File name:

ADWARE.exe

Full analysis: https://app.any.run/tasks/201bb605-e685-45d4-9529-d5e7ddcb1f80
Verdict: Malicious activity
Threats:

Adware is a form of malware that targets users with unwanted advertisements, often disrupting their browsing experience. It typically infiltrates systems through software bundling, malicious websites, or deceptive downloads. Once installed, it may track user activity, collect sensitive data, and display intrusive ads, including pop-ups or banners. Some advanced adware variants can bypass security measures and establish persistence on devices, making removal challenging. Additionally, adware can create vulnerabilities that other malware can exploit, posing a significant risk to user privacy and system security.

Analysis date: October 11, 2020, 04:14:27
OS: Windows 7 Professional Service Pack 1 (build: 7601, 32 bit)
Tags:
adware
loader
Indicators:
MIME: application/x-dosexec
File info: PE32 executable (GUI) Intel 80386, for MS Windows, UPX compressed
MD5:

9364607DFE2CBFEF763C146EE7E27DFA

SHA1:

53A7D87EEF714750CC1751182443ACFEBC41B832

SHA256:

3A75D6962893903BDFC8558485DF3E3166989BB5DD5D524D2C5C796F60221F3D

SSDEEP:

24576:eq5TfcdHj4fmbqOY2q570smVkVMyO7BlWEWEzKJ9TtLs2l0llFJ+o0zQJ9TtDi8I:eUTsamVYxkle5YlF55q

ANY.RUN is an interactive service which provides full access to the guest system. Information in this report could be distorted by user actions and is provided for user acknowledgement as it is. ANY.RUN does not guarantee maliciousness or safety of the content.
  • MALICIOUS

    • Application was dropped or rewritten from another process

      • dmr_72.exe (PID: 1748)
      • WcInstaller.exe (PID: 3648)
      • WebCompanionInstaller.exe (PID: 636)
      • OperaSetup.exe (PID: 316)
      • OperaSetup.exe (PID: 2444)
      • OperaSetup.exe (PID: 1576)
      • OperaSetup.exe (PID: 3512)
      • OperaSetup.exe (PID: 3108)
      • Opera_1218_int_Setup_x64.exe (PID: 2996)
      • WebCompanion.exe (PID: 2272)
      • Lavasoft.WCAssistant.WinService.exe (PID: 3692)
      • Ad-Aware Web Companion.exe (PID: 372)
      • _sfx.exe (PID: 4052)
      • assistant_installer.exe (PID: 1500)
      • assistant_installer.exe (PID: 1692)
      • installer.exe (PID: 712)
      • installer.exe (PID: 3932)
      • assistant_installer.exe (PID: 2644)
      • assistant_installer.exe (PID: 2848)
      • assistant_installer.exe (PID: 2080)
      • browser_assistant.exe (PID: 3056)
      • assistant_installer.exe (PID: 1344)
      • launcher.exe (PID: 3304)
      • browser_assistant.exe (PID: 3904)
      • launcher.exe (PID: 4012)
      • launcher.exe (PID: 1436)
      • WebCompanion.exe (PID: 2696)
      • launcher.exe (PID: 1008)
      • opera.exe (PID: 2856)
      • opera_crashreporter.exe (PID: 580)
      • opera.exe (PID: 672)
      • opera.exe (PID: 3784)
      • opera.exe (PID: 3116)
      • opera.exe (PID: 3348)
      • opera.exe (PID: 2868)
      • opera.exe (PID: 2772)
      • opera.exe (PID: 1908)
      • opera.exe (PID: 3220)
      • opera.exe (PID: 184)
      • opera.exe (PID: 1940)
      • opera.exe (PID: 3700)
      • opera.exe (PID: 2188)
      • opera.exe (PID: 532)
      • opera.exe (PID: 3196)
      • opera.exe (PID: 3968)
      • opera.exe (PID: 2632)
      • opera.exe (PID: 3844)
      • opera.exe (PID: 2496)
      • opera.exe (PID: 540)
      • opera.exe (PID: 2724)
      • opera_autoupdate.exe (PID: 1752)
      • launcher.exe (PID: 4076)
      • opera.exe (PID: 1676)
      • opera.exe (PID: 3232)
      • opera.exe (PID: 2488)
      • opera.exe (PID: 3216)
      • opera_autoupdate.exe (PID: 2104)
      • opera.exe (PID: 3624)
      • opera.exe (PID: 2556)
      • opera.exe (PID: 3144)
      • opera.exe (PID: 2804)
      • opera.exe (PID: 608)
      • opera.exe (PID: 2392)
      • opera.exe (PID: 3640)
      • opera.exe (PID: 3832)
      • opera.exe (PID: 3336)
      • opera.exe (PID: 3672)
      • opera.exe (PID: 1888)
      • installer.exe (PID: 3292)
      • opera.exe (PID: 3448)
      • opera_autoupdate.exe (PID: 5372)
      • opera_autoupdate.exe (PID: 4336)
      • opera.exe (PID: 2976)
      • opera.exe (PID: 3516)
      • opera.exe (PID: 4016)
      • opera_autoupdate.exe (PID: 6088)
      • opera_autoupdate.exe (PID: 4452)
      • opera.exe (PID: 2640)
    • Changes settings of System certificates

      • dmr_72.exe (PID: 1748)
      • WebCompanionInstaller.exe (PID: 636)
      • WebCompanion.exe (PID: 2272)
      • OperaSetup.exe (PID: 316)
    • Actions looks like stealing of personal data

      • OperaSetup.exe (PID: 316)
      • OperaSetup.exe (PID: 2444)
      • OperaSetup.exe (PID: 1576)
      • OperaSetup.exe (PID: 3108)
      • WebCompanion.exe (PID: 2272)
      • assistant_installer.exe (PID: 1692)
      • assistant_installer.exe (PID: 1500)
      • installer.exe (PID: 712)
      • installer.exe (PID: 3932)
      • assistant_installer.exe (PID: 2644)
      • assistant_installer.exe (PID: 2848)
      • assistant_installer.exe (PID: 1344)
      • assistant_installer.exe (PID: 2080)
      • browser_assistant.exe (PID: 3056)
      • browser_assistant.exe (PID: 3904)
      • WebCompanion.exe (PID: 2696)
      • opera_crashreporter.exe (PID: 580)
      • opera.exe (PID: 672)
      • opera.exe (PID: 3348)
      • opera.exe (PID: 3116)
      • opera.exe (PID: 2868)
      • opera.exe (PID: 3784)
      • opera.exe (PID: 2772)
      • opera.exe (PID: 1908)
      • opera.exe (PID: 1940)
      • opera.exe (PID: 184)
      • opera.exe (PID: 2188)
      • opera.exe (PID: 3220)
      • opera.exe (PID: 3196)
      • opera.exe (PID: 2632)
      • opera.exe (PID: 2496)
      • opera.exe (PID: 3844)
      • opera_autoupdate.exe (PID: 1752)
      • opera_autoupdate.exe (PID: 2104)
      • opera.exe (PID: 1676)
      • opera.exe (PID: 3232)
      • opera.exe (PID: 2856)
      • opera.exe (PID: 3216)
      • opera.exe (PID: 2488)
      • opera.exe (PID: 3624)
      • opera.exe (PID: 3144)
      • opera.exe (PID: 2556)
      • opera.exe (PID: 2724)
      • opera.exe (PID: 540)
      • opera.exe (PID: 3832)
      • opera.exe (PID: 3640)
      • opera.exe (PID: 3336)
      • opera.exe (PID: 2976)
      • opera.exe (PID: 3672)
      • opera.exe (PID: 3448)
      • opera.exe (PID: 3516)
      • opera.exe (PID: 2804)
      • opera.exe (PID: 608)
      • opera.exe (PID: 2392)
      • opera.exe (PID: 1888)
      • opera.exe (PID: 2640)
      • opera.exe (PID: 4016)
      • opera_autoupdate.exe (PID: 4452)
      • opera_autoupdate.exe (PID: 6088)
    • Loads dropped or rewritten executable

      • OperaSetup.exe (PID: 3108)
      • OperaSetup.exe (PID: 2444)
      • OperaSetup.exe (PID: 316)
      • OperaSetup.exe (PID: 1576)
      • OperaSetup.exe (PID: 3512)
      • WebCompanion.exe (PID: 2272)
      • Lavasoft.WCAssistant.WinService.exe (PID: 3692)
      • installer.exe (PID: 712)
      • installer.exe (PID: 3932)
      • WebCompanion.exe (PID: 2696)
      • opera.exe (PID: 2856)
      • opera.exe (PID: 672)
      • opera.exe (PID: 3784)
      • opera.exe (PID: 3348)
      • opera.exe (PID: 2868)
      • opera.exe (PID: 3116)
      • opera.exe (PID: 2772)
      • opera.exe (PID: 1908)
      • opera.exe (PID: 1940)
      • opera.exe (PID: 3700)
      • opera.exe (PID: 184)
      • opera.exe (PID: 3220)
      • opera.exe (PID: 532)
      • opera.exe (PID: 3196)
      • opera.exe (PID: 2188)
      • opera.exe (PID: 2632)
      • opera.exe (PID: 3968)
      • opera.exe (PID: 540)
      • opera.exe (PID: 2496)
      • opera.exe (PID: 3844)
      • opera.exe (PID: 2724)
      • opera.exe (PID: 3232)
      • opera.exe (PID: 1676)
      • opera.exe (PID: 3216)
      • opera.exe (PID: 3624)
      • opera.exe (PID: 2556)
      • opera.exe (PID: 3144)
      • opera.exe (PID: 608)
      • opera.exe (PID: 2488)
      • opera.exe (PID: 2804)
      • opera.exe (PID: 3336)
      • opera.exe (PID: 3672)
      • opera.exe (PID: 3832)
      • opera.exe (PID: 1888)
      • opera.exe (PID: 2392)
      • opera.exe (PID: 3640)
      • opera.exe (PID: 3448)
      • installer.exe (PID: 3292)
      • opera.exe (PID: 2976)
      • opera.exe (PID: 3516)
      • opera.exe (PID: 2640)
    • Changes internet zones settings

      • WebCompanionInstaller.exe (PID: 636)
    • Changes the autorun value in the registry

      • WebCompanion.exe (PID: 2272)
      • installer.exe (PID: 712)
      • assistant_installer.exe (PID: 2644)
    • Starts Visual C# compiler

      • WebCompanion.exe (PID: 2272)
    • Loads the Task Scheduler COM API

      • assistant_installer.exe (PID: 2644)
      • installer.exe (PID: 712)
      • opera.exe (PID: 2856)
  • SUSPICIOUS

    • Reads Environment values

      • dmr_72.exe (PID: 1748)
    • Reads internet explorer settings

      • dmr_72.exe (PID: 1748)
    • Executable content was dropped or overwritten

      • ADWARE.exe (PID: 2612)
      • dmr_72.exe (PID: 1748)
      • WcInstaller.exe (PID: 3648)
      • OperaSetup.exe (PID: 2444)
      • OperaSetup.exe (PID: 316)
      • OperaSetup.exe (PID: 1576)
      • OperaSetup.exe (PID: 3108)
      • Opera_1218_int_Setup_x64.exe (PID: 2996)
      • WebCompanionInstaller.exe (PID: 636)
      • csc.exe (PID: 3664)
      • _sfx.exe (PID: 4052)
      • installer.exe (PID: 712)
      • installer.exe (PID: 3932)
      • assistant_installer.exe (PID: 2644)
      • launcher.exe (PID: 4076)
      • installer.exe (PID: 3292)
    • Reads Internet Cache Settings

      • dmr_72.exe (PID: 1748)
      • OperaSetup.exe (PID: 316)
      • browser_assistant.exe (PID: 3056)
    • Adds / modifies Windows certificates

      • WebCompanionInstaller.exe (PID: 636)
      • dmr_72.exe (PID: 1748)
      • WebCompanion.exe (PID: 2272)
      • OperaSetup.exe (PID: 316)
    • Application launched itself

      • OperaSetup.exe (PID: 316)
      • OperaSetup.exe (PID: 1576)
      • assistant_installer.exe (PID: 1692)
      • installer.exe (PID: 712)
      • assistant_installer.exe (PID: 2644)
      • assistant_installer.exe (PID: 1344)
      • browser_assistant.exe (PID: 3056)
      • opera.exe (PID: 2856)
      • opera_autoupdate.exe (PID: 1752)
      • opera_autoupdate.exe (PID: 5372)
      • opera_autoupdate.exe (PID: 6088)
    • Creates files in the user directory

      • OperaSetup.exe (PID: 2444)
      • WebCompanionInstaller.exe (PID: 636)
      • WebCompanion.exe (PID: 2272)
      • installer.exe (PID: 712)
      • browser_assistant.exe (PID: 3056)
      • opera.exe (PID: 2856)
      • opera.exe (PID: 3784)
      • opera_autoupdate.exe (PID: 1752)
      • opera_autoupdate.exe (PID: 6088)
    • Starts itself from another location

      • OperaSetup.exe (PID: 316)
    • Creates files in the program directory

      • WebCompanionInstaller.exe (PID: 636)
      • WebCompanion.exe (PID: 2272)
      • Lavasoft.WCAssistant.WinService.exe (PID: 3692)
      • installer.exe (PID: 712)
      • OperaSetup.exe (PID: 1576)
      • assistant_installer.exe (PID: 2644)
      • WebCompanion.exe (PID: 2696)
      • opera_autoupdate.exe (PID: 5372)
    • Starts CMD.EXE for commands execution

      • WebCompanionInstaller.exe (PID: 636)
      • Lavasoft.WCAssistant.WinService.exe (PID: 3692)
    • Uses NETSH.EXE for network configuration

      • cmd.exe (PID: 3456)
      • cmd.exe (PID: 2060)
    • Starts SC.EXE for service management

      • WebCompanionInstaller.exe (PID: 636)
    • Creates a software uninstall entry

      • WebCompanionInstaller.exe (PID: 636)
      • installer.exe (PID: 712)
    • Executed as Windows Service

      • Lavasoft.WCAssistant.WinService.exe (PID: 3692)
      • PresentationFontCache.exe (PID: 2776)
    • Removes files from Windows directory

      • Lavasoft.WCAssistant.WinService.exe (PID: 3692)
      • WebCompanionInstaller.exe (PID: 636)
    • Creates files in the Windows directory

      • Lavasoft.WCAssistant.WinService.exe (PID: 3692)
      • WebCompanion.exe (PID: 2272)
      • WebCompanionInstaller.exe (PID: 636)
    • Modifies the open verb of a shell class

      • installer.exe (PID: 712)
    • Changes the started page of IE

      • WebCompanion.exe (PID: 2272)
    • Changes IE settings (feature browser emulation)

      • assistant_installer.exe (PID: 2644)
    • Executed via COM

      • unsecapp.exe (PID: 2596)
    • Reads the machine GUID from the registry

      • opera.exe (PID: 2856)
      • opera_autoupdate.exe (PID: 1752)
      • opera_autoupdate.exe (PID: 6088)
    • Executed via Task Scheduler

      • launcher.exe (PID: 4076)
    • Searches for installed software

      • dmr_72.exe (PID: 1748)
  • INFO

    • Dropped object may contain Bitcoin addresses

      • ADWARE.exe (PID: 2612)
      • WebCompanionInstaller.exe (PID: 636)
      • Opera_1218_int_Setup_x64.exe (PID: 2996)
      • OperaSetup.exe (PID: 1576)
      • OperaSetup.exe (PID: 316)
    • Reads settings of System Certificates

      • dmr_72.exe (PID: 1748)
      • OperaSetup.exe (PID: 316)
      • WebCompanion.exe (PID: 2272)
      • chrome.exe (PID: 3136)
      • browser_assistant.exe (PID: 3056)
      • opera.exe (PID: 3784)
    • Manual execution by user

      • chrome.exe (PID: 2828)
      • assistant_installer.exe (PID: 1344)
      • launcher.exe (PID: 1008)
    • Application launched itself

      • chrome.exe (PID: 2828)
    • Reads the hosts file

      • chrome.exe (PID: 2828)
      • chrome.exe (PID: 3136)
      • opera.exe (PID: 2856)
      • opera.exe (PID: 3784)
Find more information about signature artifacts and mapping to MITRE ATT&CK™ MATRIX at the full report
No Malware configuration.

TRiD

.exe | Win64 Executable (generic) (30.7)
.exe | UPX compressed Win32 Executable (30.1)
.exe | Win32 EXE Yoda's Crypter (29.5)
.exe | Win32 Executable (generic) (5)
.exe | Generic Win/DOS Executable (2.2)

EXIF

EXE

MachineType: Intel 386 or later, and compatibles
TimeStamp: 2015:10:30 10:29:35+01:00
PEType: PE32
LinkerVersion: 11
CodeSize: 344064
InitializedDataSize: 1122304
UninitializedDataSize: 1646592
EntryPoint: 0x1e6900
OSVersion: 5.1
ImageVersion: -
SubsystemVersion: 5.1
Subsystem: Windows GUI
FileVersionNumber: 1.1.5.5
ProductVersionNumber: 1.1.5.5
FileFlagsMask: 0x0000
FileFlags: (none)
FileOS: Win32
ObjectFileType: Unknown
FileSubtype: -
LanguageCode: German
CharacterSet: Unicode
FileVersion: 1.1.5.5
Comments: CHIP Secured Installer
FileDescription: CHIP Secured Installer
ProductVersion: 1.1.5.5
LegalCopyright: Copyright © 2015 Chip Digital GmbH

Summary

Architecture: IMAGE_FILE_MACHINE_I386
Subsystem: IMAGE_SUBSYSTEM_WINDOWS_GUI
Compilation Date: 30-Oct-2015 09:29:35
Detected languages:
  • English - United Kingdom
  • German - Germany
FileVersion: 1.1.5.5
Comments: CHIP Secured Installer
FileDescription: CHIP Secured Installer
ProductVersion: 1.1.5.5
LegalCopyright: Copyright © 2015 Chip Digital GmbH

DOS Header

Magic number: MZ
Bytes on last page of file: 0x0090
Pages in file: 0x0003
Relocations: 0x0000
Size of header: 0x0004
Min extra paragraphs: 0x0000
Max extra paragraphs: 0xFFFF
Initial SS value: 0x0000
Initial SP value: 0x00B8
Checksum: 0x0000
Initial IP value: 0x0000
Initial CS value: 0x0000
Overlay number: 0x0000
OEM identifier: 0x0000
OEM information: 0x0000
Address of NE header: 0x00000108

PE Headers

Signature: PE
Machine: IMAGE_FILE_MACHINE_I386
Number of sections: 3
Time date stamp: 30-Oct-2015 09:29:35
Pointer to Symbol Table: 0x00000000
Number of symbols: 0
Size of Optional Header: 0x00E0
Characteristics:
  • IMAGE_FILE_32BIT_MACHINE
  • IMAGE_FILE_EXECUTABLE_IMAGE
  • IMAGE_FILE_LARGE_ADDRESS_AWARE

Sections

Name
Virtual Address
Virtual Size
Raw Size
Charateristics
Entropy
UPX0
0x00001000
0x00192000
0x00000000
IMAGE_SCN_CNT_UNINITIALIZED_DATA, IMAGE_SCN_MEM_EXECUTE, IMAGE_SCN_MEM_READ, IMAGE_SCN_MEM_WRITE
0
UPX1
0x00193000
0x00054000
0x00053C00
IMAGE_SCN_CNT_INITIALIZED_DATA, IMAGE_SCN_MEM_EXECUTE, IMAGE_SCN_MEM_READ, IMAGE_SCN_MEM_WRITE
7.9361
.rsrc
0x001E7000
0x00112000
0x00111400
IMAGE_SCN_CNT_INITIALIZED_DATA, IMAGE_SCN_MEM_READ, IMAGE_SCN_MEM_WRITE
6.79687

Resources

Title
Entropy
Size
Codepage
Language
Type
1
5.32366
1444
Latin 1 / Western European
German - Germany
RT_MANIFEST
4
3.75291
9640
Latin 1 / Western European
English - United Kingdom
RT_ICON
7
3.34702
1428
Latin 1 / Western European
English - United Kingdom
RT_STRING
8
3.2817
1674
Latin 1 / Western European
English - United Kingdom
RT_STRING
9
3.28849
1168
Latin 1 / Western European
English - United Kingdom
RT_STRING
10
3.28373
1532
Latin 1 / Western European
English - United Kingdom
RT_STRING
11
3.26322
1628
Latin 1 / Western European
English - United Kingdom
RT_STRING
12
3.25812
1126
Latin 1 / Western European
English - United Kingdom
RT_STRING
99
2.0815
20
Latin 1 / Western European
English - United Kingdom
RT_GROUP_ICON
166
2.68292
80
Latin 1 / Western European
English - United Kingdom
RT_MENU

Imports

ADVAPI32.dll
COMCTL32.dll
COMDLG32.dll
GDI32.dll
IPHLPAPI.DLL
KERNEL32.DLL
MPR.dll
OLEAUT32.dll
PSAPI.DLL
SHELL32.dll
No data.
screenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshot
All screenshots are available in the full report
All screenshots are available in the full report
Total processes
154
Monitored processes
106
Malicious processes
59
Suspicious processes
11

Behavior graph

Click at the process to see the details
drop and start start drop and start drop and start drop and start drop and start drop and start drop and start drop and start drop and start drop and start drop and start drop and start drop and start drop and start adware.exe dmr_72.exe wcinstaller.exe webcompanioninstaller.exe operasetup.exe operasetup.exe operasetup.exe no specs operasetup.exe operasetup.exe opera_1218_int_setup_x64.exe sc.exe no specs sc.exe no specs sc.exe no specs cmd.exe no specs netsh.exe no specs webcompanion.exe lavasoft.wcassistant.winservice.exe cmd.exe no specs netsh.exe no specs csc.exe cvtres.exe no specs _sfx.exe assistant_installer.exe assistant_installer.exe ad-aware web companion.exe no specs chrome.exe chrome.exe no specs chrome.exe no specs chrome.exe no specs chrome.exe chrome.exe no specs chrome.exe no specs chrome.exe no specs chrome.exe no specs chrome.exe no specs installer.exe installer.exe chrome.exe no specs chrome.exe no specs chrome.exe no specs chrome.exe no specs chrome.exe no specs assistant_installer.exe assistant_installer.exe assistant_installer.exe assistant_installer.exe browser_assistant.exe browser_assistant.exe launcher.exe no specs launcher.exe no specs launcher.exe no specs webcompanion.exe unsecapp.exe no specs presentationfontcache.exe no specs launcher.exe no specs opera.exe opera_crashreporter.exe opera.exe opera.exe opera.exe opera.exe opera.exe opera.exe opera.exe opera.exe opera.exe no specs opera.exe opera.exe opera.exe opera.exe no specs opera.exe opera.exe no specs opera.exe opera.exe opera.exe opera.exe opera.exe opera_autoupdate.exe launcher.exe opera.exe opera.exe opera.exe opera_autoupdate.exe opera.exe opera.exe opera.exe opera.exe opera.exe opera.exe opera.exe opera.exe opera.exe opera.exe opera.exe opera.exe installer.exe opera.exe opera_autoupdate.exe opera_autoupdate.exe no specs opera.exe opera.exe opera.exe opera.exe opera_autoupdate.exe opera_autoupdate.exe adware.exe no specs

Process information

PID
CMD
Path
Indicators
Parent process
184"C:\Program Files\Opera\71.0.3770.228\opera.exe" --type=renderer --field-trial-handle=1112,13139653042553484088,13785452427808141463,131072 --lang=en-US --extension-process --enable-auto-reload --with-feature:installer-experiment-test=off --with-feature:installer-use-minimal-package=off --device-scale-factor=1 --num-raster-threads=2 --enable-main-frame-before-activation --renderer-client-id=12 --no-v8-untrusted-code-mitigations --mojo-platform-channel-handle=2520 /prefetch:1C:\Program Files\Opera\71.0.3770.228\opera.exe
opera.exe
User:
admin
Company:
Opera Software
Integrity Level:
LOW
Description:
Opera Internet Browser
Exit code:
0
Version:
71.0.3770.228
Modules
Images
c:\program files\opera\71.0.3770.228\opera.exe
c:\systemroot\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\program files\opera\71.0.3770.228\opera_elf.dll
c:\windows\system32\shell32.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\shlwapi.dll
c:\windows\system32\gdi32.dll
c:\windows\system32\user32.dll
316"C:\Users\admin\AppData\Local\Temp\DMR\Downloads\152e221a8bef8d2d13c58f995563a1a1\107f83e299c4ea15fe7b1a3fc055b7ec\OperaSetup.exe" --silent --allusers=0 --otd="utm.medium:pb,utm.source:chipde,utm.campaign:chipde-installer-ie" --launchopera=0 --launchopera-on-os-start=1 C:\Users\admin\AppData\Local\Temp\DMR\Downloads\152e221a8bef8d2d13c58f995563a1a1\107f83e299c4ea15fe7b1a3fc055b7ec\OperaSetup.exe
dmr_72.exe
User:
admin
Company:
Opera Software
Integrity Level:
HIGH
Description:
Opera Installer
Exit code:
0
Version:
71.0.3770.228
Modules
Images
c:\users\admin\appdata\local\temp\dmr\downloads\152e221a8bef8d2d13c58f995563a1a1\107f83e299c4ea15fe7b1a3fc055b7ec\operasetup.exe
c:\systemroot\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\winsxs\x86_microsoft.windows.common-controls_6595b64144ccf1df_6.0.7601.17514_none_41e6975e2bd6f2b2\comctl32.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\gdi32.dll
c:\windows\system32\user32.dll
c:\windows\system32\lpk.dll
c:\windows\system32\usp10.dll
372"C:\Program Files\Lavasoft\Web Companion\Application\Ad-Aware Web Companion.exe" {0633EE93-D776-472f-A0FF-E1416B8B2E3A}C:\Program Files\Lavasoft\Web Companion\Application\Ad-Aware Web Companion.exeWebCompanion.exe
User:
admin
Company:
Integrity Level:
HIGH
Description:
Ad-Aware Web Companion.exe
Exit code:
0
Version:
6.0.2270.4122
Modules
Images
c:\program files\lavasoft\web companion\application\ad-aware web companion.exe
c:\systemroot\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\user32.dll
c:\windows\system32\gdi32.dll
c:\windows\system32\lpk.dll
c:\windows\system32\usp10.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\ole32.dll
532"C:\Program Files\Opera\71.0.3770.228\opera.exe" --type=renderer --field-trial-handle=1112,13139653042553484088,13785452427808141463,131072 --lang=en-US --enable-auto-reload --with-feature:installer-experiment-test=off --with-feature:installer-use-minimal-package=off --device-scale-factor=1 --num-raster-threads=2 --enable-main-frame-before-activation --renderer-client-id=17 --no-v8-untrusted-code-mitigations --mojo-platform-channel-handle=2788 /prefetch:1C:\Program Files\Opera\71.0.3770.228\opera.exeopera.exe
User:
admin
Company:
Opera Software
Integrity Level:
LOW
Description:
Opera Internet Browser
Exit code:
0
Version:
71.0.3770.228
Modules
Images
c:\program files\opera\71.0.3770.228\opera.exe
c:\systemroot\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\program files\opera\71.0.3770.228\opera_elf.dll
c:\windows\system32\shell32.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\shlwapi.dll
c:\windows\system32\gdi32.dll
c:\windows\system32\user32.dll
540"C:\Program Files\Opera\71.0.3770.228\opera.exe" --type=utility --utility-sub-type=audio.mojom.AudioService --field-trial-handle=1112,13139653042553484088,13785452427808141463,131072 --lang=en-US --service-sandbox-type=audio --enable-quic --with-feature:installer-experiment-test=off --with-feature:installer-use-minimal-package=off --mojo-platform-channel-handle=3036 /prefetch:8C:\Program Files\Opera\71.0.3770.228\opera.exe
opera.exe
User:
admin
Company:
Opera Software
Integrity Level:
MEDIUM
Description:
Opera Internet Browser
Exit code:
0
Version:
71.0.3770.228
Modules
Images
c:\program files\opera\71.0.3770.228\opera.exe
c:\systemroot\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\program files\opera\71.0.3770.228\opera_elf.dll
c:\windows\system32\shell32.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\shlwapi.dll
c:\windows\system32\gdi32.dll
c:\windows\system32\user32.dll
580"C:\Program Files\Opera\71.0.3770.228\opera_crashreporter.exe" --type=crashpad-handler /prefetch:7 --monitor-self-annotation=ptype=crashpad-handler "--database=C:\Users\admin\AppData\Roaming\Opera Software\Opera Stable\Crash Reports" "--crash-count-file=C:\Users\admin\AppData\Roaming\Opera Software\Opera Stable\crash_count.txt" --url=https://crashstats-collector.opera.com/collector/submit --annotation=channel=Stable --annotation=plat=Win32 --annotation=prod=OperaDesktop --annotation=ver=71.0.3770.228 --initial-client-data=0x1e8,0x1ec,0x1f0,0x1bc,0x1f4,0x5bef44d0,0x5bef44e0,0x5bef44ecC:\Program Files\Opera\71.0.3770.228\opera_crashreporter.exe
opera.exe
User:
admin
Company:
Opera Software
Integrity Level:
MEDIUM
Description:
Opera crash-reporter
Exit code:
0
Version:
71.0.3770.228
Modules
Images
c:\program files\opera\71.0.3770.228\opera_crashreporter.exe
c:\systemroot\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\advapi32.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\sechost.dll
c:\windows\system32\rpcrt4.dll
c:\windows\system32\oleaut32.dll
c:\windows\system32\ole32.dll
608"C:\Program Files\Opera\71.0.3770.228\opera.exe" --type=utility --utility-sub-type=data_decoder.mojom.DataDecoderService --field-trial-handle=1112,13139653042553484088,13785452427808141463,131072 --lang=en-US --service-sandbox-type=utility --enable-quic --with-feature:installer-experiment-test=off --with-feature:installer-use-minimal-package=off --mojo-platform-channel-handle=4024 /prefetch:8C:\Program Files\Opera\71.0.3770.228\opera.exe
opera.exe
User:
admin
Company:
Opera Software
Integrity Level:
LOW
Description:
Opera Internet Browser
Exit code:
0
Version:
71.0.3770.228
Modules
Images
c:\program files\opera\71.0.3770.228\opera.exe
c:\systemroot\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\program files\opera\71.0.3770.228\opera_elf.dll
c:\windows\system32\shell32.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\shlwapi.dll
c:\windows\system32\gdi32.dll
c:\windows\system32\user32.dll
636.\WebCompanionInstaller.exe --partner=CH180901IE --campaign=LavasoftIEPRO0 --version=6.0.2270.4122 --prod --silent --partner=CH180901IE --search=1 --homepage=1C:\Users\admin\AppData\Local\Temp\7zS1E13.tmp\WebCompanionInstaller.exe
WcInstaller.exe
User:
admin
Company:
Lavasoft
Integrity Level:
HIGH
Description:
Web Companion
Exit code:
0
Version:
6.0.2270.4122
Modules
Images
c:\users\admin\appdata\local\temp\7zs1e13.tmp\webcompanioninstaller.exe
c:\systemroot\system32\ntdll.dll
c:\windows\system32\mscoree.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\apphelp.dll
c:\windows\apppatch\acgenral.dll
c:\windows\system32\sechost.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\rpcrt4.dll
672"C:\Program Files\Opera\71.0.3770.228\opera.exe" --type=gpu-process --field-trial-handle=1112,13139653042553484088,13785452427808141463,131072 --with-feature:installer-experiment-test=off --with-feature:installer-use-minimal-package=off --gpu-preferences=MAAAAAAAAADgAAAwAAAAAAAAAAAAAAAAAABgAAAAAAAQAAAAAAAAAAAAAAAAAAAAKAAAAAQAAAAgAAAAAAAAACgAAAAAAAAAMAAAAAAAAAA4AAAAAAAAABAAAAAAAAAAAAAAAAUAAAAQAAAAAAAAAAAAAAAGAAAAEAAAAAAAAAABAAAABQAAABAAAAAAAAAAAQAAAAYAAAA= --mojo-platform-channel-handle=1120 /prefetch:2C:\Program Files\Opera\71.0.3770.228\opera.exe
opera.exe
User:
admin
Company:
Opera Software
Integrity Level:
LOW
Description:
Opera Internet Browser
Exit code:
0
Version:
71.0.3770.228
Modules
Images
c:\program files\opera\71.0.3770.228\opera.exe
c:\systemroot\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\program files\opera\71.0.3770.228\opera_elf.dll
c:\windows\system32\shell32.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\shlwapi.dll
c:\windows\system32\gdi32.dll
c:\windows\system32\user32.dll
712"C:\Program Files\Opera\71.0.3770.228\installer.exe" --backend --initial-pid=316 --install --import-browser-data=0 --enable-stats=1 --enable-installer-stats=1 --launchopera=0 --installfolder="C:\Program Files\Opera" --profile-folder --language=en --singleprofile=0 --copyonly=0 --allusers=0 --setdefaultbrowser=1 --pintotaskbar=1 --pin-additional-shortcuts=1 --server-tracking-data=server_tracking_data --package-dir="C:\Users\admin\AppData\Local\Temp\.opera\Opera Installer Temp\opera_package_202010110515131" --session-guid=b059cb65-5a4c-4828-a9a1-f4a3861ec674 --server-tracking-blob=YjJiMmQzM2RlNGM1ZDcwNGQ0YWQ3ZTQ2YjhmNDA4MmYwZDlhMDUyOGI2Y2MyNTlhYmE2ZmNiZmVjOWYxMmIwNjp7ImNvdW50cnkiOiJMViIsImluc3RhbGxlcl9uYW1lIjoiT3BlcmFTZXR1cC5leGUiLCJwcm9kdWN0Ijoib3BlcmEiLCJxdWVyeSI6Ii9vcGVyYS9zdGFibGUvd2luZG93cz91dG1fc291cmNlPWNoaXBkZSZ1dG1fbWVkaXVtPXBiJnV0bV9jYW1wYWlnbj1jaGlwZGUtaW5zdGFsbGVyIiwidGltZXN0YW1wIjoiMTYwMjM4OTcxMC4yMDE2IiwidXRtIjp7ImNhbXBhaWduIjoiY2hpcGRlLWluc3RhbGxlci1pZSIsIm1lZGl1bSI6InBiIiwic291cmNlIjoiY2hpcGRlIn0sInV1aWQiOiJjM2E2MzUzYy04ZGJhLTQwZjktYTgyZS1hYjcwYmU4NTM0NTkifQ== --silent --launchopera-on-os-start --desktopshortcut=1 --install-subfolder=71.0.3770.228C:\Program Files\Opera\71.0.3770.228\installer.exe
OperaSetup.exe
User:
admin
Company:
Opera Software
Integrity Level:
HIGH
Description:
Opera Installer
Exit code:
0
Version:
71.0.3770.228
Modules
Images
c:\program files\opera\71.0.3770.228\installer.exe
c:\systemroot\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\user32.dll
c:\windows\system32\gdi32.dll
c:\windows\system32\lpk.dll
c:\windows\system32\usp10.dll
c:\windows\system32\msvcrt.dll
c:\windows\winsxs\x86_microsoft.windows.common-controls_6595b64144ccf1df_6.0.7601.17514_none_41e6975e2bd6f2b2\comctl32.dll
Total events
22 557
Read events
21 619
Write events
918
Delete events
20

Modification events

(PID) Process:(2612) ADWARE.exeKey:HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap
Operation:writeName:UNCAsIntranet
Value:
0
(PID) Process:(2612) ADWARE.exeKey:HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap
Operation:writeName:AutoDetect
Value:
1
(PID) Process:(1748) dmr_72.exeKey:HKEY_CURRENT_USER\Software\OCS
Operation:writeName:CID
Value:
a549e7b0-f8fb-4e9e-a74d-c7f7fe121563
(PID) Process:(1748) dmr_72.exeKey:HKEY_CURRENT_USER\Software\OCS
Operation:writeName:PID
Value:
chipderedesign
(PID) Process:(1748) dmr_72.exeKey:HKEY_CURRENT_USER\Software\OCS
Operation:writeName:lastPID
Value:
chipderedesign
(PID) Process:(1748) dmr_72.exeKey:HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Tracing\dmr_72_RASAPI32
Operation:writeName:EnableFileTracing
Value:
0
(PID) Process:(1748) dmr_72.exeKey:HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Tracing\dmr_72_RASAPI32
Operation:writeName:EnableConsoleTracing
Value:
0
(PID) Process:(1748) dmr_72.exeKey:HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Tracing\dmr_72_RASAPI32
Operation:writeName:FileTracingMask
Value:
4294901760
(PID) Process:(1748) dmr_72.exeKey:HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Tracing\dmr_72_RASAPI32
Operation:writeName:ConsoleTracingMask
Value:
4294901760
(PID) Process:(1748) dmr_72.exeKey:HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Tracing\dmr_72_RASAPI32
Operation:writeName:MaxFileSize
Value:
1048576
Executable files
141
Suspicious files
240
Text files
963
Unknown types
99

Dropped files

PID
Process
Filename
Type
1748dmr_72.exeC:\Users\admin\AppData\Local\Temp\CabFD3D.tmp
MD5:
SHA256:
1748dmr_72.exeC:\Users\admin\AppData\Local\Temp\TarFD3E.tmp
MD5:
SHA256:
1748dmr_72.exeC:\Users\admin\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\PO2HN1X2\main[1].csstext
MD5:
SHA256:
1748dmr_72.exeC:\Users\admin\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\PO2HN1X2\pic[1].gif
MD5:
SHA256:
1748dmr_72.exeC:\Users\admin\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\6Z2BCOUL\progress[1].htmhtm
MD5:
SHA256:
1748dmr_72.exeC:\Users\admin\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\78RFYB7Z\jquery.corner[1].jstext
MD5:
SHA256:
1748dmr_72.exeC:\Users\admin\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\78RFYB7Z\kasper-progresspg-ongrey-en[1].gifimage
MD5:
SHA256:
1748dmr_72.exeC:\Users\admin\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\6Z2BCOUL\bg-icon-speedometer[1].pngimage
MD5:
SHA256:
1748dmr_72.exeC:\Users\admin\AppData\LocalLow\Microsoft\CryptnetUrlCache\MetaData\B398B80134F72209547439DB21AB308D_592839A8569F831D0F2306AE4BB5C24Bbinary
MD5:
SHA256:
1748dmr_72.exeC:\Users\admin\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\B6QGX7LP\background%20progressad[1].gifimage
MD5:
SHA256:
Download PCAP, analyze network streams, HTTP content and a lot more at the full report
HTTP(S) requests
83
TCP/UDP connections
117
DNS requests
72
Threats
12

HTTP requests

PID
Process
Method
HTTP Code
IP
URL
CN
Type
Size
Reputation
1748
dmr_72.exe
GET
200
148.251.213.132:80
http://api.chip-secured-download.de/dotnet/com
DE
text
24 b
malicious
1748
dmr_72.exe
GET
200
148.251.213.132:80
http://api.chip-secured-download.de/geoip/geoip.php?ip=3137362e3139392e3135312e313935&givezip=true
DE
text
7 b
malicious
1748
dmr_72.exe
GET
200
148.251.213.132:80
http://api.chip-secured-download.de/track/uac.php?clientid=a549e7b0-f8fb-4e9e-a74d-c7f7fe121563&cid=56269414&pid=chipderedesign&source=mwchk&setupid=fcb4fd7f2fd843e782da1aaa665f1fc2&langcountry=en-US&state=WithoutUAC
DE
text
24 b
malicious
1748
dmr_72.exe
GET
200
148.251.213.132:80
http://api2.chip-secured-download.de/newbrandmachine/chipderedesign?cid=56269414&scid=&headline1=4F706572612031322E3138202836342042697429&headline2=434849502D444F574E4C4F4144&euid=316261396430656535346664373564343638346634636536&icon=68747470733A2F2F7777772E636869702E64652F69692F312F352F362F382F302F382F372F372F6F706572612D373333353263643439653338616138332E6A7067&screenshot=68747470733A2F2F7777772E636869702E64652F69692F312F352F362F382F302F382F372F372F6F706572612D653433356363643964326462373063642E6A7067&MetaRating=33
DE
binary
138 Kb
malicious
1748
dmr_72.exe
GET
200
148.251.213.132:80
http://api.chip-secured-download.de/downloaderContent/progress.php?pid=chipderedesign&cid=56269414&sid=fcb4fd7f2fd843e782da1aaa665f1fc2&appname=4F706572612031322E3138202836342042697429&uid=a549e7b0-f8fb-4e9e-a74d-c7f7fe121563&scid=&source=mwchk&language=en-lv&piddata=&uaexe=696578706C6F72652E657865&Camplist=30396463326630336463346232393737316637656462316562613566643564333B3837363665663961313363373539613266373735396338613362386433356564
DE
htm
1.92 Kb
malicious
1748
dmr_72.exe
GET
200
148.251.213.132:80
http://api2.chip-secured-download.de/downloaderContent/img/kasper-progresspg-ongrey-en.gif
DE
image
2.30 Kb
malicious
1748
dmr_72.exe
GET
200
148.251.213.132:80
http://api.chip-secured-download.de/downloaderContent/main.css?v=1461939270
DE
text
6.02 Kb
malicious
1748
dmr_72.exe
GET
200
148.251.213.132:80
http://api.chip-secured-download.de/downloaderContent/jquery.corner.js
DE
text
94 b
malicious
1748
dmr_72.exe
GET
200
148.251.213.132:80
http://api.chip-secured-download.de/downloaderContent/jquery.js
DE
text
102 Kb
malicious
1748
dmr_72.exe
GET
200
148.251.213.132:80
http://api.chip-secured-download.de/downloaderContent/img/bg-progressbar.jpg
DE
image
17.3 Kb
malicious
Download PCAP, analyze network streams, HTTP content and a lot more at the full report

Connections

PID
Process
IP
Domain
ASN
CN
Reputation
1748
dmr_72.exe
148.251.213.132:80
api.chip-secured-download.de
Hetzner Online GmbH
DE
malicious
1748
dmr_72.exe
5.9.176.3:8080
ocs3.chdi-server.de
Hetzner Online GmbH
DE
malicious
1748
dmr_72.exe
5.9.198.84:80
static.chip-secured-download.de
Hetzner Online GmbH
DE
suspicious
1748
dmr_72.exe
185.33.220.145:443
secure.adnxs.com
AppNexus, Inc
unknown
1748
dmr_72.exe
93.184.220.29:80
ocsp.digicert.com
MCI Communications Services, Inc. d/b/a Verizon Business
US
whitelisted
1748
dmr_72.exe
2.16.186.130:443
downloaderapi.chip.de
Akamai International B.V.
whitelisted
1748
dmr_72.exe
2.16.186.168:443
downloaderapi.chip.de
Akamai International B.V.
whitelisted
1748
dmr_72.exe
2.16.186.130:80
downloaderapi.chip.de
Akamai International B.V.
whitelisted
1748
dmr_72.exe
185.26.182.111:443
net.geo.opera.com
Opera Software AS
whitelisted
1748
dmr_72.exe
104.17.177.102:80
webcompanion.com
Cloudflare Inc
US
shared

DNS requests

Domain
IP
Reputation
api.chip-secured-download.de
  • 148.251.213.132
unknown
ocs3.chdi-server.de
  • 5.9.176.3
unknown
api2.chip-secured-download.de
  • 148.251.213.132
unknown
static.chip-secured-download.de
  • 5.9.198.84
  • 176.9.97.245
suspicious
secure.adnxs.com
  • 185.33.220.145
  • 185.33.221.88
  • 185.33.221.15
  • 185.33.220.240
  • 185.33.221.89
  • 185.33.221.53
  • 185.33.220.241
  • 185.33.221.87
whitelisted
ocsp.digicert.com
  • 93.184.220.29
whitelisted
downloaderapi.chip.de
  • 2.16.186.130
  • 2.16.186.168
whitelisted
r.chip.de
  • 2.16.186.168
  • 2.16.186.130
whitelisted
net.geo.opera.com
  • 185.26.182.111
  • 185.26.182.112
whitelisted
webcompanion.com
  • 104.17.177.102
  • 104.17.178.102
malicious

Threats

PID
Process
Class
Message
1748
dmr_72.exe
Misc activity
ADWARE [PTsecurity] DownloadSponsor outbound artifact m1
1748
dmr_72.exe
Misc activity
ADWARE [PTsecurity] DownloadSponsor inbound artifact m1
1748
dmr_72.exe
Misc activity
ADWARE [PTsecurity] DownloadSponsor inbound artifact m1
1748
dmr_72.exe
A Network Trojan was detected
MALWARE [PTsecurity] DownloadSponsor img_welcome PNG artifact
1748
dmr_72.exe
Misc activity
ADWARE [PTsecurity] DownloadSponsor inbound artifact m1
1748
dmr_72.exe
Potential Corporate Privacy Violation
ET POLICY PE EXE or DLL Windows file download HTTP
1748
dmr_72.exe
Potentially Bad Traffic
ET INFO Executable Retrieved With Minimal HTTP Headers - Potential Second Stage Download
1748
dmr_72.exe
Potential Corporate Privacy Violation
ET POLICY PE EXE or DLL Windows file download HTTP
1748
dmr_72.exe
Potentially Bad Traffic
ET INFO Executable Retrieved With Minimal HTTP Headers - Potential Second Stage Download
1748
dmr_72.exe
Misc activity
ET INFO EXE - Served Attached HTTP
1 ETPRO signatures available at the full report
Process
Message
WebCompanionInstaller.exe
Detecting windows culture
WebCompanionInstaller.exe
10/11/2020 5:15:17 AM :-> Starting installer 6.0.2270.4122 with: .\WebCompanionInstaller.exe --partner=CH180901IE --campaign=LavasoftIEPRO0 --version=6.0.2270.4122 --prod --silent --partner=CH180901IE --search=1 --homepage=1, Run as admin: True
WebCompanionInstaller.exe
Preparing for installing Web Companion
WebCompanionInstaller.exe
10/11/2020 5:15:18 AM :-> Machine Id and Install Id has been generated
WebCompanionInstaller.exe
10/11/2020 5:15:18 AM :-> Generating Machine and Install Id ...
WebCompanionInstaller.exe
10/11/2020 5:15:18 AM :-> Antivirus not detected
WebCompanionInstaller.exe
10/11/2020 5:15:18 AM :-> Checking prerequisites ...
WebCompanionInstaller.exe
10/11/2020 5:15:19 AM :-> vm_check False
WebCompanionInstaller.exe
10/11/2020 5:15:19 AM :-> reg_check :False
WebCompanionInstaller.exe
10/11/2020 5:15:19 AM :-> Installed .Net framework is V40