Home Malware Programs Potentially Unwanted Programs (PUPs) WeDownload Manager

WeDownload Manager

Posted: September 16, 2013

Threat Metric

Ranking: 4,676
Threat Level: 2/10
Infected PCs: 172,531
First Seen: September 16, 2013
Last Seen: October 13, 2023
OS(es) Affected: Windows

WeDownload Manager is a potentially unwanted application that affects all Internet browsers that are installed on the targeted computer system. WeDownload Manager may keep track of the target computer user's browsing activity, show annoying pop-up ads and cause unwanted redirects to dubious advertising websites. WeDownload Manager may make affected PC users visit affiliated websites and show pop-up ads that carry sponsored links. WeDownload Manager does not ask a permission to enter the vulnerable computer. WeDownload Manager usually comes bundled together with freeware and shareware programs that web users can download from the net. WeDownload Manager may make changes on the targeted computer that may additionally lead to unwanted browser redirects to tricky websites and slow downs of the computer system.

Technical Details

File System Modifications

Tutorials: If you wish to learn how to remove malware components manually, you can read the tutorials on how to find malware, kill unwanted processes, remove malicious DLLs and delete other harmful files. Always be sure to back up your PC before making any changes.

The following files were created in the system:



%PROGRAMFILES(x86)%\The weDownload\The weDownload-bho64.dll File name: The weDownload-bho64.dll
Size: 969.21 KB (969216 bytes)
MD5: bba1269db0f7a2a5f08bf170c949515a
Detection count: 932
File type: Dynamic link library
Mime Type: unknown/dll
Path: %PROGRAMFILES(x86)%\The weDownload
Group: Malware file
Last Updated: August 30, 2019
C:\Program Files (x86)\The weDownload Manager\Uninstall.exe File name: Uninstall.exe
Size: 77.31 KB (77312 bytes)
MD5: 4eb2c1b2f97f3a9e39faa54f1fef9c2b
Detection count: 262
File type: Executable File
Mime Type: unknown/exe
Path: C:\Program Files (x86)\The weDownload Manager\Uninstall.exe
Group: Malware file
Last Updated: February 10, 2023
C:\AdwCleaner\Quarantine\C\Program Files (x86)\The weDownload\Uninstall.exe.vir File name: Uninstall.exe.vir
Size: 77.31 KB (77312 bytes)
MD5: 17fda6aa05a402f281a5fd7b867a4f1a
Detection count: 112
Mime Type: unknown/vir
Path: C:\AdwCleaner\Quarantine\C\Program Files (x86)\The weDownload\Uninstall.exe.vir
Group: Malware file
Last Updated: April 16, 2022
%PROGRAMFILES%\weDownload Manager\weDownload Manager-updater.exe File name: weDownload Manager-updater.exe
Size: 391.16 KB (391168 bytes)
MD5: a37db88a9884a61b34f1ad0401d7481b
Detection count: 95
File type: Executable File
Mime Type: unknown/exe
Path: %PROGRAMFILES%\weDownload Manager
Group: Malware file
Last Updated: February 17, 2014
%PROGRAMFILES%\weDownload Manager\weDownload Manager-chromeinstaller.exe File name: weDownload Manager-chromeinstaller.exe
Size: 586.74 KB (586747 bytes)
MD5: 5577463478b15ed5da6d4726ba653a4b
Detection count: 94
File type: Executable File
Mime Type: unknown/exe
Path: %PROGRAMFILES%\weDownload Manager
Group: Malware file
Last Updated: February 17, 2014
%PROGRAMFILES%\weDownload Manager\weDownload Manager-enabler.exe File name: weDownload Manager-enabler.exe
Size: 374.27 KB (374272 bytes)
MD5: dec60bd16c2dc02525137bacfe5d1ee7
Detection count: 93
File type: Executable File
Mime Type: unknown/exe
Path: %PROGRAMFILES%\weDownload Manager
Group: Malware file
Last Updated: February 17, 2014
%PROGRAMFILES%\weDownload Manager\weDownload Manager-codedownloader.exe File name: weDownload Manager-codedownloader.exe
Size: 603.08 KB (603080 bytes)
MD5: 25c0bc5d6c6ac5a394a45f78bb21ce50
Detection count: 93
File type: Executable File
Mime Type: unknown/exe
Path: %PROGRAMFILES%\weDownload Manager
Group: Malware file
Last Updated: February 17, 2014
%PROGRAMFILES%\weDownload Manager\weDownload Manager-enabler.exe File name: weDownload Manager-enabler.exe
Size: 423.3 KB (423303 bytes)
MD5: d815fe64d8196f8045bb07ea449f56c9
Detection count: 92
File type: Executable File
Mime Type: unknown/exe
Path: %PROGRAMFILES%\weDownload Manager
Group: Malware file
Last Updated: February 17, 2014
%PROGRAMFILES%\weDownload Manager\weDownload Manager-firefoxinstaller.exe File name: weDownload Manager-firefoxinstaller.exe
Size: 852.47 KB (852476 bytes)
MD5: 8e2e12c924db5c98b8c15c4f32c46b47
Detection count: 91
File type: Executable File
Mime Type: unknown/exe
Path: %PROGRAMFILES%\weDownload Manager
Group: Malware file
Last Updated: February 17, 2014
%PROGRAMFILES%\weDownload Manager\weDownload Manager-updater.exe File name: weDownload Manager-updater.exe
Size: 435.07 KB (435075 bytes)
MD5: 5ef51d404efdcf6c19317030aa240fcb
Detection count: 90
File type: Executable File
Mime Type: unknown/exe
Path: %PROGRAMFILES%\weDownload Manager
Group: Malware file
Last Updated: February 17, 2014
%PROGRAMFILES(x86)%\weDownload Manager Pro\weDownload Manager Pro-enabler.exe File name: weDownload Manager Pro-enabler.exe
Size: 346.62 KB (346624 bytes)
MD5: 8b035f6969b8a9b0c3ca5ac5f9f820c4
Detection count: 85
File type: Executable File
Mime Type: unknown/exe
Path: %PROGRAMFILES(x86)%\weDownload Manager Pro
Group: Malware file
Last Updated: February 17, 2014
%PROGRAMFILES(x86)%\weDownload Manager Pro\weDownload Manager Pro-codedownloader.exe File name: weDownload Manager Pro-codedownloader.exe
Size: 487.42 KB (487424 bytes)
MD5: 228def208223b845c8da16c954537252
Detection count: 84
File type: Executable File
Mime Type: unknown/exe
Path: %PROGRAMFILES(x86)%\weDownload Manager Pro
Group: Malware file
Last Updated: February 17, 2014
%PROGRAMFILES(x86)%\weDownload Manager Pro\weDownload Manager Pro-buttonutil64.exe File name: weDownload Manager Pro-buttonutil64.exe
Size: 423.93 KB (423936 bytes)
MD5: 08fc5817f51dd5370f717c1f2d54d723
Detection count: 19
File type: Executable File
Mime Type: unknown/exe
Path: %PROGRAMFILES(x86)%\weDownload Manager Pro\weDownload Manager Pro-buttonutil64.exe
Group: Malware file
Last Updated: July 24, 2022
%PROGRAMFILES%\weDownload Manager Pro\weDownload Manager Pro-bho.dll File name: weDownload Manager Pro-bho.dll
Size: 637.44 KB (637440 bytes)
MD5: 58d2fd86c09f6549429d70721078d708
Detection count: 14
File type: Dynamic link library
Mime Type: unknown/dll
Path: %PROGRAMFILES%\weDownload Manager Pro
Group: Malware file
Last Updated: February 17, 2014
%PROGRAMFILES%\weDownload Manager Pro\weDownload Manager Pro-firefoxinstaller.exe File name: weDownload Manager Pro-firefoxinstaller.exe
Size: 907.77 KB (907776 bytes)
MD5: f38ac8fa28e7bbe27423956ec6b5eaf5
Detection count: 5
File type: Executable File
Mime Type: unknown/exe
Path: %PROGRAMFILES%\weDownload Manager Pro
Group: Malware file
Last Updated: February 17, 2014
%PROGRAMFILES%\weDownload Manager Pro\weDownload Manager Pro-updater.exe File name: weDownload Manager Pro-updater.exe
Size: 429.56 KB (429568 bytes)
MD5: dbc7c9f592255169175dfc5fbf088d3f
Detection count: 5
File type: Executable File
Mime Type: unknown/exe
Path: %PROGRAMFILES%\weDownload Manager Pro
Group: Malware file
Last Updated: February 17, 2014
%PROGRAMFILES(x86)%\weDownload Manager Pro\weDownload Manager Pro-codedownloader.exe File name: weDownload Manager Pro-codedownloader.exe
Size: 519.68 KB (519680 bytes)
MD5: e7b6574e3f2bc29f351b8195937cdc55
Detection count: 5
File type: Executable File
Mime Type: unknown/exe
Path: %PROGRAMFILES(x86)%\weDownload Manager Pro
Group: Malware file
Last Updated: February 17, 2014
%PROGRAMFILES%\The weDownload\The weDownload-chromeinstaller.exe File name: The weDownload-chromeinstaller.exe
Size: 1.03 MB (1032704 bytes)
MD5: 0cb6f8ddd7f7bfc102361d62381842af
Detection count: 5
File type: Executable File
Mime Type: unknown/exe
Path: %PROGRAMFILES%\The weDownload
Group: Malware file
Last Updated: February 17, 2014
%PROGRAMFILES%\The weDownload\The weDownload-codedownloader.exe File name: The weDownload-codedownloader.exe
Size: 631.29 KB (631296 bytes)
MD5: bf2946d0db5e607a50f35caffcb98993
Detection count: 5
File type: Executable File
Mime Type: unknown/exe
Path: %PROGRAMFILES%\The weDownload
Group: Malware file
Last Updated: February 17, 2014
%PROGRAMFILES%\The weDownload\The weDownload-enabler.exe File name: The weDownload-enabler.exe
Size: 454.65 KB (454656 bytes)
MD5: 23dd2e83bbaaa16cfef012356bceb461
Detection count: 5
File type: Executable File
Mime Type: unknown/exe
Path: %PROGRAMFILES%\The weDownload
Group: Malware file
Last Updated: February 17, 2014
%PROGRAMFILES%\The weDownload\The weDownload-firefoxinstaller.exe File name: The weDownload-firefoxinstaller.exe
Size: 993.28 KB (993280 bytes)
MD5: dcde2b71601a8f2fbb7001b924232ca7
Detection count: 5
File type: Executable File
Mime Type: unknown/exe
Path: %PROGRAMFILES%\The weDownload
Group: Malware file
Last Updated: February 17, 2014
%PROGRAMFILES%\The weDownload\The weDownload-updater.exe File name: The weDownload-updater.exe
Size: 452.6 KB (452608 bytes)
MD5: ba07762fc20a05400fb67fb90d2a7be6
Detection count: 5
File type: Executable File
Mime Type: unknown/exe
Path: %PROGRAMFILES%\The weDownload
Group: Malware file
Last Updated: February 17, 2014
%PROGRAMFILES(x86)%\The weDownload\The weDownload-validator.exe File name: The weDownload-validator.exe
Size: 2.01 MB (2019328 bytes)
MD5: 1f2bea10d1d58a0c08b6e2549d76d83f
Detection count: 5
File type: Executable File
Mime Type: unknown/exe
Path: %PROGRAMFILES(x86)%\The weDownload
Group: Malware file
Last Updated: February 17, 2014
%PROGRAMFILES%\weDownload Manager\weDownload Manager-codedownloader.exe File name: weDownload Manager-codedownloader.exe
Size: 515.07 KB (515072 bytes)
MD5: 51ead83bb7cdc3b87fb16070f489003e
Detection count: 5
File type: Executable File
Mime Type: unknown/exe
Path: %PROGRAMFILES%\weDownload Manager
Group: Malware file
Last Updated: February 17, 2014
%PROGRAMFILES%\weDownload Manager\weDownload Manager-firefoxinstaller.exe File name: weDownload Manager-firefoxinstaller.exe
Size: 750.59 KB (750592 bytes)
MD5: 779ac3649b71af0b6bec21f04b354291
Detection count: 5
File type: Executable File
Mime Type: unknown/exe
Path: %PROGRAMFILES%\weDownload Manager
Group: Malware file
Last Updated: February 17, 2014

More files

Registry Modifications

The following newly produced Registry Values are:

CLSID{11111111-1111-1111-1111-110411581120}{11111111-1111-1111-1111-110411901172}{11111111-1111-1111-1111-110411901174}{22222222-2222-2222-2222-220422582220}{22222222-2222-2222-2222-220422902272}{22222222-2222-2222-2222-220422902274}{44444444-4444-4444-4444-440444584420}{44444444-4444-4444-4444-440444904472}{44444444-4444-4444-4444-440444904474}{55555555-5555-5555-5555-550455585520}{55555555-5555-5555-5555-550455905572}{55555555-5555-5555-5555-550455905574}{66666666-6666-6666-6666-660466586620}{66666666-6666-6666-6666-660466906672}{66666666-6666-6666-6666-660466906674}HKEY..\..\..\..{RegistryKeys}Software\AppDataLow\Software\Crossrider\onBeforeNavigate\49072Software\AppDataLow\Software\Crossrider\onRequest\49072Software\AppDataLow\Software\The weDownloadSoftware\AppDataLow\Software\The weDownload ManagerSoftware\AppDataLow\Software\The weDownload\UpdateSoftware\AppDataLow\Software\weDownloadSOFTWARE\Classes\CrossriderApp0045820.BHOSOFTWARE\Classes\CrossriderApp0045820.BHO.1SOFTWARE\Classes\CrossriderApp0045820.SandboxSOFTWARE\Classes\CrossriderApp0045820.Sandbox.1SOFTWARE\Classes\CrossriderApp0049072.BHOSOFTWARE\Classes\CrossriderApp0049072.BHO.1SOFTWARE\Classes\CrossriderApp0049072.SandboxSOFTWARE\Classes\CrossriderApp0049072.Sandbox.1SOFTWARE\Classes\CrossriderApp0049074.BHOSOFTWARE\Classes\CrossriderApp0049074.BHO.1SOFTWARE\Classes\CrossriderApp0049074.SandboxSOFTWARE\Classes\CrossriderApp0049074.Sandbox.1Software\Classes\Local Settings\Software\Microsoft\Windows\CurrentVersion\AppContainer\Storage\windows_ie_ac_001\Software\The weDownloadSoftware\Classes\Local Settings\Software\Microsoft\Windows\CurrentVersion\AppContainer\Storage\windows_ie_ac_001\Software\The weDownload ManagerSoftware\InstalledBrowserExtensions\21501Software\InstalledBrowserExtensions\weDownloadSoftware\Microsoft\Internet Explorer\Approved Extensions\{11111111-1111-1111-1111-110411581120}Software\Microsoft\Internet Explorer\Approved Extensions\{11111111-1111-1111-1111-110411901172}Software\Microsoft\Internet Explorer\ApprovedExtensionsMigration\{11111111-1111-1111-1111-110411901174}SOFTWARE\Microsoft\Internet Explorer\Low Rights\ElevationPolicy\{08cb9b4e-1cca-4e21-a44b-cd4a7d7177ff}Software\Microsoft\Internet Explorer\Low Rights\ElevationPolicy\{0b89ac14-55d3-4267-afd6-0645a40d92b8}Software\Microsoft\Internet Explorer\Low Rights\ElevationPolicy\{3fc09e11-fdbc-4523-bc73-d5ede4c2203c}SOFTWARE\Microsoft\Internet Explorer\Low Rights\ElevationPolicy\{61d12012-d3af-42f1-b0f7-ed6feffa463d}Software\Microsoft\Internet Explorer\Low Rights\ElevationPolicy\{61e309e0-ddd1-4b8b-8280-83906a419e95}Software\Microsoft\Internet Explorer\Low Rights\ElevationPolicy\{909e7b95-0cf8-4846-a707-ba4843063839}Software\Microsoft\Internet Explorer\Low Rights\ElevationPolicy\{cc4fd57f-8174-4f55-9f24-0b4e330d2eb5}SOFTWARE\Microsoft\Internet Explorer\MAIN\FeatureControl\FEATURE_BROWSER_EMULATION\The weDownload-bg.exeSOFTWARE\Microsoft\Tracing\DownloadManager_RASAPI32SOFTWARE\Microsoft\Tracing\DownloadManager_RASMANCSSOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tree\The weDownload-codedownloaderSOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tree\The weDownload-enablerSOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tree\The weDownload-firefoxinstallerSOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tree\The weDownload-updaterSOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tree\weDownload-chromeinstallerSOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tree\weDownload-codedownloaderSOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tree\weDownload-enablerSOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tree\weDownload-firefoxinstallerSOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tree\weDownload-updaterSOFTWARE\Microsoft\Windows\CurrentVersion\explorer\Browser Helper Objects\{11111111-1111-1111-1111-110411581120}SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{11111111-1111-1111-1111-110411901172}Software\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{11111111-1111-1111-1111-110411901174}SOFTWARE\Microsoft\Windows\CurrentVersion\Ext\PreApproved\{11111111-1111-1111-1111-110411901174}Software\Microsoft\Windows\CurrentVersion\Ext\Settings\{11111111-1111-1111-1111-110411581120}Software\Microsoft\Windows\CurrentVersion\Ext\Settings\{11111111-1111-1111-1111-110411901172}Software\Microsoft\Windows\CurrentVersion\Ext\Stats\{11111111-1111-1111-1111-110411581120}Software\Microsoft\Windows\CurrentVersion\Ext\Stats\{11111111-1111-1111-1111-110411901172}SOFTWARE\Microsoft\Windows\CurrentVersion\Policies\Ext\CLSID\\{11111111-1111-1111-1111-110411901172}SOFTWARE\Microsoft\Windows\CurrentVersion\Policies\Ext\CLSID\{11111111-1111-1111-1111-110411901174}SOFTWARE\The weDownloadSOFTWARE\The weDownload ManagerSoftware\WeDlMngrSOFTWARE\weDownloadSoftware\weDownload LtdSOFTWARE\Wow6432Node\InstalledBrowserExtensions\21501SOFTWARE\Wow6432Node\Microsoft\Internet Explorer\Low Rights\ElevationPolicy\{08cb9b4e-1cca-4e21-a44b-cd4a7d7177ff}SOFTWARE\Wow6432Node\Microsoft\Internet Explorer\Low Rights\ElevationPolicy\{0b89ac14-55d3-4267-afd6-0645a40d92b8}SOFTWARE\Wow6432Node\Microsoft\Internet Explorer\Low Rights\ElevationPolicy\{3fc09e11-fdbc-4523-bc73-d5ede4c2203c}SOFTWARE\Wow6432Node\Microsoft\Internet Explorer\Low Rights\ElevationPolicy\{61d12012-d3af-42f1-b0f7-ed6feffa463d}SOFTWARE\Wow6432Node\Microsoft\Internet Explorer\Low Rights\ElevationPolicy\{61e309e0-ddd1-4b8b-8280-83906a419e95}SOFTWARE\Wow6432Node\Microsoft\Internet Explorer\Low Rights\ElevationPolicy\{909e7b95-0cf8-4846-a707-ba4843063839}SOFTWARE\Wow6432Node\Microsoft\Internet Explorer\Low Rights\ElevationPolicy\{cc4fd57f-8174-4f55-9f24-0b4e330d2eb5}SOFTWARE\Wow6432Node\Microsoft\Internet Explorer\MAIN\FeatureControl\FEATURE_BROWSER_EMULATION\The weDownload-bg.exeSOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\Ext\PreApproved\{11111111-1111-1111-1111-110411901174}SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\Policies\Ext\CLSID\{11111111-1111-1111-1111-110411901172}SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\Policies\Ext\CLSID\{11111111-1111-1111-1111-110411901174}SOFTWARE\Wow6432Node\The weDownloadSOFTWARE\Wow6432Node\The weDownload ManagerSOFTWARE\Wow6432Node\weDownloadSOFTWARE\Wow6432Node\weDownload LtdHKEY_LOCAL_MACHINE\Software\[APPLICATION]\Microsoft\Windows\CurrentVersion\Uninstall..{Uninstaller}The weDownloadThe weDownload ManagerweDownload

Additional Information

The following directories were created:
%APPDATA%\weDownload Ltd%PROGRAMFILES%\The weDownload%PROGRAMFILES%\The weDownload Manager%PROGRAMFILES%\weDownload%PROGRAMFILES(X86)%\weDownload%PROGRAMFILES(x86)%\The weDownload%PROGRAMFILES(x86)%\The weDownload Manager%USERPROFILE%\AppData\LocalLow\weDownload
Loading...