Home Malware Programs Potentially Unwanted Programs (PUPs) RayDownload

RayDownload

Posted: October 5, 2015

Threat Metric

Ranking: 9,583
Threat Level: 1/10
Infected PCs: 28,848
First Seen: September 18, 2015
Last Seen: March 4, 2025
OS(es) Affected: Windows

RayDownload is a tiny application of less than 1 MB that works as a download manager. This tool may appear to be useful initially, but you should not agree to install it without knowing all of its features. RayDownload is a Potentially Unwanted Program (PUP) that may have a negative impact on your web clients. Instead of assisting you by optimizing your downloads, this application may become annoying to you because it may insert additional advertising materials. According to Woodtable Technology Inc, the presence of such commercial materials is required to maintain the license of RayDownload free. However, according to most specialists, the ads are there just to generate income for the company. What is certain is that most clients are unhappy to see intrusive pop-ups, banners, interstitial ads and videos by RayDownload. The first and most noticeable negative aspect of these new commercial materials is that the users may find them on many different pages. This behavior may cause distraction and irritation because some of the ads may be placed in such a way to block some site buttons. What is more, they tend to be as eye-catching as possible. Some of the ads may lead to shopping sites, but a significant portion of the commercial materials may be totally useless. For example, they may claim that you have won the lottery, or you are the 'lucky visitor.' They also may offer you short surveys. Using these tactics, some companies may try to make you share your phone number or email address, which may afterward be used for spam campaigns. To maintain your system clean, you should consider removing the PUP.

Technical Details

File System Modifications

Tutorials: If you wish to learn how to remove malware components manually, you can read the tutorials on how to find malware, kill unwanted processes, remove malicious DLLs and delete other harmful files. Always be sure to back up your PC before making any changes.

The following files were created in the system:



Directory\Dannie_0792080062.docx File name: Dannie_0792080062.docx
Size: 441.95 KB (441950 bytes)
MD5: dc6c46ff966795fb09bf47a153236671
Detection count: 61
Mime Type: unknown/docx
Path: Directory
Group: Malware file
Last Updated: October 2, 2015
%PROGRAMFILES%\TData\TData.exe File name: TData.exe
Size: 137.41 KB (137416 bytes)
MD5: 10c804145b2214f0264e3240e7811540
Detection count: 5
File type: Executable File
Mime Type: unknown/exe
Path: %PROGRAMFILES%\TData
Group: Malware file
Last Updated: June 30, 2016
829cca8b6529840346fabd9fbd77c400 File name: 829cca8b6529840346fabd9fbd77c400
Size: 613.02 KB (613024 bytes)
MD5: 829cca8b6529840346fabd9fbd77c400
Detection count: 2
Group: Malware file
Last Updated: January 5, 2021

More files

Registry Modifications

The following newly produced Registry Values are:

CLSID{8DD92279-9B04-4C6F-A862-EF3C24603804}HKEY..\..\..\..{RegistryKeys}SOFTWARE\ihpmserverSOFTWARE\RayDldSOFTWARE\Wow6432Node\ihpmserverSOFTWARE\Wow6432Node\RayDldSYSTEM\ControlSet001\services\ihpmServerSYSTEM\ControlSet002\services\ihpmServerSYSTEM\CurrentControlSet\services\ihpmServer

Additional Information

The following directories were created:
%PROGRAMFILES%\RayDld%PROGRAMFILES%\RayDownload%PROGRAMFILES(x86)%\RayDld%PROGRAMFILES(x86)%\RayDownload

Related Posts

Loading...