weDownload Manager

weDownload Manager

Known Toolbar

by weDownload Ltd

What is weDownload Manager?

weDownload Manager is software application developed by weDownload Ltd. It is most commonly found on computers running Windows 7 with nearly 64.44% of installations running this operating system. weDownload Manager's installer is typically 3.00 MB in size and installs around 15 files. The most common release is 1.28.153.1 with 53.89% of all installations currently using this version.

weDownload Manager is most popular in the United States with 53.59% of installations residing in this country.

weDownload Manager adds 1 scheduled task to the Windows Task Scheduler launching the program at randomly scheduled times. When using a computer that is connected to the internet, weDownload Manager is known to create 5 firewall exceptions to allow inbound and outbound connectivity.

About weDownload Manager?

The weDownload Manager is a software download distribution utility that includes various additional offerings such as the Ominent Toolbar. This utility may offer adware and toolbar options for users to consider during the installation process. It is important to note that some of these options may inject advertising into the user's Internet browser in the form of search-related ads, banner and video ads, in-text ads and links, transitional, interstitial and full page ads. It is important to be aware that ads and features that appear on websites using this adware plugin are not associated with the underlying website the user is currently visiting and are injected. These ads are typically injected in the header or footer area of the web page. The software may be distributed in adware bundles from websites such as todownload.com.

Multiple virus scanners have detected malware in weDownload Manager.

utils.exe (MD5: 951829ee993aa314cad109693ecd4e08) has been flagged by 30 scanners:
Scanner Software Result
Avira AntiVir Adware/Downloader.M.3
avast! Win32:Dropper-gen [Drp]
Baidu-International Trojan.Win32.Packed.adWQ
Dr.Web Trojan.Crossrider.9
ESET-NOD32 Win32/Packed.ScrambleWrapper.C
Kingsoft AntiVirus Win32.Troj.Generic.a.(kcloud)
McAfee Artemis!951829EE993A
McAfee-GW-Edition Heuristic.BehavesLike.Win32.Suspicious-PKR.G
TrendMicro-HouseCall TROJ_GEN.F47V0923
Lavasoft Ad-Aware Adware.Generic.616022
Antiy-AVL AdWare/Win32.Lyckriks
AVG Generic5.AIIQ
Bitdefender Adware.Generic.616022
Bkav FE HW32.Laneul.wauu
Emsisoft Anti-Malware Adware.Generic.616022 (B)
Fortinet FortiGate Adware/Lyckriks
F-Secure Adware.Generic.616022
G Data Adware.Generic.616022
Jiangmin AdWare/Lyckriks.dm
K7 AntiVirus Trojan ( 0048e2ed1 )
K7GW Trojan ( 0048e2ed1 )
Kaspersky not-a-virus:AdWare.Win32.Lyckriks.ly
Malwarebytes PUP.Optional.WeDownload.A
MicroWorld-eScan Adware.Generic.616022
Sophos Generic PUA ND
Symantec Adware.FindLyrics
VIPRE Antivirus Crossrider (fs)
Vba32 AntiVirus AdWare.Lyckriks
Norman Suspicious_Gen4.FNMLZ
Panda Antivirus Suspicious file
weDownload Manager-updater.exe (MD5: b3643bdc9c54daa1b695155d9dad1f04) has been flagged by 8 scanners:
Scanner Software Result
ESET-NOD32 probably a variant of Win32/Toolbar.CrossRider.I
McAfee Artemis!B3643BDC9C54
McAfee-GW-Edition Artemis!B3643BDC9C54
TrendMicro-HouseCall TROJ_GEN.F47V0915
VIPRE Antivirus Crossrider (fs)
Baidu-International Trojan.Win32.Win64.Toolbar.Crossrider
Bkav FE W32.Clodbf6.Trojan.80d1
Malwarebytes PUP.Optional.WeDownload.A
weDownload Manager-firefoxinstaller.exe (MD5: 97fa5404f9d494a7079d35d1041e058d) has been flagged by 16 scanners:
Scanner Software Result
Baidu-International Adware.Win32.ElexInstall.71
ESET-NOD32 a variant of Win32/Toolbar.CrossRider.J
K7 AntiVirus Trojan ( 0048e2ed1 )
K7GW Trojan ( 0048e2ed1 )
Malwarebytes PUP.Optional.WeDownload.A
Norman Suspicious_Gen4.FNMLZ
Panda Antivirus Suspicious file
Sophos Generic PUA CH
Symantec Adware.FindLyrics
TrendMicro-HouseCall TROJ_GEN.R047H05JL13
VIPRE Antivirus Crossrider (fs)
McAfee Artemis!2805C71E9F81
McAfee-GW-Edition Heuristic.BehavesLike.Win32.Suspicious-BAY.K
AVG Generic5.AJKA
Kingsoft AntiVirus Win32.Troj.Generic.a.(kcloud)
Bkav FE W32.Clodbf6.Trojan.80d1
weDownload Manager-enabler.exe (MD5: 5db9d681daaa99209e891dd206f6d140) has been flagged by 12 scanners:
Scanner Software Result
AVG Generic5.AJKA
K7 AntiVirus Trojan ( 0048c68d1 )
K7GW Trojan ( 0048c68d1 )
Kingsoft AntiVirus Win32.Troj.Generic.a.(kcloud)
Malwarebytes PUP.Optional.WeDownload.A
McAfee Artemis!5DB9D681DAAA
McAfee-GW-Edition Heuristic.BehavesLike.Win32.Suspicious-BAY.K
ESET-NOD32 probably a variant of Win32/Toolbar.CrossRider.I
TrendMicro-HouseCall TROJ_GEN.F47V0915
VIPRE Antivirus Crossrider (fs)
Baidu-International Trojan.Win32.Win64.Toolbar.Crossrider
Bkav FE W32.Clodbf6.Trojan.80d1
weDownload Manager-codedownloader.exe (MD5: 2805c71e9f8159bfa33fa1479286104c) has been flagged by 13 scanners:
Scanner Software Result
Baidu-International Adware.Win32.AddLyrics.45
ESET-NOD32 a variant of Win32/Toolbar.CrossRider.K
K7 AntiVirus Trojan ( 0048e2021 )
K7GW Trojan ( 0048e2021 )
Malwarebytes PUP.Optional.WeDownload.A
McAfee Artemis!2805C71E9F81
McAfee-GW-Edition Heuristic.BehavesLike.Win32.Suspicious-BAY.K
Symantec WS.Reputation.1
TrendMicro-HouseCall TROJ_GEN.F47V1021
VIPRE Antivirus Crossrider (fs)
AVG Generic5.AJKA
Kingsoft AntiVirus Win32.Troj.Generic.a.(kcloud)
Bkav FE W32.Clodbf6.Trojan.80d1

Software Behaviors

Firewall:
  • weDownload Manager-updater.exe is added as a firewall exception for 'C:\Program Files\weDownload Manager\weDownload Manager-updater.exe'.
  • weDownload Manager-firefoxinstaller.exe is added as a firewall exception for 'C:\Program Files\weDownload Manager\weDownload Manager-firefoxinstaller.exe'.
  • weDownload Manager-enabler.exe is added as a firewall exception for 'C:\Program Files\weDownload Manager\weDownload Manager-enabler.exe'.
  • weDownload Manager-codedownloader.exe is added as a firewall exception for 'C:\Program Files\weDownload Manager\weDownload Manager-codedownloader.exe'.
  • weDownload Manager-chromeinstaller.exe is added as a firewall exception for 'C:\Program Files\weDownload Manager\weDownload Manager-chromeinstaller.exe'.
Scheduled tasks:
  • weDownload Manager-enabler.exe is scheduled as a task named 'temp_weDownload Manager-enabler'.

Startup Entries

Startup tasks:
  • weDownload Manager-updater.exe is automatically launched at startup through a scheduled task named weDownload Manager-updater.
  • weDownload Manager-firefoxinstaller.exe is automatically launched at startup through a scheduled task named weDownload Manager-firefoxinstaller.
  • weDownload Manager-enabler.exe is automatically launched at startup through a scheduled task named weDownload Manager-enabler.
  • weDownload Manager-codedownloader.exe is automatically launched at startup through a scheduled task named weDownload Manager-codedownloader.
  • weDownload Manager-chromeinstaller.exe is automatically launched at startup through a scheduled task named weDownload Manager-chromeinstaller.

Software Details

URL:
https://www.wedownload.com
Support:
–
Installation path:
C:\Program Files\wedownload manager
Uninstaller:
C:\Program Files\weDownload Manager\Uninstall.exe /fromcontrolpanel=1
Size:
3.00 MB
Language:
English

weDownload Manager Executable Details

Primary executable:
utils.exe
Name:
weDownload Manager
Path:
C:\Program Files\wedownload manager\utils.exe
MD5:
951829ee993aa314cad109693ecd4e08
SHA-1:
–
SHA-256:
–
Files installed by weDownload Manager
File Type Filename MD5
EXE
ab91a7350a5fddcdf0a7b0c60e8e4e71
EXE
utils.exe
Malware
951829ee993aa314cad109693ecd4e08
EXE
1f0357dedd4d371c8436826792cc5542
EXE
b3643bdc9c54daa1b695155d9dad1f04
EXE
97fa5404f9d494a7079d35d1041e058d
EXE
5db9d681daaa99209e891dd206f6d140
EXE
2805c71e9f8159bfa33fa1479286104c
EXE
c929fca29d2be842b339eeb5374ad170
EXE
f7777f2c55174b6632879d8b6e83b2d1
EXE
42e1799887f120592a633d50d9caaaa8