Home Malware Programs Potentially Unwanted Programs (PUPs) WeDownload Manager

WeDownload Manager

Posted: September 16, 2013

Threat Metric

Ranking: 6,094
Threat Level: 2/10
Infected PCs: 173,079
First Seen: September 16, 2013
Last Seen: March 10, 2025
OS(es) Affected: Windows

WeDownload Manager is a potentially unwanted application that affects all Internet browsers that are installed on the targeted computer system. WeDownload Manager may keep track of the target computer user's browsing activity, show annoying pop-up ads and cause unwanted redirects to dubious advertising websites. WeDownload Manager may make affected PC users visit affiliated websites and show pop-up ads that carry sponsored links. WeDownload Manager does not ask a permission to enter the vulnerable computer. WeDownload Manager usually comes bundled together with freeware and shareware programs that web users can download from the net. WeDownload Manager may make changes on the targeted computer that may additionally lead to unwanted browser redirects to tricky websites and slow downs of the computer system.

Technical Details

File System Modifications

Tutorials: If you wish to learn how to remove malware components manually, you can read the tutorials on how to find malware, kill unwanted processes, remove malicious DLLs and delete other harmful files. Always be sure to back up your PC before making any changes.

The following files were created in the system:



%PROGRAMFILES(x86)%\The weDownload\The weDownload-bho64.dll File name: The weDownload-bho64.dll
Size: 969.21 KB (969216 bytes)
MD5: bba1269db0f7a2a5f08bf170c949515a
Detection count: 932
File type: Dynamic link library
Mime Type: unknown/dll
Path: %PROGRAMFILES(x86)%\The weDownload
Group: Malware file
Last Updated: August 30, 2019
C:\Program Files (x86)\The weDownload Manager\Uninstall.exe File name: Uninstall.exe
Size: 77.31 KB (77312 bytes)
MD5: 4eb2c1b2f97f3a9e39faa54f1fef9c2b
Detection count: 262
File type: Executable File
Mime Type: unknown/exe
Path: C:\Program Files (x86)\The weDownload Manager\Uninstall.exe
Group: Malware file
Last Updated: February 10, 2023
C:\AdwCleaner\Quarantine\C\Program Files (x86)\The weDownload\Uninstall.exe.vir File name: Uninstall.exe.vir
Size: 77.31 KB (77312 bytes)
MD5: 17fda6aa05a402f281a5fd7b867a4f1a
Detection count: 112
Mime Type: unknown/vir
Path: C:\AdwCleaner\Quarantine\C\Program Files (x86)\The weDownload\Uninstall.exe.vir
Group: Malware file
Last Updated: April 16, 2022
%PROGRAMFILES%\weDownload Manager\weDownload Manager-chromeinstaller.exe File name: weDownload Manager-chromeinstaller.exe
Size: 586.74 KB (586747 bytes)
MD5: 5577463478b15ed5da6d4726ba653a4b
Detection count: 94
File type: Executable File
Mime Type: unknown/exe
Path: %PROGRAMFILES%\weDownload Manager
Group: Malware file
Last Updated: February 17, 2014
%PROGRAMFILES%\weDownload Manager\weDownload Manager-codedownloader.exe File name: weDownload Manager-codedownloader.exe
Size: 603.08 KB (603080 bytes)
MD5: 25c0bc5d6c6ac5a394a45f78bb21ce50
Detection count: 93
File type: Executable File
Mime Type: unknown/exe
Path: %PROGRAMFILES%\weDownload Manager
Group: Malware file
Last Updated: February 17, 2014
%PROGRAMFILES%\weDownload Manager\weDownload Manager-enabler.exe File name: weDownload Manager-enabler.exe
Size: 423.3 KB (423303 bytes)
MD5: d815fe64d8196f8045bb07ea449f56c9
Detection count: 92
File type: Executable File
Mime Type: unknown/exe
Path: %PROGRAMFILES%\weDownload Manager
Group: Malware file
Last Updated: February 17, 2014
%PROGRAMFILES%\weDownload Manager\weDownload Manager-firefoxinstaller.exe File name: weDownload Manager-firefoxinstaller.exe
Size: 852.47 KB (852476 bytes)
MD5: 8e2e12c924db5c98b8c15c4f32c46b47
Detection count: 91
File type: Executable File
Mime Type: unknown/exe
Path: %PROGRAMFILES%\weDownload Manager
Group: Malware file
Last Updated: February 17, 2014
%PROGRAMFILES%\weDownload Manager\weDownload Manager-updater.exe File name: weDownload Manager-updater.exe
Size: 435.07 KB (435075 bytes)
MD5: 5ef51d404efdcf6c19317030aa240fcb
Detection count: 90
File type: Executable File
Mime Type: unknown/exe
Path: %PROGRAMFILES%\weDownload Manager
Group: Malware file
Last Updated: February 17, 2014
%PROGRAMFILES(x86)%\weDownload Manager Pro\weDownload Manager Pro-enabler.exe File name: weDownload Manager Pro-enabler.exe
Size: 346.62 KB (346624 bytes)
MD5: 8b035f6969b8a9b0c3ca5ac5f9f820c4
Detection count: 85
File type: Executable File
Mime Type: unknown/exe
Path: %PROGRAMFILES(x86)%\weDownload Manager Pro
Group: Malware file
Last Updated: February 17, 2014
%PROGRAMFILES(x86)%\weDownload Manager Pro\weDownload Manager Pro-codedownloader.exe File name: weDownload Manager Pro-codedownloader.exe
Size: 487.42 KB (487424 bytes)
MD5: 228def208223b845c8da16c954537252
Detection count: 84
File type: Executable File
Mime Type: unknown/exe
Path: %PROGRAMFILES(x86)%\weDownload Manager Pro
Group: Malware file
Last Updated: February 17, 2014
%PROGRAMFILES(x86)%\weDownload Manager Pro\weDownload Manager Pro-buttonutil64.exe File name: weDownload Manager Pro-buttonutil64.exe
Size: 423.93 KB (423936 bytes)
MD5: 08fc5817f51dd5370f717c1f2d54d723
Detection count: 19
File type: Executable File
Mime Type: unknown/exe
Path: %PROGRAMFILES(x86)%\weDownload Manager Pro\weDownload Manager Pro-buttonutil64.exe
Group: Malware file
Last Updated: July 24, 2022
%PROGRAMFILES%\weDownload Manager Pro\weDownload Manager Pro-bho.dll File name: weDownload Manager Pro-bho.dll
Size: 637.44 KB (637440 bytes)
MD5: 58d2fd86c09f6549429d70721078d708
Detection count: 14
File type: Dynamic link library
Mime Type: unknown/dll
Path: %PROGRAMFILES%\weDownload Manager Pro
Group: Malware file
Last Updated: February 17, 2014
%PROGRAMFILES%\weDownload\weDownload-chromeinstaller.exe File name: weDownload-chromeinstaller.exe
Size: 571.39 KB (571392 bytes)
MD5: 8b6a9c67cb4ad15150fd4381e3ea4d1b
Detection count: 5
File type: Executable File
Mime Type: unknown/exe
Path: %PROGRAMFILES%\weDownload
Group: Malware file
Last Updated: February 17, 2014
%PROGRAMFILES%\weDownload\weDownload-codedownloader.exe File name: weDownload-codedownloader.exe
Size: 591.87 KB (591872 bytes)
MD5: 6ce5d73f5ba8dd182012b255c2a5f1f4
Detection count: 5
File type: Executable File
Mime Type: unknown/exe
Path: %PROGRAMFILES%\weDownload
Group: Malware file
Last Updated: February 17, 2014
%PROGRAMFILES%\weDownload\weDownload-enabler.exe File name: weDownload-enabler.exe
Size: 408.06 KB (408064 bytes)
MD5: ad5f65efe6d5d6c7241ff29c6df64c96
Detection count: 5
File type: Executable File
Mime Type: unknown/exe
Path: %PROGRAMFILES%\weDownload
Group: Malware file
Last Updated: February 17, 2014
%PROGRAMFILES%\weDownload Manager Pro\weDownload Manager Pro-firefoxinstaller.exe File name: weDownload Manager Pro-firefoxinstaller.exe
Size: 907.77 KB (907776 bytes)
MD5: f38ac8fa28e7bbe27423956ec6b5eaf5
Detection count: 5
File type: Executable File
Mime Type: unknown/exe
Path: %PROGRAMFILES%\weDownload Manager Pro
Group: Malware file
Last Updated: February 17, 2014
%PROGRAMFILES%\weDownload Manager Pro\weDownload Manager Pro-updater.exe File name: weDownload Manager Pro-updater.exe
Size: 429.56 KB (429568 bytes)
MD5: dbc7c9f592255169175dfc5fbf088d3f
Detection count: 5
File type: Executable File
Mime Type: unknown/exe
Path: %PROGRAMFILES%\weDownload Manager Pro
Group: Malware file
Last Updated: February 17, 2014
%PROGRAMFILES%\The weDownload\The weDownload-chromeinstaller.exe File name: The weDownload-chromeinstaller.exe
Size: 1.03 MB (1032704 bytes)
MD5: 0cb6f8ddd7f7bfc102361d62381842af
Detection count: 5
File type: Executable File
Mime Type: unknown/exe
Path: %PROGRAMFILES%\The weDownload
Group: Malware file
Last Updated: February 17, 2014
%PROGRAMFILES%\The weDownload\The weDownload-codedownloader.exe File name: The weDownload-codedownloader.exe
Size: 631.29 KB (631296 bytes)
MD5: bf2946d0db5e607a50f35caffcb98993
Detection count: 5
File type: Executable File
Mime Type: unknown/exe
Path: %PROGRAMFILES%\The weDownload
Group: Malware file
Last Updated: February 17, 2014
%PROGRAMFILES%\The weDownload\The weDownload-enabler.exe File name: The weDownload-enabler.exe
Size: 454.65 KB (454656 bytes)
MD5: 23dd2e83bbaaa16cfef012356bceb461
Detection count: 5
File type: Executable File
Mime Type: unknown/exe
Path: %PROGRAMFILES%\The weDownload
Group: Malware file
Last Updated: February 17, 2014
%PROGRAMFILES%\The weDownload\The weDownload-firefoxinstaller.exe File name: The weDownload-firefoxinstaller.exe
Size: 993.28 KB (993280 bytes)
MD5: dcde2b71601a8f2fbb7001b924232ca7
Detection count: 5
File type: Executable File
Mime Type: unknown/exe
Path: %PROGRAMFILES%\The weDownload
Group: Malware file
Last Updated: February 17, 2014
%PROGRAMFILES%\The weDownload\The weDownload-updater.exe File name: The weDownload-updater.exe
Size: 452.6 KB (452608 bytes)
MD5: ba07762fc20a05400fb67fb90d2a7be6
Detection count: 5
File type: Executable File
Mime Type: unknown/exe
Path: %PROGRAMFILES%\The weDownload
Group: Malware file
Last Updated: February 17, 2014
%PROGRAMFILES(x86)%\The weDownload\The weDownload-validator.exe File name: The weDownload-validator.exe
Size: 2.01 MB (2019328 bytes)
MD5: 1f2bea10d1d58a0c08b6e2549d76d83f
Detection count: 5
File type: Executable File
Mime Type: unknown/exe
Path: %PROGRAMFILES(x86)%\The weDownload
Group: Malware file
Last Updated: February 17, 2014

More files

Registry Modifications

The following newly produced Registry Values are:

CLSID{11111111-1111-1111-1111-110411581120}{11111111-1111-1111-1111-110411901172}{11111111-1111-1111-1111-110411901174}{22222222-2222-2222-2222-220422582220}{22222222-2222-2222-2222-220422902272}{22222222-2222-2222-2222-220422902274}{44444444-4444-4444-4444-440444584420}{44444444-4444-4444-4444-440444904472}{44444444-4444-4444-4444-440444904474}{55555555-5555-5555-5555-550455585520}{55555555-5555-5555-5555-550455905572}{55555555-5555-5555-5555-550455905574}{66666666-6666-6666-6666-660466586620}{66666666-6666-6666-6666-660466906672}{66666666-6666-6666-6666-660466906674}HKEY..\..\..\..{RegistryKeys}Software\AppDataLow\Software\Crossrider\onBeforeNavigate\49072Software\AppDataLow\Software\Crossrider\onRequest\49072Software\AppDataLow\Software\The weDownloadSoftware\AppDataLow\Software\The weDownload ManagerSoftware\AppDataLow\Software\The weDownload\UpdateSoftware\AppDataLow\Software\weDownloadSOFTWARE\Classes\CrossriderApp0045820.BHOSOFTWARE\Classes\CrossriderApp0045820.BHO.1SOFTWARE\Classes\CrossriderApp0045820.SandboxSOFTWARE\Classes\CrossriderApp0045820.Sandbox.1SOFTWARE\Classes\CrossriderApp0049072.BHOSOFTWARE\Classes\CrossriderApp0049072.BHO.1SOFTWARE\Classes\CrossriderApp0049072.SandboxSOFTWARE\Classes\CrossriderApp0049072.Sandbox.1SOFTWARE\Classes\CrossriderApp0049074.BHOSOFTWARE\Classes\CrossriderApp0049074.BHO.1SOFTWARE\Classes\CrossriderApp0049074.SandboxSOFTWARE\Classes\CrossriderApp0049074.Sandbox.1Software\Classes\Local Settings\Software\Microsoft\Windows\CurrentVersion\AppContainer\Storage\windows_ie_ac_001\Software\The weDownloadSoftware\Classes\Local Settings\Software\Microsoft\Windows\CurrentVersion\AppContainer\Storage\windows_ie_ac_001\Software\The weDownload ManagerSoftware\InstalledBrowserExtensions\21501Software\InstalledBrowserExtensions\weDownloadSoftware\Microsoft\Internet Explorer\Approved Extensions\{11111111-1111-1111-1111-110411581120}Software\Microsoft\Internet Explorer\Approved Extensions\{11111111-1111-1111-1111-110411901172}Software\Microsoft\Internet Explorer\ApprovedExtensionsMigration\{11111111-1111-1111-1111-110411901174}SOFTWARE\Microsoft\Internet Explorer\Low Rights\ElevationPolicy\{08cb9b4e-1cca-4e21-a44b-cd4a7d7177ff}Software\Microsoft\Internet Explorer\Low Rights\ElevationPolicy\{0b89ac14-55d3-4267-afd6-0645a40d92b8}Software\Microsoft\Internet Explorer\Low Rights\ElevationPolicy\{3fc09e11-fdbc-4523-bc73-d5ede4c2203c}SOFTWARE\Microsoft\Internet Explorer\Low Rights\ElevationPolicy\{61d12012-d3af-42f1-b0f7-ed6feffa463d}Software\Microsoft\Internet Explorer\Low Rights\ElevationPolicy\{61e309e0-ddd1-4b8b-8280-83906a419e95}Software\Microsoft\Internet Explorer\Low Rights\ElevationPolicy\{909e7b95-0cf8-4846-a707-ba4843063839}Software\Microsoft\Internet Explorer\Low Rights\ElevationPolicy\{cc4fd57f-8174-4f55-9f24-0b4e330d2eb5}SOFTWARE\Microsoft\Internet Explorer\MAIN\FeatureControl\FEATURE_BROWSER_EMULATION\The weDownload-bg.exeSOFTWARE\Microsoft\Tracing\DownloadManager_RASAPI32SOFTWARE\Microsoft\Tracing\DownloadManager_RASMANCSSOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tree\The weDownload-codedownloaderSOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tree\The weDownload-enablerSOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tree\The weDownload-firefoxinstallerSOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tree\The weDownload-updaterSOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tree\weDownload-chromeinstallerSOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tree\weDownload-codedownloaderSOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tree\weDownload-enablerSOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tree\weDownload-firefoxinstallerSOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tree\weDownload-updaterSOFTWARE\Microsoft\Windows\CurrentVersion\explorer\Browser Helper Objects\{11111111-1111-1111-1111-110411581120}SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{11111111-1111-1111-1111-110411901172}Software\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{11111111-1111-1111-1111-110411901174}SOFTWARE\Microsoft\Windows\CurrentVersion\Ext\PreApproved\{11111111-1111-1111-1111-110411901174}Software\Microsoft\Windows\CurrentVersion\Ext\Settings\{11111111-1111-1111-1111-110411581120}Software\Microsoft\Windows\CurrentVersion\Ext\Settings\{11111111-1111-1111-1111-110411901172}Software\Microsoft\Windows\CurrentVersion\Ext\Stats\{11111111-1111-1111-1111-110411581120}Software\Microsoft\Windows\CurrentVersion\Ext\Stats\{11111111-1111-1111-1111-110411901172}SOFTWARE\Microsoft\Windows\CurrentVersion\Policies\Ext\CLSID\\{11111111-1111-1111-1111-110411901172}SOFTWARE\Microsoft\Windows\CurrentVersion\Policies\Ext\CLSID\{11111111-1111-1111-1111-110411901174}SOFTWARE\The weDownloadSOFTWARE\The weDownload ManagerSoftware\WeDlMngrSOFTWARE\weDownloadSoftware\weDownload LtdSOFTWARE\Wow6432Node\InstalledBrowserExtensions\21501SOFTWARE\Wow6432Node\Microsoft\Internet Explorer\Low Rights\ElevationPolicy\{08cb9b4e-1cca-4e21-a44b-cd4a7d7177ff}SOFTWARE\Wow6432Node\Microsoft\Internet Explorer\Low Rights\ElevationPolicy\{0b89ac14-55d3-4267-afd6-0645a40d92b8}SOFTWARE\Wow6432Node\Microsoft\Internet Explorer\Low Rights\ElevationPolicy\{3fc09e11-fdbc-4523-bc73-d5ede4c2203c}SOFTWARE\Wow6432Node\Microsoft\Internet Explorer\Low Rights\ElevationPolicy\{61d12012-d3af-42f1-b0f7-ed6feffa463d}SOFTWARE\Wow6432Node\Microsoft\Internet Explorer\Low Rights\ElevationPolicy\{61e309e0-ddd1-4b8b-8280-83906a419e95}SOFTWARE\Wow6432Node\Microsoft\Internet Explorer\Low Rights\ElevationPolicy\{909e7b95-0cf8-4846-a707-ba4843063839}SOFTWARE\Wow6432Node\Microsoft\Internet Explorer\Low Rights\ElevationPolicy\{cc4fd57f-8174-4f55-9f24-0b4e330d2eb5}SOFTWARE\Wow6432Node\Microsoft\Internet Explorer\MAIN\FeatureControl\FEATURE_BROWSER_EMULATION\The weDownload-bg.exeSOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\Ext\PreApproved\{11111111-1111-1111-1111-110411901174}SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\Policies\Ext\CLSID\{11111111-1111-1111-1111-110411901172}SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\Policies\Ext\CLSID\{11111111-1111-1111-1111-110411901174}SOFTWARE\Wow6432Node\The weDownloadSOFTWARE\Wow6432Node\The weDownload ManagerSOFTWARE\Wow6432Node\weDownloadSOFTWARE\Wow6432Node\weDownload LtdHKEY_LOCAL_MACHINE\Software\[APPLICATION]\Microsoft\Windows\CurrentVersion\Uninstall..{Uninstaller}The weDownloadThe weDownload ManagerweDownload

Additional Information

The following directories were created:
%APPDATA%\weDownload Ltd%PROGRAMFILES%\The weDownload%PROGRAMFILES%\The weDownload Manager%PROGRAMFILES%\weDownload%PROGRAMFILES(X86)%\weDownload%PROGRAMFILES(x86)%\The weDownload%PROGRAMFILES(x86)%\The weDownload Manager%USERPROFILE%\AppData\LocalLow\weDownload
Loading...