\Microsoft\Internet Explorer\Low Rights\ElevationPolicy\{3fc09e11-fdbc-4523-bc73-d5ede4c2203c}SOFTWARE\Wow6432Node\Microsoft\Internet Explorer\Low Rights\ElevationPolicy\{61d12012-d3af-42f1-b0f7-ed6feffa463d}SOFTWARE\Wow6432Node\Microsoft\Internet Explorer\Low Rights\ElevationPolicy\{61e309e0-ddd1-4b8b-8280-83906a419e95}SOFTWARE\Wow6432Node\Microsoft\Internet Explorer\Low Rights\ElevationPolicy\{909e7b95-0cf8-4846-a707-ba4843063839}SOFTWARE\Wow6432Node\Microsoft\Internet Explorer\Low Rights\ElevationPolicy\{cc4fd57f-8174-4f55-9f24-0b4e330d2eb5}SOFTWARE\Wow6432Node\Microsoft\Internet Explorer\Low Rights\ElevationPolicy\{cee7aa14-1e25-478f-b7cf-1e3996a492f5}SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\explorer\Browser Helper Objects\{11111111-1111-1111-1111-110411581120}SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\Policies\Ext\CLSID, value: {11111111-1111-1111-1111-110411901172}SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\Uninstall\weDownloadSOFTWARE\Wow6432Node\The weDownload Manager
  • The following CLSID's were detected:
    HKEY..\..\{CLSID Path} {44444444-4444-4444-4444-440444904474}{66666666-6666-6666-6666-660466906674}{55555555-5555-5555-5555-550455905574}{22222222-2222-2222-2222-220422902274}{11111111-1111-1111-1111-110411901174}{44444444-4444-4444-4444-440444904472}{66666666-6666-6666-6666-660466906672}{55555555-5555-5555-5555-550455905572}{22222222-2222-2222-2222-220422902272}{11111111-1111-1111-1111-110411901172}{44444444-4444-4444-4444-440444584420}{66666666-6666-6666-6666-660466586620}
Posted: September 16, 2013 | By
Share:
Rate this article:
1 Star2 Stars3 Stars4 Stars5 Stars (No Ratings Yet)
Loading ... Loading ...
Threat Metric
Threat Level: 2/10
Detection Count: 1,189,710

Leave a Reply

What is 7 + 5 ?
Please leave these two fields as-is:
IMPORTANT! To be able to proceed, you need to solve the following simple math (so we know that you are a human) :-)