The weDownload Manager

The weDownload Manager

Known Toolbar

by weDownload Ltd

What is The weDownload Manager?

The weDownload Manager is software application developed by weDownload Ltd. It is most commonly found on computers running Windows 7 with nearly 55.17% of installations running this operating system. The weDownload Manager's installer is typically 9.00 MB in size and installs around 407 files. The most common release is 1.34.2.13 with 27.20% of all installations currently using this version.

The weDownload Manager is most popular in the United States with 63.52% of installations residing in this country.

The weDownload Manager adds 6 scheduled tasks to the Windows Task Scheduler launching the program at randomly scheduled times.

About The weDownload Manager?

WeDownload Manager is a software download distribution utility that facilitates the installation of various adware and toolbar offerings, including the Ominent Toolbar. The software is distributed using the Soft32 downloader and is commonly packaged with legitimate software products on distribution websites such as todownload.com, soft32.com, xtremedownload.com, free-downloads.us.com, and others.

Multiple virus scanners have detected malware in The weDownload Manager.

36cba358-e418-425b-9436-da3d2d9081fc-4.exe (MD5: c962db0aae4344d8a79329b396dda2c5) has been flagged by 44 scanners:
Scanner Software Result
Lavasoft Ad-Aware Trojan.Generic.11492923
Avira AntiVir Adware/CrossRider.A.17898
Antiy-AVL Trojan/Win32.TSGeneric
Baidu-International Adware.Win32.CrossRider.bAK
Bitdefender Trojan.Generic.11492923
Emsisoft Anti-Malware Trojan.Generic.11492923 (B)
ESET-NOD32 a variant of Win32/Toolbar.CrossRider.AK
Fortinet FortiGate Riskware/Toolbar_CrossRider
F-Secure Trojan.Generic.11492923
G Data Trojan.Generic.11492923
IKARUS anti.virus AdWare.Adload
K7 AntiVirus Trojan ( 0049c2a41 )
K7GW Trojan ( 0049c2a41 )
Malwarebytes PUP.Optional.weDownload.A
McAfee Artemis!C962DB0AAE43
McAfee-GW-Edition Artemis!C962DB0AAE43
MicroWorld-eScan Trojan.Generic.11492923
NANO AntiVirus Riskware.Win32.AdLoad.dcccgv
Panda Antivirus Trj/Genetic.gen
Sophos weDownload Manager
Symantec WS.Reputation.1
TrendMicro-HouseCall Suspicious_GEN.F47V0708
VIPRE Antivirus Crossrider (fs)
AVG Generic.D77
AVware Crossrider (fs)
CAT-QuickHeal AdWare.NSIS.r5 (Not a Virus)
Dr.Web Trojan.Crossrider.28616
Kaspersky not-a-virus:AdWare.NSIS.Adwapper.ai
Kingsoft AntiVirus Win32.Troj.Generic.a.(kcloud)
Rising Antivirus PE:Trojan.Win32.Generic.1733098B!389220747
Vba32 AntiVirus AdWare.Adwapper
Zillya Trojan.GoogUpdate.Win32.958
Comodo Security ApplicUnwnt
F-Prot W32/A-eb9ef301!Eldorado
AhnLab-V3 PUP/Win32.CrossRider
avast! Win32:Adware-gen [Adw]
Avira Adware/CrossRider.pq
Qihoo-360 HEUR/Malware.QVM10.Gen
Tencent Nsis.Adware.Adwapper.Edxj
Jiangmin Trojan.NSIS.GoogUpdate.br
SUPERAntiSpyware Adware.Crossrider/Variant
Bkav FE W32.CrossRider.Trojan
Agnitum Outpost PUA.Toolbar.CrossRider!
Trend Micro TROJ_MOSERAN.BMC
36cba358-e418-425b-9436-da3d2d9081fc-2.exe (MD5: 23a199f47a2803d225e1aa9d0c7265ce) has been flagged by 43 scanners:
Scanner Software Result
Lavasoft Ad-Aware Trojan.Generic.11493082
Avira AntiVir Adware/CrossRider.A.17820
Baidu-International Adware.Win32.CrossRider.BAJ
Bitdefender Trojan.Generic.11493082
Emsisoft Anti-Malware Trojan.Generic.11493082 (B)
ESET-NOD32 a variant of Win32/Toolbar.CrossRider.AJ
Fortinet FortiGate Riskware/Toolbar_CrossRider
F-Prot W32/A-eb9ef301!Eldorado
G Data Trojan.Generic.11493082
IKARUS anti.virus AdWare.Adload
K7 AntiVirus Trojan ( 0049bf0b1 )
K7GW Trojan ( 0049bf0b1 )
Malwarebytes PUP.Optional.weDownload.A
McAfee Artemis!23A199F47A28
MicroWorld-eScan Trojan.Generic.11493082
NANO AntiVirus Riskware.Win32.AdLoad.dcccgn
Rising Antivirus PE:Malware.Obscure!1.9C59
Sophos weDownload Manager
TrendMicro-HouseCall Suspicious_GEN.F47V0708
VIPRE Antivirus Crossrider (fs)
Zillya Adware.AdLoad.Win32.145
AVG Generic.16F
AVware Crossrider (fs)
Dr.Web Trojan.Crossrider.27022
F-Secure Gen:Variant.Adware.Kazy.374062
Kingsoft AntiVirus Win32.Troj.NSIS.br.(kcloud)
McAfee-GW-Edition Artemis!42AA1E814AAD
Panda Antivirus Trj/Genetic.gen
AhnLab-V3 PUP/Win32.CrossRider
Comodo Security ApplicUnwnt
Qihoo-360 Win32/Virus.Adware.ab1
Antiy-AVL GrayWare[AdWare:not-a-virus]/Win32.AdLoad
Avira Adware/CrossRider.pq
Kaspersky not-a-virus:AdWare.NSIS.Adwapper.ai
Symantec WS.Reputation.1
avast! Win32:Adware-gen [Adw]
Tencent Nsis.Trojan.Googupdate.Hvja
Vba32 AntiVirus Trojan.GoogUpdate
Jiangmin Trojan.NSIS.GoogUpdate.br
SUPERAntiSpyware Adware.Crossrider/Variant
Bkav FE W32.CrossRider.Trojan
Agnitum Outpost PUA.Toolbar.CrossRider!
Trend Micro TROJ_MOSERAN.BMC
36cba358-e418-425b-9436-da3d2d9081fc-11.exe (MD5: f5ced9cc2796ee9c23dec14034fbe333) has been flagged by 43 scanners:
Scanner Software Result
Lavasoft Ad-Aware Trojan.Generic.11481131
Avira AntiVir Adware/CrossRider.A.17803
Antiy-AVL GrayWare[AdWare:not-a-virus]/Win32.AdLoad
Baidu-International Adware.Win32.CrossRider.BAK
Bitdefender Trojan.Generic.11481131
Emsisoft Anti-Malware Trojan.Generic.11481131 (B)
ESET-NOD32 a variant of Win32/Toolbar.CrossRider.AK
Fortinet FortiGate Riskware/Toolbar_CrossRider
F-Secure Trojan.Generic.11481131
G Data Trojan.Generic.11481131
IKARUS anti.virus AdWare.Adload
K7 AntiVirus Trojan ( 0049c2a41 )
K7GW Trojan ( 0049c2a41 )
Malwarebytes PUP.Optional.weDownload.A
MicroWorld-eScan Trojan.Generic.11481131
NANO AntiVirus Riskware.Win32.AdLoad.dcbzfn
Panda Antivirus Trj/Genetic.gen
Sophos weDownload Manager
TrendMicro-HouseCall Suspicious_GEN.F47V0708
VIPRE Antivirus Crossrider (fs)
Zillya Adware.AdLoad.Win32.146
AhnLab-V3 PUP/Win32.CrossRider
AVG Generic.D77
Avira Adware/CrossRider.pq
AVware Crossrider (fs)
Dr.Web Trojan.Crossrider.33024
Kaspersky not-a-virus:AdWare.NSIS.Adwapper.ai
Qihoo-360 Win32/Virus.Adware.970
Rising Antivirus PE:Malware.Obscure!1.9C59
Symantec WS.Reputation.1
avast! Win32:Adware-gen [Adw]
McAfee Artemis!628509A3A09B
McAfee-GW-Edition Artemis!628509A3A09B
Kingsoft AntiVirus Win32.Troj.Generic.a.(kcloud)
Tencent Nsis.Trojan.Googupdate.Hvja
Vba32 AntiVirus Trojan.GoogUpdate
Comodo Security ApplicUnwnt
F-Prot W32/A-b38b90e7!Eldorado
Jiangmin Trojan.NSIS.GoogUpdate.br
SUPERAntiSpyware Adware.Crossrider/Variant
Bkav FE W32.CrossRider.Trojan
Agnitum Outpost PUA.Toolbar.CrossRider!
Trend Micro TROJ_MOSERAN.BMC
2edc0289-cc77-43d7-96a7-b05654baac3c-7.exe (MD5: b13418f26b6e71870ca997aaa2c59003) has been flagged by 40 scanners:
Scanner Software Result
AVG Generic.D77
Avira Adware/CrossRider.pq
AVware Crossrider (fs)
Dr.Web Trojan.Crossrider.31451
ESET-NOD32 a variant of Win32/Toolbar.CrossRider.AM
Fortinet FortiGate Adware/Adwapper
G Data Win32.Adware.Crossrider.M
IKARUS anti.virus Trojan.GoogUpdate
Kaspersky not-a-virus:AdWare.NSIS.Adwapper.ai
Kingsoft AntiVirus Win32.Troj.Generic.a.(kcloud)
Malwarebytes PUP.Optional.weDownload.A
NANO AntiVirus Riskware.Win32.Crossrider.devuka
Panda Antivirus Trj/Genetic.gen
Qihoo-360 HEUR/Malware.QVM10.Gen
Sophos weDownload Manager
Tencent Nsis.Adware.Adwapper.Pbyi
VIPRE Antivirus Crossrider (fs)
McAfee Artemis!C0481281D3F5
McAfee-GW-Edition Artemis
AhnLab-V3 PUP/Win32.CrossRider
K7 AntiVirus Adware ( 004a970a1 )
K7GW Adware ( 004a970a1 )
avast! Win32:Crossrider-N [PUP]
Baidu-International Trojan.Win32.GoogUpdate.AlQp
F-Prot W32/A-04c00d5a!Eldorado
TrendMicro-HouseCall Suspicious_GEN.F47V0809
Lavasoft Ad-Aware Gen:Variant.Adware.Kazy.374062
Bitdefender Gen:Variant.Adware.Kazy.374062
Emsisoft Anti-Malware Gen:Variant.Adware.Kazy.374062 (B)
F-Secure Gen:Variant.Adware.Kazy.374062
MicroWorld-eScan Gen:Variant.Adware.Kazy.374062
Rising Antivirus PE:Malware.Obscure!1.9C59
Antiy-AVL GrayWare[AdWare:not-a-virus]/NSIS.Adwapper
Zillya Trojan.GoogUpdate.Win32.1952
Avira AntiVir ADWARE/CrossRider.Gen2
Symantec Adware.Crossid!gen1
SUPERAntiSpyware Adware.Crossrider/Variant
Bkav FE W32.CrossRider.Trojan
Agnitum Outpost PUA.Toolbar.CrossRider!
Trend Micro TROJ_MOSERAN.BMC
2edc0289-cc77-43d7-96a7-b05654baac3c-6.exe (MD5: cb3c4477f6aa2333d801987a47af5221) has been flagged by 40 scanners:
Scanner Software Result
AVG Generic.D77
Avira Adware/CrossRider.pq
AVware Crossrider (fs)
Dr.Web Trojan.Crossrider.31452
ESET-NOD32 a variant of Win32/Toolbar.CrossRider.AP
G Data Win32.Adware.Crossrider.M
IKARUS anti.virus PUA.PlusHD
Kaspersky not-a-virus:AdWare.NSIS.Adwapper.ai
Kingsoft AntiVirus Win32.Troj.Generic.a.(kcloud)
Malwarebytes PUP.Optional.weDownload.A
McAfee Artemis!CB3C4477F6AA
McAfee-GW-Edition BehavesLike.Win32.BadFile.th
Panda Antivirus Trj/Chgt.F
Qihoo-360 Win32/Virus.Adware.970
Sophos Generic PUA EA
Tencent Nsis.Adware.Adwapper.Syrs
VIPRE Antivirus Crossrider (fs)
avast! Win32:Crossrider-N [PUP]
Baidu-International Trojan.Win32.GoogUpdate.AlQp
Fortinet FortiGate W32/GoogUpdate.AE!tr
F-Prot W32/A-04c00d5a!Eldorado
TrendMicro-HouseCall Suspicious_GEN.F47V0809
Lavasoft Ad-Aware Gen:Variant.Adware.Kazy.374062
Bitdefender Gen:Variant.Adware.Kazy.374062
Emsisoft Anti-Malware Gen:Variant.Adware.Kazy.374062 (B)
F-Secure Gen:Variant.Adware.Kazy.374062
MicroWorld-eScan Gen:Variant.Adware.Kazy.374062
Rising Antivirus PE:Malware.Obscure!1.9C59
AhnLab-V3 PUP/Win32.CrossRider
Antiy-AVL GrayWare[AdWare:not-a-virus]/NSIS.Adwapper
NANO AntiVirus Trojan.Win32.GoogUpdate.deofza
K7 AntiVirus Adware ( 004a90bb1 )
K7GW Adware ( 004a90bb1 )
Zillya Trojan.GoogUpdate.Win32.1952
Avira AntiVir ADWARE/CrossRider.Gen2
Symantec Adware.Crossid!gen1
SUPERAntiSpyware Adware.Crossrider/Variant
Bkav FE W32.CrossRider.Trojan
Agnitum Outpost PUA.Toolbar.CrossRider!
Trend Micro TROJ_MOSERAN.BMC

Software Behaviors

Scheduled tasks:
  • b9a50c40-f2cc-420c-be6f-593440d8deaa-6.exe is scheduled as a task named '731b28ed-138e-45a5-af8b-7ef590e61293-6'.
  • The weDownload Manager-codedownloader.exe is scheduled as a task named 'ebed045b-11c2-47a7-bae0-1f07ff30e3c0-7'.
  • ebed045b-11c2-47a7-bae0-1f07ff30e3c0-6.exe is scheduled as a task named 'temp_ebed045b-11c2-47a7-bae0-1f07ff30e3c0-6'.
  • ebed045b-11c2-47a7-bae0-1f07ff30e3c0-2.exe is scheduled as a task named 'temp_ebed045b-11c2-47a7-bae0-1f07ff30e3c0-2'.
  • bc39018e-d2de-4d68-aa32-0afacbc16f5f-2.exe is scheduled as a task named 'temp_bc39018e-d2de-4d68-aa32-0afacbc16f5f-2'.
  • 03091666-40b5-44af-b8b1-7438214ece0b-4.exe is scheduled as a task named '03091666-40b5-44af-b8b1-7438214ece0b-4'.

Startup Entries

Startup tasks:
  • b9a50c40-f2cc-420c-be6f-593440d8deaa-6.exe is automatically launched at startup through a scheduled task named 5d2076bc-d559-4c68-aca0-29a2e5982b96-7.
  • The weDownload Manager-nova.exe is automatically launched at startup through a scheduled task named 09d2f095-b00b-4e2a-8f47-83a824a7126a-7.
  • The weDownload Manager-novainstaller.exe is automatically launched at startup through a scheduled task named 1fb50b06-6845-4d15-b2d8-32c25ced1291-6.
  • 1fb50b06-6845-4d15-b2d8-32c25ced1291-11.exe is automatically launched at startup through a scheduled task named 1fb50b06-6845-4d15-b2d8-32c25ced1291-3.
  • 2e18c836-5212-44f2-b4dd-c1ea360752fb-7.exe is automatically launched at startup through a scheduled task named 2e18c836-5212-44f2-b4dd-c1ea360752fb-1.
  • 2e18c836-5212-44f2-b4dd-c1ea360752fb-5.exe is automatically launched at startup through a scheduled task named 2e18c836-5212-44f2-b4dd-c1ea360752fb-5_user.

Software Details

URL:
https://www.wedownload.com
Support:
–
Installation path:
C:\Program Files\the wedownload manager
Uninstaller:
C:\Program Files\The weDownload Manager\Uninstall.exe /fromcontrolpanel=1
Size:
9.00 MB
Language:
English

The weDownload Manager Executable Details

Primary executable:
utils.exe
Name:
The weDownload Manager
Path:
C:\Program Files\the wedownload manager\utils.exe
MD5:
–
SHA-1:
–
SHA-256:
–
Files installed by The weDownload Manager
File Type Filename MD5
EXE
ab91a7350a5fddcdf0a7b0c60e8e4e71
EXE
a0bdc8051a740904d9e5f24d697f6875
EXE
c962db0aae4344d8a79329b396dda2c5
EXE
23a199f47a2803d225e1aa9d0c7265ce
EXE
f5ced9cc2796ee9c23dec14034fbe333
EXE
b13418f26b6e71870ca997aaa2c59003
EXE
e0820862fc4f213422a666fd73fade3e
EXE
cb3c4477f6aa2333d801987a47af5221
EXE
8a1c3c363ae5fafee3820b5664c634a1
EXE
1c3d70d3215574149a3c88e7b91edcdc