WeDownload Manager

WeDownload Manager Description

WeDownload Manager is a potentially unwanted program that targets all web browsers that are installed on the compromised PC. WeDownload Manager may trace the affected web user's Internet surfing activities, display annoying pop-up advertisements and result in irritating diversions to misleading advertisement websites. WeDownload Manager may make target computer users visit associated websites and display pop-up advertisements that contain sponsored links. WeDownload Manager does not ask an authorization of the PC user to access the affected PC. WeDownload Manager usually comes packed together with freeware and shareware applications that Internet user can download online. WeDownload Manager makes modifications to the corrupted PC that may additionally result in annoying browser diversions and slow downs of the PC.

Technical Information

File System Details

WeDownload Manager creates the following file(s):
# File Name Size MD5 Detection Count
1 %PROGRAMFILES%\The weDownload Manager\The weDownload Manager-chromeinstaller.exe 922,112 01887c74e5801d476a9c513cf03ea4a7 1,957
2 %PROGRAMFILES%\The weDownload\The weDownload-codedownloader.exe 524,800 5ba45a488e54a23a0de3b329862f9428 527
3 %PROGRAMFILES%\The weDownload\The weDownload-updater.exe 354,304 e57cf7a22d1b2ba360a4fcf9ef639532 523
4 %PROGRAMFILES%\The weDownload\The weDownload-enabler.exe 344,064 f522e0b8e1e961aedac49feb741d3f0d 502
5 %PROGRAMFILES%\The weDownload\The weDownload-firefoxinstaller.exe 886,784 982156fddfc998a58b356dd9e1457f86 478
6 %PROGRAMFILES%\The weDownload\The weDownload-chromeinstaller.exe 922,112 efbe2390e882d867d0646f0d0fa019c8 459
7 %PROGRAMFILES(x86)%\weDownload Manager Pro\weDownload Manager Pro-firefoxinstaller.exe 763,392 e9bbea9f255f2ff8edf35cf42ac3aa16 233
8 %PROGRAMFILES(x86)%\weDownload Manager\weDownload Manager-firefoxinstaller.exe 763,392 eeb477ccc0325cf36ef3dfeee4252fa3 232
9 %PROGRAMFILES%\The weDownload Manager\The weDownload Manager-firefoxinstaller.exe 932,352 c5acbca9bce48f850d37fcfc317734da 159
10 %PROGRAMFILES%\The weDownload Manager\The weDownload Manager-codedownloader.exe 553,984 64a52da2b81c2e6dd902d4bf10e3dbb1 146
11 %PROGRAMFILES(x86)%\weDownload Manager\weDownload Manager-updater.exe 346,112 94dbb76cdb8deacc97c5eeb2dd47aa40 106
12 %PROGRAMFILES(x86)%\weDownload Manager\weDownload Manager-codedownloader.exe 514,048 b38cf77ae343aee03bfce4ab5879fe91 104
13 %PROGRAMFILES(x86)%\weDownload Manager\weDownload Manager-enabler.exe 334,336 d8dcf91784b1e367d285361da1ce8087 104
14 %PROGRAMFILES%\weDownload Manager\weDownload Manager-bho.dll 636,928 afab25b7bd1e169fe3762c68c4e9d808 70
15 %PROGRAMFILES(x86)%\The weDownload\The weDownload-bho64.dll 870,400 e48fac65f468b29795843b4bea2d0b80 36
16 %PROGRAMFILES%\The weDownload Manager\The weDownload Manager-bho.dll 624,128 a27335c8213d093187d477aa4320117b 25
17 %PROGRAMFILES%\The weDownload Manager\The weDownload Manager-updater.exe 391,680 82f581455fbeb53145eddfdcb9a94a68 22
18 %PROGRAMFILES%\The weDownload Manager\The weDownload Manager-enabler.exe 411,136 7d48ca108465d1226b89eaccccb7be10 19
19 %PROGRAMFILES%\wedownload manager pro\wedownload manager pro-buttonutil.exe 330,752 3b8bda9702e69aba7d06e7f4a583499f 14
20 %PROGRAMFILES(x86)%\wedownload manager pro\wedownload manager pro-buttonutil64.exe 423,936 08fc5817f51dd5370f717c1f2d54d723 5
21 %PROGRAMFILES(x86)%\The weDownload Manager\The weDownload Manager-bho64.dll 870,400 bc7a2f3370ba36ccb8d8f841a8b52cf1 4
22 %PROGRAMFILES(x86)%\weDownload Manager Pro\weDownload Manager Pro-chromeinstaller.exe 573,440 71ac7af478afafb0fd1a39154262e373 2
23 %PROGRAMFILES(x86)%\The weDownload\The weDownload-validator.exe 2,019,328 1f2bea10d1d58a0c08b6e2549d76d83f 2
24 %PROGRAMFILES(x86)%\the wedownload\the wedownload-bg.exe 655,360 c9c625acd777e55fc5739e9a428b1dce 2
25 %PROGRAMFILES%\weDownload Manager\weDownload Manager-helper.exe 331,264 68a5fcbace644924314e69572fd3c473 1
26 %PROGRAMFILES(x86)%\the wedownload manager\the wedownload manager-bg.exe 622,592 9dfb01d938234ff33a91d926adaa511a 1
More files

Registry Details

WeDownload Manager creates the following registry entry or registry entries:
Uninstaller
The weDownload
The weDownload Manager
weDownload
Registry key
Software\AppDataLow\Software\Crossrider\onBeforeNavigate\49072
Software\AppDataLow\Software\Crossrider\onRequest\49072
Software\AppDataLow\Software\The weDownload
Software\AppDataLow\Software\The weDownload Manager
Software\AppDataLow\Software\The weDownload\Update
Software\AppDataLow\Software\weDownload
SOFTWARE\Classes\CrossriderApp0045820.BHO
SOFTWARE\Classes\CrossriderApp0045820.BHO.1
SOFTWARE\Classes\CrossriderApp0045820.Sandbox
SOFTWARE\Classes\CrossriderApp0045820.Sandbox.1
SOFTWARE\Classes\CrossriderApp0049072.BHO
SOFTWARE\Classes\CrossriderApp0049072.BHO.1
SOFTWARE\Classes\CrossriderApp0049072.Sandbox
SOFTWARE\Classes\CrossriderApp0049072.Sandbox.1
SOFTWARE\Classes\CrossriderApp0049074.BHO
SOFTWARE\Classes\CrossriderApp0049074.BHO.1
SOFTWARE\Classes\CrossriderApp0049074.Sandbox
SOFTWARE\Classes\CrossriderApp0049074.Sandbox.1
Software\Classes\Local Settings\Software\Microsoft\Windows\CurrentVersion\AppContainer\Storage\windows_ie_ac_001\Software\The weDownload
Software\Classes\Local Settings\Software\Microsoft\Windows\CurrentVersion\AppContainer\Storage\windows_ie_ac_001\Software\The weDownload Manager
Software\InstalledBrowserExtensions\21501
Software\InstalledBrowserExtensions\weDownload
Software\Microsoft\Internet Explorer\Approved Extensions\{11111111-1111-1111-1111-110411581120}
Software\Microsoft\Internet Explorer\Approved Extensions\{11111111-1111-1111-1111-110411901172}
Software\Microsoft\Internet Explorer\ApprovedExtensionsMigration\{11111111-1111-1111-1111-110411901174}
SOFTWARE\Microsoft\Internet Explorer\Low Rights\ElevationPolicy\{08cb9b4e-1cca-4e21-a44b-cd4a7d7177ff}
Software\Microsoft\Internet Explorer\Low Rights\ElevationPolicy\{0b89ac14-55d3-4267-afd6-0645a40d92b8}
Software\Microsoft\Internet Explorer\Low Rights\ElevationPolicy\{3fc09e11-fdbc-4523-bc73-d5ede4c2203c}
SOFTWARE\Microsoft\Internet Explorer\Low Rights\ElevationPolicy\{61d12012-d3af-42f1-b0f7-ed6feffa463d}
Software\Microsoft\Internet Explorer\Low Rights\ElevationPolicy\{61e309e0-ddd1-4b8b-8280-83906a419e95}
Software\Microsoft\Internet Explorer\Low Rights\ElevationPolicy\{909e7b95-0cf8-4846-a707-ba4843063839}
Software\Microsoft\Internet Explorer\Low Rights\ElevationPolicy\{cc4fd57f-8174-4f55-9f24-0b4e330d2eb5}
SOFTWARE\Microsoft\Internet Explorer\MAIN\FeatureControl\FEATURE_BROWSER_EMULATION\The weDownload-bg.exe
SOFTWARE\Microsoft\Tracing\DownloadManager_RASAPI32
SOFTWARE\Microsoft\Tracing\DownloadManager_RASMANCS
SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tree\The weDownload-codedownloader
SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tree\The weDownload-enabler
SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tree\The weDownload-firefoxinstaller
SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tree\The weDownload-updater
SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tree\weDownload-chromeinstaller
SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tree\weDownload-codedownloader
SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tree\weDownload-enabler
SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tree\weDownload-firefoxinstaller
SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tree\weDownload-updater
SOFTWARE\Microsoft\Windows\CurrentVersion\explorer\Browser Helper Objects\{11111111-1111-1111-1111-110411581120}
SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{11111111-1111-1111-1111-110411901172}
Software\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{11111111-1111-1111-1111-110411901174}
SOFTWARE\Microsoft\Windows\CurrentVersion\Ext\PreApproved\{11111111-1111-1111-1111-110411901174}
Software\Microsoft\Windows\CurrentVersion\Ext\Settings\{11111111-1111-1111-1111-110411581120}
Software\Microsoft\Windows\CurrentVersion\Ext\Settings\{11111111-1111-1111-1111-110411901172}
Software\Microsoft\Windows\CurrentVersion\Ext\Stats\{11111111-1111-1111-1111-110411581120}
Software\Microsoft\Windows\CurrentVersion\Ext\Stats\{11111111-1111-1111-1111-110411901172}
SOFTWARE\Microsoft\Windows\CurrentVersion\Policies\Ext\CLSID\\{11111111-1111-1111-1111-110411901172}
SOFTWARE\Microsoft\Windows\CurrentVersion\Policies\Ext\CLSID\{11111111-1111-1111-1111-110411901174}
SOFTWARE\The weDownload
SOFTWARE\The weDownload Manager
Software\WeDlMngr
SOFTWARE\weDownload
Software\weDownload Ltd
SOFTWARE\Wow6432Node\InstalledBrowserExtensions\21501
SOFTWARE\Wow6432Node\Microsoft\Internet Explorer\Low Rights\ElevationPolicy\{08cb9b4e-1cca-4e21-a44b-cd4a7d7177ff}
SOFTWARE\Wow6432Node\Microsoft\Internet Explorer\Low Rights\ElevationPolicy\{0b89ac14-55d3-4267-afd6-0645a40d92b8}
SOFTWARE\Wow6432Node\Microsoft\Internet Explorer\Low Rights\ElevationPolicy\{3fc09e11-fdbc-4523-bc73-d5ede4c2203c}
SOFTWARE\Wow6432Node\Microsoft\Internet Explorer\Low Rights\ElevationPolicy\{61d12012-d3af-42f1-b0f7-ed6feffa463d}
SOFTWARE\Wow6432Node\Microsoft\Internet Explorer\Low Rights\ElevationPolicy\{61e309e0-ddd1-4b8b-8280-83906a419e95}
SOFTWARE\Wow6432Node\Microsoft\Internet Explorer\Low Rights\ElevationPolicy\{909e7b95-0cf8-4846-a707-ba4843063839}
SOFTWARE\Wow6432Node\Microsoft\Internet Explorer\Low Rights\ElevationPolicy\{cc4fd57f-8174-4f55-9f24-0b4e330d2eb5}
SOFTWARE\Wow6432Node\Microsoft\Internet Explorer\MAIN\FeatureControl\FEATURE_BROWSER_EMULATION\The weDownload-bg.exe
SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\Ext\PreApproved\{11111111-1111-1111-1111-110411901174}
SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\Policies\Ext\CLSID\{11111111-1111-1111-1111-110411901172}
SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\Policies\Ext\CLSID\{11111111-1111-1111-1111-110411901174}
SOFTWARE\Wow6432Node\The weDownload
SOFTWARE\Wow6432Node\The weDownload Manager
SOFTWARE\Wow6432Node\weDownload
SOFTWARE\Wow6432Node\weDownload Ltd
CLSID
{11111111-1111-1111-1111-110411581120}
{11111111-1111-1111-1111-110411901172}
{11111111-1111-1111-1111-110411901174}
{22222222-2222-2222-2222-220422582220}
{22222222-2222-2222-2222-220422902272}
{22222222-2222-2222-2222-220422902274}
{44444444-4444-4444-4444-440444584420}
{44444444-4444-4444-4444-440444904472}
{44444444-4444-4444-4444-440444904474}
{55555555-5555-5555-5555-550455585520}
{55555555-5555-5555-5555-550455905572}
{55555555-5555-5555-5555-550455905574}
{66666666-6666-6666-6666-660466586620}
{66666666-6666-6666-6666-660466906672}
{66666666-6666-6666-6666-660466906674}
Directory
%APPDATA%\weDownload Ltd
%LocalAppData%\Google\Chrome\User Data\Default\databases\chrome-extension_fhhamfkcejhlnpojdpnjbmcfkpnadlpn_0
%LocalAppData%\Google\Chrome\User Data\Default\Extensions\fhhamfkcejhlnpojdpnjbmcfkpnadlpn
%LocalAppData%\Google\Chrome\User Data\Default\Local Extension Settings\fhhamfkcejhlnpojdpnjbmcfkpnadlpn
%PROGRAMFILES%\The weDownload
%PROGRAMFILES%\The weDownload Manager
%PROGRAMFILES%\weDownload
%PROGRAMFILES(x86)%\The weDownload
%PROGRAMFILES(x86)%\The weDownload Manager
%PROGRAMFILES(X86)%\weDownload
%USERPROFILE%\AppData\LocalLow\weDownload
File name without path
chrome-extension_fhhamfkcejhlnpojdpnjbmcfkpnadlpn_0.localstorage
chrome-extension_fhhamfkcejhlnpojdpnjbmcfkpnadlpn_0.localstorage-journal

Site Disclaimer

Enigmasoftware.com is not associated, affiliated, sponsored or owned by the malware creators or distributors mentioned on this article. This article should NOT be mistaken or confused in being associated in any way with the promotion or endorsement of malware. Our intent is to provide information that will educate computer users on how to detect, and ultimately remove, malware from their computer with the help of SpyHunter and/or manual removal instructions provided on this article.

This article is provided "as is" and to be used for educational information purposes only. By following any instructions on this article, you agree to be bound by the disclaimer. We make no guarantees that this article will help you completely remove the malware threats on your computer. Spyware changes regularly; therefore, it is difficult to fully clean an infected machine through manual means.

Leave a Reply

Please DO NOT use this comment system for support or billing questions. For SpyHunter technical support requests, please contact our technical support team directly by opening a customer support ticket via your SpyHunter. For billing issues, please refer to our "Billing Questions or Problems?" page. For general inquiries (complaints, legal, press, marketing, copyright), visit our "Inquiries and Feedback" page.