The weDownload Manager

The weDownload Manager

Known Toolbar

by weDownload Ltd

What is The weDownload Manager?

The weDownload Manager is software application developed by weDownload Ltd. It is most commonly found on computers running Windows 7 with nearly 55.17% of installations running this operating system. The weDownload Manager's installer is typically 9.00 MB in size and installs around 407 files. The most common release is 1.34.2.13 with 27.20% of all installations currently using this version.

The weDownload Manager is most popular in the United States with 63.52% of installations residing in this country.

The weDownload Manager adds 6 scheduled tasks to the Windows Task Scheduler launching the program at randomly scheduled times.

About The weDownload Manager?

WeDownload Manager is a software download distribution utility that facilitates the installation of various adware and toolbar offerings, including the Ominent Toolbar. The software is distributed using the Soft32 downloader and is commonly packaged with legitimate software products on distribution websites such as todownload.com, soft32.com, xtremedownload.com, free-downloads.us.com, and others.

Multiple virus scanners have detected malware in The weDownload Manager.

36cba358-e418-425b-9436-da3d2d9081fc-4.exe (MD5: c962db0aae4344d8a79329b396dda2c5) has been flagged by 44 scanners:
Scanner Software Result
Lavasoft Ad-Aware Trojan.Generic.11492923
Avira AntiVir Adware/CrossRider.A.17898
Antiy-AVL Trojan/Win32.TSGeneric
Baidu-International Adware.Win32.CrossRider.bAK
Bitdefender Trojan.Generic.11492923
Emsisoft Anti-Malware Trojan.Generic.11492923 (B)
ESET-NOD32 a variant of Win32/Toolbar.CrossRider.AK
Fortinet FortiGate Riskware/Toolbar_CrossRider
F-Secure Trojan.Generic.11492923
G Data Trojan.Generic.11492923
IKARUS anti.virus AdWare.Adload
K7 AntiVirus Trojan ( 0049c2a41 )
K7GW Trojan ( 0049c2a41 )
Malwarebytes PUP.Optional.weDownload.A
McAfee Artemis!C962DB0AAE43
McAfee-GW-Edition Artemis!C962DB0AAE43
MicroWorld-eScan Trojan.Generic.11492923
NANO AntiVirus Riskware.Win32.AdLoad.dcccgv
Panda Antivirus Trj/Genetic.gen
Sophos weDownload Manager
Symantec WS.Reputation.1
TrendMicro-HouseCall Suspicious_GEN.F47V0708
VIPRE Antivirus Crossrider (fs)
AVG Generic.D77
AVware Crossrider (fs)
CAT-QuickHeal AdWare.NSIS.r5 (Not a Virus)
Dr.Web Trojan.Crossrider.28616
Kaspersky not-a-virus:AdWare.NSIS.Adwapper.ai
Kingsoft AntiVirus Win32.Troj.Generic.a.(kcloud)
Rising Antivirus PE:Trojan.Win32.Generic.1733098B!389220747
Vba32 AntiVirus AdWare.Adwapper
Zillya Trojan.GoogUpdate.Win32.958
Comodo Security ApplicUnwnt
F-Prot W32/A-eb9ef301!Eldorado
AhnLab-V3 PUP/Win32.CrossRider
avast! Win32:Adware-gen [Adw]
Avira Adware/CrossRider.pq
Qihoo-360 HEUR/Malware.QVM10.Gen
Tencent Nsis.Adware.Adwapper.Edxj
Jiangmin Trojan.NSIS.GoogUpdate.br
SUPERAntiSpyware Adware.Crossrider/Variant
Bkav FE W32.CrossRider.Trojan
Agnitum Outpost PUA.Toolbar.CrossRider!
Trend Micro TROJ_MOSERAN.BMC
36cba358-e418-425b-9436-da3d2d9081fc-2.exe (MD5: 23a199f47a2803d225e1aa9d0c7265ce) has been flagged by 43 scanners:
Scanner Software Result
Lavasoft Ad-Aware Trojan.Generic.11493082
Avira AntiVir Adware/CrossRider.A.17820
Baidu-International Adware.Win32.CrossRider.BAJ
Bitdefender Trojan.Generic.11493082
Emsisoft Anti-Malware Trojan.Generic.11493082 (B)
ESET-NOD32 a variant of Win32/Toolbar.CrossRider.AJ
Fortinet FortiGate Riskware/Toolbar_CrossRider
F-Prot W32/A-eb9ef301!Eldorado
G Data Trojan.Generic.11493082
IKARUS anti.virus AdWare.Adload
K7 AntiVirus Trojan ( 0049bf0b1 )
K7GW Trojan ( 0049bf0b1 )
Malwarebytes PUP.Optional.weDownload.A
McAfee Artemis!23A199F47A28
MicroWorld-eScan Trojan.Generic.11493082
NANO AntiVirus Riskware.Win32.AdLoad.dcccgn
Rising Antivirus PE:Malware.Obscure!1.9C59
Sophos weDownload Manager
TrendMicro-HouseCall Suspicious_GEN.F47V0708
VIPRE Antivirus Crossrider (fs)
Zillya Adware.AdLoad.Win32.145
AVG Generic.16F
AVware Crossrider (fs)
Dr.Web Trojan.Crossrider.27022
F-Secure Gen:Variant.Adware.Kazy.374062
Kingsoft AntiVirus Win32.Troj.NSIS.br.(kcloud)
McAfee-GW-Edition Artemis!42AA1E814AAD
Panda Antivirus Trj/Genetic.gen
AhnLab-V3 PUP/Win32.CrossRider
Comodo Security ApplicUnwnt
Qihoo-360 Win32/Virus.Adware.ab1
Antiy-AVL GrayWare[AdWare:not-a-virus]/Win32.AdLoad
Avira Adware/CrossRider.pq
Kaspersky not-a-virus:AdWare.NSIS.Adwapper.ai
Symantec WS.Reputation.1
avast! Win32:Adware-gen [Adw]
Tencent Nsis.Trojan.Googupdate.Hvja
Vba32 AntiVirus Trojan.GoogUpdate
Jiangmin Trojan.NSIS.GoogUpdate.br
SUPERAntiSpyware Adware.Crossrider/Variant
Bkav FE W32.CrossRider.Trojan
Agnitum Outpost PUA.Toolbar.CrossRider!
Trend Micro TROJ_MOSERAN.BMC
36cba358-e418-425b-9436-da3d2d9081fc-11.exe (MD5: f5ced9cc2796ee9c23dec14034fbe333) has been flagged by 43 scanners:
Scanner Software Result
Lavasoft Ad-Aware Trojan.Generic.11481131
Avira AntiVir Adware/CrossRider.A.17803
Antiy-AVL GrayWare[AdWare:not-a-virus]/Win32.AdLoad
Baidu-International Adware.Win32.CrossRider.BAK
Bitdefender Trojan.Generic.11481131
Emsisoft Anti-Malware Trojan.Generic.11481131 (B)
ESET-NOD32 a variant of Win32/Toolbar.CrossRider.AK
Fortinet FortiGate Riskware/Toolbar_CrossRider
F-Secure Trojan.Generic.11481131
G Data Trojan.Generic.11481131
IKARUS anti.virus AdWare.Adload
K7 AntiVirus Trojan ( 0049c2a41 )
K7GW Trojan ( 0049c2a41 )
Malwarebytes PUP.Optional.weDownload.A
MicroWorld-eScan Trojan.Generic.11481131
NANO AntiVirus Riskware.Win32.AdLoad.dcbzfn
Panda Antivirus Trj/Genetic.gen
Sophos weDownload Manager
TrendMicro-HouseCall Suspicious_GEN.F47V0708
VIPRE Antivirus Crossrider (fs)
Zillya Adware.AdLoad.Win32.146
AhnLab-V3 PUP/Win32.CrossRider
AVG Generic.D77
Avira Adware/CrossRider.pq
AVware Crossrider (fs)
Dr.Web Trojan.Crossrider.33024
Kaspersky not-a-virus:AdWare.NSIS.Adwapper.ai
Qihoo-360 Win32/Virus.Adware.970
Rising Antivirus PE:Malware.Obscure!1.9C59
Symantec WS.Reputation.1
avast! Win32:Adware-gen [Adw]
McAfee Artemis!628509A3A09B
McAfee-GW-Edition Artemis!628509A3A09B
Kingsoft AntiVirus Win32.Troj.Generic.a.(kcloud)
Tencent Nsis.Trojan.Googupdate.Hvja
Vba32 AntiVirus Trojan.GoogUpdate
Comodo Security ApplicUnwnt
F-Prot W32/A-b38b90e7!Eldorado
Jiangmin Trojan.NSIS.GoogUpdate.br
SUPERAntiSpyware Adware.Crossrider/Variant
Bkav FE W32.CrossRider.Trojan
Agnitum Outpost PUA.Toolbar.CrossRider!
Trend Micro TROJ_MOSERAN.BMC
2edc0289-cc77-43d7-96a7-b05654baac3c-7.exe (MD5: b13418f26b6e71870ca997aaa2c59003) has been flagged by 40 scanners:
Scanner Software Result
AVG Generic.D77
Avira Adware/CrossRider.pq
AVware Crossrider (fs)
Dr.Web Trojan.Crossrider.31451
ESET-NOD32 a variant of Win32/Toolbar.CrossRider.AM
Fortinet FortiGate Adware/Adwapper
G Data Win32.Adware.Crossrider.M
IKARUS anti.virus Trojan.GoogUpdate
Kaspersky not-a-virus:AdWare.NSIS.Adwapper.ai
Kingsoft AntiVirus Win32.Troj.Generic.a.(kcloud)
Malwarebytes PUP.Optional.weDownload.A
NANO AntiVirus Riskware.Win32.Crossrider.devuka
Panda Antivirus Trj/Genetic.gen
Qihoo-360 HEUR/Malware.QVM10.Gen
Sophos weDownload Manager
Tencent Nsis.Adware.Adwapper.Pbyi
VIPRE Antivirus Crossrider (fs)
McAfee Artemis!C0481281D3F5
McAfee-GW-Edition Artemis
AhnLab-V3 PUP/Win32.CrossRider
K7 AntiVirus Adware ( 004a970a1 )
K7GW Adware ( 004a970a1 )
avast! Win32:Crossrider-N [PUP]
Baidu-International Trojan.Win32.GoogUpdate.AlQp
F-Prot W32/A-04c00d5a!Eldorado
TrendMicro-HouseCall Suspicious_GEN.F47V0809
Lavasoft Ad-Aware Gen:Variant.Adware.Kazy.374062
Bitdefender Gen:Variant.Adware.Kazy.374062
Emsisoft Anti-Malware Gen:Variant.Adware.Kazy.374062 (B)
F-Secure Gen:Variant.Adware.Kazy.374062
MicroWorld-eScan Gen:Variant.Adware.Kazy.374062
Rising Antivirus PE:Malware.Obscure!1.9C59
Antiy-AVL GrayWare[AdWare:not-a-virus]/NSIS.Adwapper
Zillya Trojan.GoogUpdate.Win32.1952
Avira AntiVir ADWARE/CrossRider.Gen2
Symantec Adware.Crossid!gen1
SUPERAntiSpyware Adware.Crossrider/Variant
Bkav FE W32.CrossRider.Trojan
Agnitum Outpost PUA.Toolbar.CrossRider!
Trend Micro TROJ_MOSERAN.BMC
2edc0289-cc77-43d7-96a7-b05654baac3c-6.exe (MD5: cb3c4477f6aa2333d801987a47af5221) has been flagged by 40 scanners:
Scanner Software Result
AVG Generic.D77
Avira Adware/CrossRider.pq
AVware Crossrider (fs)
Dr.Web Trojan.Crossrider.31452
ESET-NOD32 a variant of Win32/Toolbar.CrossRider.AP
G Data Win32.Adware.Crossrider.M
IKARUS anti.virus PUA.PlusHD
Kaspersky not-a-virus:AdWare.NSIS.Adwapper.ai
Kingsoft AntiVirus Win32.Troj.Generic.a.(kcloud)
Malwarebytes PUP.Optional.weDownload.A
McAfee Artemis!CB3C4477F6AA
McAfee-GW-Edition BehavesLike.Win32.BadFile.th
Panda Antivirus Trj/Chgt.F
Qihoo-360 Win32/Virus.Adware.970
Sophos Generic PUA EA
Tencent Nsis.Adware.Adwapper.Syrs
VIPRE Antivirus Crossrider (fs)
avast! Win32:Crossrider-N [PUP]
Baidu-International Trojan.Win32.GoogUpdate.AlQp
Fortinet FortiGate W32/GoogUpdate.AE!tr
F-Prot W32/A-04c00d5a!Eldorado
TrendMicro-HouseCall Suspicious_GEN.F47V0809
Lavasoft Ad-Aware Gen:Variant.Adware.Kazy.374062
Bitdefender Gen:Variant.Adware.Kazy.374062
Emsisoft Anti-Malware Gen:Variant.Adware.Kazy.374062 (B)
F-Secure Gen:Variant.Adware.Kazy.374062
MicroWorld-eScan Gen:Variant.Adware.Kazy.374062
Rising Antivirus PE:Malware.Obscure!1.9C59
AhnLab-V3 PUP/Win32.CrossRider
Antiy-AVL GrayWare[AdWare:not-a-virus]/NSIS.Adwapper
NANO AntiVirus Trojan.Win32.GoogUpdate.deofza
K7 AntiVirus Adware ( 004a90bb1 )
K7GW Adware ( 004a90bb1 )
Zillya Trojan.GoogUpdate.Win32.1952
Avira AntiVir ADWARE/CrossRider.Gen2
Symantec Adware.Crossid!gen1
SUPERAntiSpyware Adware.Crossrider/Variant
Bkav FE W32.CrossRider.Trojan
Agnitum Outpost PUA.Toolbar.CrossRider!
Trend Micro TROJ_MOSERAN.BMC

Software Behaviors

Scheduled tasks:
  • b9a50c40-f2cc-420c-be6f-593440d8deaa-6.exe is scheduled as a task named '731b28ed-138e-45a5-af8b-7ef590e61293-6'.
  • The weDownload Manager-codedownloader.exe is scheduled as a task named 'ebed045b-11c2-47a7-bae0-1f07ff30e3c0-7'.
  • ebed045b-11c2-47a7-bae0-1f07ff30e3c0-6.exe is scheduled as a task named 'temp_ebed045b-11c2-47a7-bae0-1f07ff30e3c0-6'.
  • ebed045b-11c2-47a7-bae0-1f07ff30e3c0-2.exe is scheduled as a task named 'temp_ebed045b-11c2-47a7-bae0-1f07ff30e3c0-2'.
  • bc39018e-d2de-4d68-aa32-0afacbc16f5f-2.exe is scheduled as a task named 'temp_bc39018e-d2de-4d68-aa32-0afacbc16f5f-2'.
  • 03091666-40b5-44af-b8b1-7438214ece0b-4.exe is scheduled as a task named '03091666-40b5-44af-b8b1-7438214ece0b-4'.

Startup Entries

Startup tasks:
  • b9a50c40-f2cc-420c-be6f-593440d8deaa-6.exe is automatically launched at startup through a scheduled task named 5d2076bc-d559-4c68-aca0-29a2e5982b96-7.
  • The weDownload Manager-nova.exe is automatically launched at startup through a scheduled task named 09d2f095-b00b-4e2a-8f47-83a824a7126a-7.
  • The weDownload Manager-novainstaller.exe is automatically launched at startup through a scheduled task named 1fb50b06-6845-4d15-b2d8-32c25ced1291-6.
  • 1fb50b06-6845-4d15-b2d8-32c25ced1291-11.exe is automatically launched at startup through a scheduled task named 1fb50b06-6845-4d15-b2d8-32c25ced1291-3.
  • 2e18c836-5212-44f2-b4dd-c1ea360752fb-7.exe is automatically launched at startup through a scheduled task named 2e18c836-5212-44f2-b4dd-c1ea360752fb-1.
  • 2e18c836-5212-44f2-b4dd-c1ea360752fb-5.exe is automatically launched at startup through a scheduled task named 2e18c836-5212-44f2-b4dd-c1ea360752fb-5_user.

Software Details

URL:
https://www.wedownload.com
Support:
–
Installation path:
C:\Program Files\the wedownload manager
Uninstaller:
C:\Program Files\The weDownload Manager\Uninstall.exe /fromcontrolpanel=1
Size:
9.00 MB
Language:
English

The weDownload Manager Executable Details

Primary executable:
utils.exe
Name:
The weDownload Manager
Path:
C:\Program Files\the wedownload manager\utils.exe
MD5:
–
SHA-1:
–
SHA-256:
–
Files installed by The weDownload Manager
File Type Filename MD5
EXE
3c4d8dc51f11b1655440d46ef96311f2
EXE
4a76cc3911a9294837a5a648ac3ec081
EXE
863591eade688e6e3e6efd70774e7e54
EXE
d512431295a86ff272909cbc734faca2
EXE
4457803ff8f66df5e3caaf97d5cedf9a
EXE
24b4bf287ac7fe07a5ec5baee4e789b5
EXE
e899d01cbfae4f6ad450d7b661a7a3c3
EXE
3451fff6f15919f573aedf1a6e898aa8
EXE
d2b68f0fd76752f86ac12d6b57528f7c
EXE
e97c4b85fcf633bdec4283f7f3eda349