WeDownload Manager

WeDownload Manager Description

WeDownload Manager is a potentially unwanted program that targets all web browsers that are installed on the compromised PC. WeDownload Manager may trace the affected web user's Internet surfing activities, display annoying pop-up advertisements and result in irritating diversions to misleading advertisement websites. WeDownload Manager may make target computer users visit associated websites and display pop-up advertisements that contain sponsored links. WeDownload Manager does not ask an authorization of the PC user to access the affected PC. WeDownload Manager usually comes packed together with freeware and shareware applications that Internet user can download online. WeDownload Manager makes modifications to the corrupted PC that may additionally result in annoying browser diversions and slow downs of the PC.

Infected with WeDownload Manager? Scan Your PC for Free

Download SpyHunter’s Spyware Scanner
to Detect WeDownload Manager

Security Doesn't Let You Download SpyHunter or Access the Internet?


Solutions: Your computer may have malware hiding in memory that prevents any program, including SpyHunter, from executing on your computer. Follow to download SpyHunter and gain access to the Internet:
  • Use an alternative browser. Malware may disable your browser. If you're using IE, for example, and having problems downloading SpyHunter, you should open Firefox, Chrome or Safari browser instead.
  • Use a removable media. Download SpyHunter on another clean computer, burn it to a USB flash drive, DVD/CD, or any preferred removable media, then install it on your infected computer and run SpyHunter's malware scanner.
  • Start Windows in Safe Mode. If you can not access your Window's desktop, reboot your computer in 'Safe Mode with Networking' and install SpyHunter in Safe Mode.
  • IE Users: Disable proxy server for Internet Explorer to browse the web with Internet Explorer or update your anti-spyware program. Malware modifies your Windows settings to use a proxy server to prevent you from browsing the web with IE.

If you still can't install SpyHunter? View other possible causes of installation issues.

Technical Information

Infection Statistics


Our MalwareTracker shows malware activity across the world. Explore real-time data of WeDownload Manager outbreaks and other threats from global to local level.

File System Details

WeDownload Manager creates the following file(s):
# File Name Size MD5 Detection Count
1 %PROGRAMFILES%\weDownload Manager Pro\weDownload Manager Pro-firefoxinstaller.exe 722,944 813670753c5665902c98420a8668397c 915
2 %PROGRAMFILES(x86)%\weDownload Manager Pro\weDownload Manager Pro-codedownloader.exe 487,424 a89d4b41f88b92ba5e3f52cb844e1f70 622
3 %PROGRAMFILES(x86)%\weDownload Manager Pro\weDownload Manager Pro-enabler.exe 346,624 8040246054b0b73e7eb785962114212f 621
4 %PROGRAMFILES(x86)%\weDownload Manager\weDownload Manager-enabler.exe 343,552 228197b24d39f7984c2663b2dc9ff0fd 5,606
5 %PROGRAMFILES(x86)%\weDownload Manager\weDownload Manager-chromeinstaller.exe 484,864 c929fca29d2be842b339eeb5374ad170 5,124
6 %PROGRAMFILES%\weDownload\weDownload-enabler.exe 342,528 9ac98c553e00fe7fe0b941def1691cba 2,808
7 %PROGRAMFILES%\weDownload\weDownload-codedownloader.exe 476,672 97da8e17c0ff8c759c8c61c3b29dab50 2,724
8 %PROGRAMFILES(x86)%\weDownload\weDownload-updater.exe 363,520 994d74e080febf782c91d5dbc275a304 2,384
9 %PROGRAMFILES(x86)%\weDownload Manager\weDownload Manager-bho64.dll 940,544 e2c3b07f7fd8c705d09db572f93c0288 2,352
10 %PROGRAMFILES%\weDownload\weDownload-chromeinstaller.exe 460,800 7a4feab8ce4d6808188b6ab04ebccd3b 2,066
11 %PROGRAMFILES%\The weDownload Manager\The weDownload Manager-enabler.exe 344,064 840e73e53f08561d024e3b0a547a1293 1,946
12 %PROGRAMFILES(x86)%\weDownload Manager\weDownload Manager-codedownloader.exe 487,424 7cbf75a8af564eb5ebb85ffdc798e997 1,933
13 %PROGRAMFILES%\The weDownload Manager\The weDownload Manager-codedownloader.exe 524,800 dff87e5a27676c0e1bec085e63f3f8b3 1,919
14 %PROGRAMFILES%\weDownload Manager\weDownload Manager-bho.dll 598,528 9dd119cef72aa46acaaf4b360a5d45df 1,308
15 %PROGRAMFILES(x86)%\weDownload Manager Pro\weDownload Manager Pro-chromeinstaller.exe 484,864 879b3ef7d13865d1aa0fbc879cfcde93 1,051

More files

Registry Details

WeDownload Manager creates the following registry entry or registry entries:
HKEY_LOCAL_MACHINE\Software\[APPLICATION]\Microsoft\Windows\CurrentVersion\Uninstall..{Uninstaller}
The weDownload
The weDownload Manager
HKEY..\..\..\..{RegistryKeys}
SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\explorer\Browser Helper Objects\{11111111-1111-1111-1111-110411581120}
SOFTWARE\Wow6432Node\Microsoft\Internet Explorer\Low Rights\ElevationPolicy\{cc4fd57f-8174-4f55-9f24-0b4e330d2eb5}
SOFTWARE\Wow6432Node\Microsoft\Internet Explorer\Low Rights\ElevationPolicy\{909e7b95-0cf8-4846-a707-ba4843063839}
SOFTWARE\Wow6432Node\Microsoft\Internet Explorer\Low Rights\ElevationPolicy\{61e309e0-ddd1-4b8b-8280-83906a419e95}
SOFTWARE\Wow6432Node\Microsoft\Internet Explorer\Low Rights\ElevationPolicy\{3fc09e11-fdbc-4523-bc73-d5ede4c2203c}
SOFTWARE\Wow6432Node\Microsoft\Internet Explorer\Low Rights\ElevationPolicy\{0b89ac14-55d3-4267-afd6-0645a40d92b8}
SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tree\weDownload-updater
SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tree\weDownload-chromeinstaller
SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tasks\{505D68FE-DD60-40C5-B6E8-7C331FE8D429}
SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tasks\{0CCF4FD2-29CD-4F8A-8637-878EE7144297}
SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tasks\{0BB5DB57-92AC-4045-B615-60D10E35F178}
SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tasks\{09A03EBD-4E28-48CB-8217-913A35888FBE}
SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tasks\{001BFCEE-FDD6-4163-AB6D-3FAEAE05CA9F}
SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Logon\{505D68FE-DD60-40C5-B6E8-7C331FE8D429}
SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Logon\{0CCF4FD2-29CD-4F8A-8637-878EE7144297}
SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Logon\{001BFCEE-FDD6-4163-AB6D-3FAEAE05CA9F}
Software\Microsoft\Windows\CurrentVersion\Ext\Stats\{11111111-1111-1111-1111-110411581120}
Software\Microsoft\Windows\CurrentVersion\Ext\Settings\{11111111-1111-1111-1111-110411581120}
Software\Microsoft\Internet Explorer\Low Rights\ElevationPolicy\{D6EBE8E1-E998-4868-9F17-93B89EA3370}
Software\Microsoft\Internet Explorer\Low Rights\ElevationPolicy\{D36CE1D9-FB79-4C9C-B32F-E87CCDAA97DA}
Software\Microsoft\Internet Explorer\Low Rights\ElevationPolicy\{cc4fd57f-8174-4f55-9f24-0b4e330d2eb5}
Software\Microsoft\Internet Explorer\Low Rights\ElevationPolicy\{C13AF94A-CBDA-4E16-A537-F87E034B2B2}
Software\Microsoft\Internet Explorer\Low Rights\ElevationPolicy\{909e7b95-0cf8-4846-a707-ba4843063839}
Software\Microsoft\Internet Explorer\Low Rights\ElevationPolicy\{173AC77D-5D8F-4DD5-96E7-FFA2D1B6CB68}
Software\Microsoft\Internet Explorer\Low Rights\ElevationPolicy\{0b89ac14-55d3-4267-afd6-0645a40d92b8}
SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\Uninstall\weDownload
Local Settings\Software\Microsoft\Windows\CurrentVersion\AppContainer\Storage\windows_ie_ac_001\Software\weDownload
SOFTWARE\Microsoft\Tracing\DownloadManager_RASMANCS
SOFTWARE\Microsoft\Tracing\DownloadManager_RASAPI32
SOFTWARE\Classes\CrossriderApp0045820.Sandbox.1
SOFTWARE\Classes\CrossriderApp0045820.Sandbox
CrossriderApp0045820.Sandbox.1
CrossriderApp0045820.Sandbox
CrossriderApp0045820.BHO.1
CrossriderApp0045820.BHO
Software\InstalledBrowserExtensions\weDownload
Software\AppDataLow\Software\weDownload
Software\WeDlMngr
SOFTWARE\weDownload
Software\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{11111111-1111-1111-1111-110411901174}
SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\Policies\Ext\CLSID, value: {11111111-1111-1111-1111-110411901172}
SOFTWARE\Microsoft\Windows\CurrentVersion\Policies\Ext\CLSID\, value: {11111111-1111-1111-1111-110411901172}
Software\Microsoft\Internet Explorer\Approved Extensions, value: {11111111-1111-1111-1111-110411901172}
SOFTWARE\The weDownload
SOFTWARE\Wow6432Node\Microsoft\Internet Explorer\Low Rights\ElevationPolicy\{cee7aa14-1e25-478f-b7cf-1e3996a492f5}
SOFTWARE\Wow6432Node\Microsoft\Internet Explorer\Low Rights\ElevationPolicy\{05b276ea-b7a3-42dc-b13a-e2c7ff1528cf}
SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tree\The weDownload-updater
SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tree\The weDownload-firefoxinstaller
SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tree\The weDownload-enabler
SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tree\The weDownload-codedownloader
SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{11111111-1111-1111-1111-110411901172}
SOFTWARE\Classes\CrossriderApp0049072.BHO
Software\weDownload Ltd
Software\Microsoft\Internet Explorer\Low Rights\ElevationPolicy\{CFD0B20E-F05D-44E2-BB59-93CE9484B31}
Software\Microsoft\Internet Explorer\Low Rights\ElevationPolicy\{cee7aa14-1e25-478f-b7cf-1e3996a492f5}
Software\Microsoft\Internet Explorer\Low Rights\ElevationPolicy\{A679DBFD-A346-41E5-AF17-B3FFE8DAB281}
Software\Microsoft\Internet Explorer\Low Rights\ElevationPolicy\{8ACB51EA-B593-46F9-ACB9-9DC82EB3ED37}
Software\Microsoft\Internet Explorer\Low Rights\ElevationPolicy\{572A1C2A-F61F-42BA-A662-9027712CC3C1}
Local Settings\Software\Microsoft\Windows\CurrentVersion\AppContainer\Storage\windows_ie_ac_001\Software\The weDownload
CrossriderApp0049072.Sandbox.1
CrossriderApp0049072.Sandbox
CrossriderApp0049072.BHO.1
CrossriderApp0049072.BHO
Software\AppDataLow\Software\Crossrider\onRequest, value: 49072
Software\AppDataLow\Software\Crossrider\onBeforeNavigate, value: 49072
Software\Microsoft\Windows\CurrentVersion\Ext\Stats\{11111111-1111-1111-1111-110411901172}
Software\Microsoft\Windows\CurrentVersion\Ext\Settings\{11111111-1111-1111-1111-110411901172}
Software\Microsoft\Internet Explorer\Low Rights\ElevationPolicy\{D5ED6EAF-4065-43F3-9DA3-3522ADC3CF}
Software\Microsoft\Internet Explorer\Low Rights\ElevationPolicy\{53CA519B-E1AE-47A6-B198-9B8DF059EF84}
Software\Microsoft\Internet Explorer\Low Rights\ElevationPolicy\{45EFA2A9-2398-4EE0-B7BB-7070B0662AC1}
Software\Microsoft\Internet Explorer\Low Rights\ElevationPolicy\{2A546669-791D-408B-98FA-58DB8C8E7D84}
SOFTWARE\The weDownload Manager
SOFTWARE\Microsoft\Windows\CurrentVersion\Ext\PreApproved\{11111111-1111-1111-1111-110411901174}
SOFTWARE\Microsoft\Internet Explorer\Low Rights\ElevationPolicy\{08cb9b4e-1cca-4e21-a44b-cd4a7d7177ff}
SOFTWARE\Microsoft\Internet Explorer\Low Rights\ElevationPolicy\{61d12012-d3af-42f1-b0f7-ed6feffa463d}
SOFTWARE\Wow6432Node\The weDownload Manager
SOFTWARE\Wow6432Node\Microsoft\Internet Explorer\Low Rights\ElevationPolicy\{61d12012-d3af-42f1-b0f7-ed6feffa463d}
SOFTWARE\Wow6432Node\InstalledBrowserExtensions\21501
SOFTWARE\Microsoft\Windows\CurrentVersion\Policies\Ext\CLSID, value: {11111111-1111-1111-1111-110411901174}
SOFTWARE\Classes\CrossriderApp0049074.Sandbox
SOFTWARE\Classes\CrossriderApp0049074.Sandbox.1
SOFTWARE\Classes\CrossriderApp0049074.BHO.1
SOFTWARE\Classes\CrossriderApp0049074.BHO
Software\Microsoft\Internet Explorer\Low Rights\ElevationPolicy\{95D103C8-44-409A-BBBB-CA8D75D6C78D}
Software\Microsoft\Internet Explorer\Low Rights\ElevationPolicy\{61d12012-d3af-42f1-b0f7-ed6feffa463d}
Software\Microsoft\Internet Explorer\Low Rights\ElevationPolicy\{611E0B20-8793-4066-9256-368428D49F26}
Software\Microsoft\Internet Explorer\Low Rights\ElevationPolicy\{4295812A-10EC-4480-A982-8AE8D1D2D43E}
Software\Microsoft\Internet Explorer\Low Rights\ElevationPolicy\{16BE2A1C-2351-4092-9DF6-45386EA29FC0}
Software\Microsoft\Internet Explorer\Low Rights\ElevationPolicy\{156B9B44-6203-4AF7-BD34-531E8F397A8C}
Software\Microsoft\Internet Explorer\Low Rights\ElevationPolicy\{08cb9b4e-1cca-4e21-a44b-cd4a7d7177ff}
CrossriderApp0049074.BHO
CrossriderApp0049074.BHO.1
CrossriderApp0049074.Sandbox
CrossriderApp0049074.Sandbox.1
Local Settings\Software\Microsoft\Windows\CurrentVersion\AppContainer\Storage\windows_ie_ac_001\Software\The weDownload Manager
Software\Classes\Local Settings\Software\Microsoft\Windows\CurrentVersion\AppContainer\Storage\windows_ie_ac_001\Software\The weDownload Manager
The following CLSID's were found:
HKEY..\..\{CLSID Path}
{11111111-1111-1111-1111-110411581120}
{11111111-1111-1111-1111-110411901172}
{11111111-1111-1111-1111-110411901174}
{22222222-2222-2222-2222-220422902272}
{22222222-2222-2222-2222-220422902274}
{44444444-4444-4444-4444-440444584420}
{44444444-4444-4444-4444-440444904472}
{44444444-4444-4444-4444-440444904474}
{55555555-5555-5555-5555-550455905572}
{55555555-5555-5555-5555-550455905574}
{66666666-6666-6666-6666-660466586620}
{66666666-6666-6666-6666-660466906672}
{66666666-6666-6666-6666-660466906674}

Site Disclaimer

Leave a Reply

IMPORTANT! To be able to proceed, you need to solve the following simple math.
Please leave these two fields as-is:
What is 15 + 4 ?