File name:

Setup_WebCompanion.exe

Full analysis: https://app.any.run/tasks/4f624e98-4186-46f1-a867-31e102c6d4ed
Verdict: Malicious activity
Threats:

Adware is a form of malware that targets users with unwanted advertisements, often disrupting their browsing experience. It typically infiltrates systems through software bundling, malicious websites, or deceptive downloads. Once installed, it may track user activity, collect sensitive data, and display intrusive ads, including pop-ups or banners. Some advanced adware variants can bypass security measures and establish persistence on devices, making removal challenging. Additionally, adware can create vulnerabilities that other malware can exploit, posing a significant risk to user privacy and system security.

Analysis date: December 10, 2025, 18:20:45
OS: Windows 7 Professional Service Pack 1 (build: 7601, 32 bit)
Tags:
adware
adaware
webcompanion
tool
arch-scr
Indicators:
MIME: application/vnd.microsoft.portable-executable
File info: PE32 executable (GUI) Intel 80386, for MS Windows, 5 sections
MD5:

BAAAE88074273E75505C073215CF24EE

SHA1:

8FC218E1E6F1FA103048D091671773BB4D358440

SHA256:

6DE25D09F4E405BD52E81D21C6DB3C080A7CE49F907CF335DEF0E2728BD3104D

SSDEEP:

12288:VG5knZfFKefG90j92I6qg/hZL4kIwGoqeBzY//OJ1:VG50ZfFKYGw2IVg5ZL4klGg1

ANY.RUN is an interactive service which provides full access to the guest system. Information in this report could be distorted by user actions and is provided for user acknowledgement as it is. ANY.RUN does not guarantee maliciousness or safety of the content.
  • MALICIOUS

    • ADAWARE has been detected (SURICATA)

      • WebCompanion.exe (PID: 2224)
    • Changes the autorun value in the registry

      • WebCompanion.exe (PID: 2024)
      • WebCompanion.exe (PID: 2224)
    • Changes settings of System certificates

      • WebCompanionInstaller.exe (PID: 2744)
  • SUSPICIOUS

    • Executable content was dropped or overwritten

      • Setup_WebCompanion.exe (PID: 3504)
      • WebCompanionInstaller.exe (PID: 3672)
    • Searches for installed software

      • WebCompanionInstaller.exe (PID: 3672)
      • WebCompanion.exe (PID: 2224)
      • WebCompanion.exe (PID: 2024)
      • WebCompanionInstaller.exe (PID: 2744)
    • Reads settings of System Certificates

      • WebCompanionInstaller.exe (PID: 3672)
      • WebCompanion.exe (PID: 2224)
      • WebCompanion.exe (PID: 2024)
      • WebCompanionInstaller.exe (PID: 2744)
    • Reads the Internet Settings

      • WebCompanionInstaller.exe (PID: 3672)
      • WebCompanion.exe (PID: 2224)
      • WebCompanion.exe (PID: 2024)
      • WebCompanionInstaller.exe (PID: 2744)
    • Drops 7-zip archiver for unpacking

      • WebCompanionInstaller.exe (PID: 3672)
    • Process drops legitimate windows executable

      • WebCompanionInstaller.exe (PID: 3672)
    • The process drops C-runtime libraries

      • WebCompanionInstaller.exe (PID: 3672)
    • Reads security settings of Internet Explorer

      • WebCompanionInstaller.exe (PID: 3672)
      • WebCompanion.exe (PID: 2224)
      • WebCompanion.exe (PID: 2024)
    • Changes internet zones settings

      • WebCompanionInstaller.exe (PID: 3672)
    • Starts CMD.EXE for commands execution

      • WebCompanionInstaller.exe (PID: 3672)
    • Suspicious use of NETSH.EXE

      • cmd.exe (PID: 1464)
    • Access to an unwanted program domain was detected

      • WebCompanion.exe (PID: 2224)
    • The process verifies whether the antivirus software is installed

      • WebCompanion.exe (PID: 2224)
      • WebCompanion.exe (PID: 2024)
    • There is functionality for taking screenshot (YARA)

      • WebCompanion.exe (PID: 2024)
    • Adds/modifies Windows certificates

      • WebCompanionInstaller.exe (PID: 2744)
  • INFO

    • Reads the computer name

      • WebCompanionInstaller.exe (PID: 3672)
      • WebCompanion.exe (PID: 2224)
      • WebCompanion.exe (PID: 2024)
      • WebCompanionInstaller.exe (PID: 2744)
    • Checks supported languages

      • Setup_WebCompanion.exe (PID: 3504)
      • WebCompanionInstaller.exe (PID: 3672)
      • WebCompanion.exe (PID: 2224)
      • WebCompanion.exe (PID: 2024)
      • WebCompanionInstaller.exe (PID: 2744)
    • The sample compiled with english language support

      • Setup_WebCompanion.exe (PID: 3504)
      • WebCompanionInstaller.exe (PID: 3672)
    • Reads Environment values

      • WebCompanionInstaller.exe (PID: 3672)
      • WebCompanion.exe (PID: 2224)
      • WebCompanion.exe (PID: 2024)
      • WebCompanionInstaller.exe (PID: 2744)
    • Reads the machine GUID from the registry

      • WebCompanionInstaller.exe (PID: 3672)
      • WebCompanion.exe (PID: 2224)
      • WebCompanion.exe (PID: 2024)
      • WebCompanionInstaller.exe (PID: 2744)
    • Create files in a temporary directory

      • Setup_WebCompanion.exe (PID: 3504)
      • WebCompanionInstaller.exe (PID: 3672)
    • Disables trace logs

      • WebCompanionInstaller.exe (PID: 3672)
      • WebCompanion.exe (PID: 2224)
      • WebCompanion.exe (PID: 2024)
      • WebCompanionInstaller.exe (PID: 2744)
    • Creates files or folders in the user directory

      • WebCompanionInstaller.exe (PID: 3672)
      • WebCompanion.exe (PID: 2224)
      • WebCompanion.exe (PID: 2024)
    • SQLite executable

      • WebCompanionInstaller.exe (PID: 3672)
    • Creates a software uninstall entry

      • WebCompanionInstaller.exe (PID: 3672)
    • Creates files in the program directory

      • WebCompanion.exe (PID: 2224)
      • WebCompanionInstaller.exe (PID: 2744)
    • Launching a file from a Registry key

      • WebCompanion.exe (PID: 2224)
      • WebCompanion.exe (PID: 2024)
    • Reads product name

      • WebCompanion.exe (PID: 2224)
      • WebCompanion.exe (PID: 2024)
    • Application launched itself

      • chrome.exe (PID: 1856)
    • ADAWAREWEBCOMPANION mutex has been found

      • WebCompanion.exe (PID: 2024)
Find more information about signature artifacts and mapping to MITRE ATT&CK™ MATRIX at the full report
No Malware configuration.

TRiD

.exe | InstallShield setup (33)
.exe | Win32 Executable MS Visual C++ (generic) (23.9)
.exe | Win64 Executable (generic) (21.2)
.scr | Windows screen saver (10)
.dll | Win32 Dynamic Link Library (generic) (5)

EXIF

EXE

MachineType: Intel 386 or later, and compatibles
TimeStamp: 2011:04:18 18:54:06+00:00
ImageFileCharacteristics: No relocs, Executable, No line numbers, No symbols, Large address aware, 32-bit
PEType: PE32
LinkerVersion: 6
CodeSize: 104448
InitializedDataSize: 60416
UninitializedDataSize: -
EntryPoint: 0x148d4
OSVersion: 4
ImageVersion: -
SubsystemVersion: 4
Subsystem: Windows GUI
FileVersionNumber: 11.904.0.689
ProductVersionNumber: 11.904.0.689
FileFlagsMask: 0x003f
FileFlags: (none)
FileOS: Windows NT 32-bit
ObjectFileType: Executable application
FileSubtype: -
LanguageCode: English (U.S.)
CharacterSet: Unicode
FileVersion: 11.904.0.689
ProductVersion: 11.904.0.689
CompanyName: Lavasoft
FileDescription: Web Companion Installer
InternalName: Installer.exe
LegalCopyright: c Lavasoft Limited. All Rights Reserved.
OriginalFileName: Installer.exe
ProductName: Web Companion Installer
No data.
screenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshot
All screenshots are available in the full report
All screenshots are available in the full report
Total processes
72
Monitored processes
25
Malicious processes
4
Suspicious processes
1

Behavior graph

Click at the process to see the details
start setup_webcompanion.exe webcompanioninstaller.exe cmd.exe no specs netsh.exe no specs #ADAWARE webcompanion.exe webcompanion.exe chrome.exe chrome.exe no specs chrome.exe no specs chrome.exe chrome.exe no specs chrome.exe no specs chrome.exe no specs chrome.exe no specs chrome.exe no specs chrome.exe no specs chrome.exe no specs webcompanioninstaller.exe chrome.exe no specs chrome.exe no specs chrome.exe no specs chrome.exe no specs chrome.exe no specs chrome.exe no specs chrome.exe no specs

Process information

PID
CMD
Path
Indicators
Parent process
892"C:\Program Files\Google\Chrome\Application\chrome.exe" --type=utility --utility-sub-type=unzip.mojom.Unzipper --lang=en-US --service-sandbox-type=service --disable-quic --mojo-platform-channel-handle=3716 --field-trial-handle=1224,i,12890370449850471694,17612920667059211280,131072 /prefetch:8C:\Program Files\Google\Chrome\Application\chrome.exechrome.exe
User:
admin
Company:
Google LLC
Integrity Level:
LOW
Description:
Google Chrome
Exit code:
0
Version:
109.0.5414.120
Modules
Images
c:\program files\google\chrome\application\chrome.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\program files\google\chrome\application\109.0.5414.120\chrome_elf.dll
c:\windows\system32\version.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\api-ms-win-core-synch-l1-2-0.dll
c:\windows\system32\advapi32.dll
c:\windows\system32\sechost.dll
1176"C:\Program Files\Google\Chrome\Application\chrome.exe" --type=utility --utility-sub-type=network.mojom.NetworkService --lang=en-US --service-sandbox-type=none --disable-quic --mojo-platform-channel-handle=1416 --field-trial-handle=1224,i,12890370449850471694,17612920667059211280,131072 /prefetch:8C:\Program Files\Google\Chrome\Application\chrome.exe
chrome.exe
User:
admin
Company:
Google LLC
Integrity Level:
MEDIUM
Description:
Google Chrome
Version:
109.0.5414.120
Modules
Images
c:\program files\google\chrome\application\chrome.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\program files\google\chrome\application\109.0.5414.120\chrome_elf.dll
c:\windows\system32\version.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\api-ms-win-core-synch-l1-2-0.dll
c:\windows\system32\advapi32.dll
c:\windows\system32\sechost.dll
1368"C:\Program Files\Google\Chrome\Application\chrome.exe" --type=gpu-process --gpu-preferences=UAAAAAAAAADgAAAYAAAAAAAAAAAAAAAAAABgAAAAAAAwAAAAAAAAAAAAAAAQAAAAAAAAAAAAAAAAAAAAAAAAAEgAAAAAAAAASAAAAAAAAAAYAAAAAgAAABAAAAAAAAAAGAAAAAAAAAAQAAAAAAAAAAAAAAAOAAAAEAAAAAAAAAABAAAADgAAAAgAAAAAAAAACAAAAAAAAAA= --mojo-platform-channel-handle=1096 --field-trial-handle=1224,i,12890370449850471694,17612920667059211280,131072 /prefetch:2C:\Program Files\Google\Chrome\Application\chrome.exechrome.exe
User:
admin
Company:
Google LLC
Integrity Level:
LOW
Description:
Google Chrome
Exit code:
0
Version:
109.0.5414.120
Modules
Images
c:\program files\google\chrome\application\chrome.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\program files\google\chrome\application\109.0.5414.120\chrome_elf.dll
c:\windows\system32\version.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\api-ms-win-core-synch-l1-2-0.dll
c:\windows\system32\advapi32.dll
c:\windows\system32\sechost.dll
1372"C:\Program Files\Google\Chrome\Application\chrome.exe" --type=renderer --extension-process --lang=en-US --device-scale-factor=1 --num-raster-threads=2 --enable-main-frame-before-activation --renderer-client-id=7 --mojo-platform-channel-handle=3104 --field-trial-handle=1224,i,12890370449850471694,17612920667059211280,131072 /prefetch:1C:\Program Files\Google\Chrome\Application\chrome.exechrome.exe
User:
admin
Company:
Google LLC
Integrity Level:
LOW
Description:
Google Chrome
Exit code:
0
Version:
109.0.5414.120
Modules
Images
c:\program files\google\chrome\application\chrome.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\program files\google\chrome\application\109.0.5414.120\chrome_elf.dll
c:\windows\system32\version.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\api-ms-win-core-synch-l1-2-0.dll
c:\windows\system32\advapi32.dll
c:\windows\system32\sechost.dll
1464"C:\Windows\System32\cmd.exe" /C netsh http add urlacl url=http://+:9007/ user=EveryoneC:\Windows\System32\cmd.exeWebCompanionInstaller.exe
User:
admin
Company:
Microsoft Corporation
Integrity Level:
MEDIUM
Description:
Windows Command Processor
Exit code:
1
Version:
6.1.7601.17514 (win7sp1_rtm.101119-1850)
Modules
Images
c:\windows\system32\cmd.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\winbrand.dll
c:\windows\system32\user32.dll
c:\windows\system32\gdi32.dll
c:\windows\system32\lpk.dll
c:\windows\system32\usp10.dll
1856"C:\Program Files\Google\Chrome\Application\chrome.exe" https://webcompanion.com/en/install.php?partner=IN220101&campaign=16075236377C:\Program Files\Google\Chrome\Application\chrome.exe
WebCompanionInstaller.exe
User:
admin
Company:
Google LLC
Integrity Level:
MEDIUM
Description:
Google Chrome
Version:
109.0.5414.120
Modules
Images
c:\program files\google\chrome\application\chrome.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\program files\google\chrome\application\109.0.5414.120\chrome_elf.dll
c:\windows\system32\version.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\api-ms-win-core-synch-l1-2-0.dll
c:\windows\system32\advapi32.dll
c:\windows\system32\sechost.dll
1904"C:\Program Files\Google\Chrome\Application\chrome.exe" --type=utility --utility-sub-type=storage.mojom.StorageService --lang=en-US --service-sandbox-type=service --disable-quic --mojo-platform-channel-handle=1600 --field-trial-handle=1224,i,12890370449850471694,17612920667059211280,131072 /prefetch:8C:\Program Files\Google\Chrome\Application\chrome.exechrome.exe
User:
admin
Company:
Google LLC
Integrity Level:
LOW
Description:
Google Chrome
Version:
109.0.5414.120
Modules
Images
c:\program files\google\chrome\application\chrome.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\program files\google\chrome\application\109.0.5414.120\chrome_elf.dll
c:\windows\system32\version.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\api-ms-win-core-synch-l1-2-0.dll
c:\windows\system32\advapi32.dll
c:\windows\system32\sechost.dll
2024"C:\Users\admin\AppData\Roaming\Lavasoft\Web Companion\Application\WebCompanion.exe" --afterinstall C:\Users\admin\AppData\Roaming\Lavasoft\Web Companion\Application\WebCompanion.exe
WebCompanionInstaller.exe
User:
admin
Company:
Lavasoft
Integrity Level:
MEDIUM
Description:
Web Companion
Exit code:
4294967295
Version:
11.4.0.689
Modules
Images
c:\users\admin\appdata\roaming\lavasoft\web companion\application\webcompanion.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\mscoree.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\advapi32.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\sechost.dll
c:\windows\system32\rpcrt4.dll
c:\windows\microsoft.net\framework\v4.0.30319\mscoreei.dll
2224"C:\Users\admin\AppData\Roaming\Lavasoft\Web Companion\Application\WebCompanion.exe" --install --geo= C:\Users\admin\AppData\Roaming\Lavasoft\Web Companion\Application\WebCompanion.exe
WebCompanionInstaller.exe
User:
admin
Company:
Lavasoft
Integrity Level:
MEDIUM
Description:
Web Companion
Exit code:
0
Version:
11.4.0.689
Modules
Images
c:\users\admin\appdata\roaming\lavasoft\web companion\application\webcompanion.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\mscoree.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\advapi32.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\sechost.dll
c:\windows\system32\rpcrt4.dll
c:\windows\microsoft.net\framework\v4.0.30319\mscoreei.dll
2392"C:\Program Files\Google\Chrome\Application\chrome.exe" --type=gpu-process --gpu-preferences=UAAAAAAAAADgAAAYAAAAAAAAAAAAAAAAAABgAAAAAAAwAAAAAAAAAAAAAAAQAAAAAAAAAAAAAAAAAAAAAAAAAEgAAAAAAAAASAAAAAAAAAAYAAAAAgAAABAAAAAAAAAAGAAAAAAAAAAQAAAAAAAAAAAAAAAOAAAAEAAAAAAAAAABAAAADgAAAAgAAAAAAAAACAAAAAAAAAA= --use-gl=angle --use-angle=swiftshader-webgl --mojo-platform-channel-handle=1528 --field-trial-handle=1224,i,12890370449850471694,17612920667059211280,131072 /prefetch:2C:\Program Files\Google\Chrome\Application\chrome.exechrome.exe
User:
admin
Company:
Google LLC
Integrity Level:
LOW
Description:
Google Chrome
Version:
109.0.5414.120
Modules
Images
c:\program files\google\chrome\application\chrome.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\program files\google\chrome\application\109.0.5414.120\chrome_elf.dll
c:\windows\system32\version.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\api-ms-win-core-synch-l1-2-0.dll
c:\windows\system32\advapi32.dll
c:\windows\system32\sechost.dll
Total events
24 018
Read events
23 836
Write events
179
Delete events
3

Modification events

(PID) Process:(3672) WebCompanionInstaller.exeKey:HKEY_CURRENT_USER\Software\Lavasoft\Web Companion
Operation:writeName:MachineId
Value:
8569aaff-63aa-a71d-8040-0e2571e89667
(PID) Process:(3672) WebCompanionInstaller.exeKey:HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Tracing\WebCompanionInstaller_RASAPI32
Operation:writeName:EnableFileTracing
Value:
0
(PID) Process:(3672) WebCompanionInstaller.exeKey:HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Tracing\WebCompanionInstaller_RASAPI32
Operation:writeName:EnableConsoleTracing
Value:
0
(PID) Process:(3672) WebCompanionInstaller.exeKey:HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Tracing\WebCompanionInstaller_RASAPI32
Operation:writeName:FileTracingMask
Value:
(PID) Process:(3672) WebCompanionInstaller.exeKey:HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Tracing\WebCompanionInstaller_RASAPI32
Operation:writeName:ConsoleTracingMask
Value:
(PID) Process:(3672) WebCompanionInstaller.exeKey:HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Tracing\WebCompanionInstaller_RASAPI32
Operation:writeName:MaxFileSize
Value:
1048576
(PID) Process:(3672) WebCompanionInstaller.exeKey:HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Tracing\WebCompanionInstaller_RASAPI32
Operation:writeName:FileDirectory
Value:
%windir%\tracing
(PID) Process:(3672) WebCompanionInstaller.exeKey:HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Tracing\WebCompanionInstaller_RASMANCS
Operation:writeName:EnableFileTracing
Value:
0
(PID) Process:(3672) WebCompanionInstaller.exeKey:HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Tracing\WebCompanionInstaller_RASMANCS
Operation:writeName:EnableConsoleTracing
Value:
0
(PID) Process:(3672) WebCompanionInstaller.exeKey:HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Tracing\WebCompanionInstaller_RASMANCS
Operation:writeName:FileTracingMask
Value:
Executable files
98
Suspicious files
126
Text files
83
Unknown types
0

Dropped files

PID
Process
Filename
Type
3504Setup_WebCompanion.exeC:\Users\admin\AppData\Local\Temp\7zS0BD3C65F\WebCompanionInstaller.exe.configxml
MD5:634D2D29F0ECFEE31F2D1E3C0FE6832D
SHA256:9825E2E2AACB7F01BC779101E6141F1ABFE71E23F69B1B0ED434B1F5DFF7615C
3504Setup_WebCompanion.exeC:\Users\admin\AppData\Local\Temp\7zS0BD3C65F\Newtonsoft.Json.dllexecutable
MD5:B4C13884516B327C813F7B3E7C5D8135
SHA256:B1A466D22198D9B04A8943083A08BA26336D8D9A6757F1E59A94344D368E4272
3504Setup_WebCompanion.exeC:\Users\admin\AppData\Local\Temp\7zS0BD3C65F\ja-JP\WebCompanionInstaller.resources.dllexecutable
MD5:D315FD206AAE3DF3489E7863A949E518
SHA256:C59560241CCA5D8F7CFAD2C8434CDDF366A501A3BA0DB119CB663EA3E7270DFF
3504Setup_WebCompanion.exeC:\Users\admin\AppData\Local\Temp\7zS0BD3C65F\ru-RU\WebCompanionInstaller.resources.dllexecutable
MD5:8F15E3AADB5032A2D4C677EDD2117522
SHA256:6ECE4F64535618D51F3357E8763DE232A1903BD1D6A7D338692E992E9786132D
3504Setup_WebCompanion.exeC:\Users\admin\AppData\Local\Temp\7zS0BD3C65F\pt-BR\WebCompanionInstaller.resources.dllexecutable
MD5:0BBC570FBD0304EC4BF4185D8616816B
SHA256:4B5613BD7C4AF5CFF9038DC44D63232C016CF673D0F0245B1BE0A635FC9F87AA
3504Setup_WebCompanion.exeC:\Users\admin\AppData\Local\Temp\7zS0BD3C65F\WebCompanionInstaller.exeexecutable
MD5:2376204BA2EBE92158D45FA8D7A6C9BF
SHA256:A89679885457ED266DB3C8BD50220CFBE0229BABE84BE4334EF2A01CB219D755
3504Setup_WebCompanion.exeC:\Users\admin\AppData\Local\Temp\7zS0BD3C65F\tr-TR\WebCompanionInstaller.resources.dllexecutable
MD5:ABD17C89314092FE77C41F8955D43575
SHA256:9337801ABAE112DC677763E67B976796422CCC8B998F29EDD96F1BD93E512169
3504Setup_WebCompanion.exeC:\Users\admin\AppData\Local\Temp\7zS0BD3C65F\zh-CHS\WebCompanionInstaller.resources.dllexecutable
MD5:15648622E734510A7DFB2C72888D73EB
SHA256:5A6FFB98E59C82B5EAD46D60D421886F57A11EAAEA4DF4190118FA27667828D1
3672WebCompanionInstaller.exeC:\Users\admin\AppData\Roaming\Lavasoft\Web Companion\Options\Statistics.txtbinary
MD5:72AC9054A1658A4D74A582B12BD3A28B
SHA256:20059DDE16536113916A7890F64D70CD764AD81B986572B0535BC87ECC02DD1A
3504Setup_WebCompanion.exeC:\Users\admin\AppData\Local\Temp\7zS0BD3C65F\en-US\WebCompanionInstaller.resources.dllexecutable
MD5:8D42954DD718AB37335ED0FB2D18164D
SHA256:D70F2C75A00890453EEA09DAD0A7E0B0AD0F65899B41A8D455BF7A991CAA1866
Download PCAP, analyze network streams, HTTP content and a lot more at the full report
HTTP(S) requests
15
TCP/UDP connections
74
DNS requests
87
Threats
56

HTTP requests

PID
Process
Method
HTTP Code
IP
URL
CN
Type
Size
Reputation
3672
WebCompanionInstaller.exe
GET
200
104.16.148.130:80
http://geo.lavasoft.com/
unknown
whitelisted
3672
WebCompanionInstaller.exe
GET
104.16.148.130:80
http://wcdownloadercdn.lavasoft.com/11.4.0.689/WebCompanion-11.4.0.689-prod.zip
unknown
whitelisted
2224
WebCompanion.exe
GET
200
104.16.148.130:80
http://geo.lavasoft.com/
unknown
whitelisted
2224
WebCompanion.exe
GET
200
64.18.87.81:80
http://wc-partners.lavasoft.com/Partner.svc/GetPartnerInfo?partner=IN220101
unknown
whitelisted
2224
WebCompanion.exe
GET
200
64.18.87.81:80
http://wc-partners.lavasoft.com/Partner.svc/GetPartnerInfo?partner=IN220101_wb
unknown
whitelisted
2224
WebCompanion.exe
GET
200
64.18.87.81:80
http://wc-partners.lavasoft.com/Partner.svc/GetPartnerInfo?partner=IN220101_ab
unknown
whitelisted
2224
WebCompanion.exe
GET
200
104.16.148.130:80
http://geo.lavasoft.com/
unknown
whitelisted
2224
WebCompanion.exe
GET
200
64.18.87.81:80
http://wc-partners.lavasoft.com/Partner.svc/GetPartnerInfo?partner=IN220101_ac
unknown
whitelisted
2224
WebCompanion.exe
GET
200
104.19.208.152:80
http://webcompanion.com/version_logs?json=true&version=11.4.0.689
unknown
unknown
2024
WebCompanion.exe
GET
200
104.19.208.152:80
http://webcompanion.com/version_logs?json=true&version=13.901.0.1133
unknown
unknown
Download PCAP, analyze network streams, HTTP content and a lot more at the full report

Connections

PID
Process
IP
Domain
ASN
CN
Reputation
4
System
192.168.100.255:137
Not routed
whitelisted
224.0.0.252:5355
whitelisted
4
System
192.168.100.255:138
Not routed
whitelisted
3672
WebCompanionInstaller.exe
104.16.148.130:80
geo.lavasoft.com
CLOUDFLARENET
US
whitelisted
1092
svchost.exe
224.0.0.252:5355
whitelisted
3672
WebCompanionInstaller.exe
104.16.148.130:443
geo.lavasoft.com
CLOUDFLARENET
US
whitelisted
3672
WebCompanionInstaller.exe
104.18.26.149:443
flwadw.com
CLOUDFLARENET
US
whitelisted
2224
WebCompanion.exe
104.16.148.130:80
geo.lavasoft.com
CLOUDFLARENET
US
whitelisted
2224
WebCompanion.exe
104.16.148.130:443
geo.lavasoft.com
CLOUDFLARENET
US
whitelisted
2224
WebCompanion.exe
104.18.26.149:443
flwadw.com
CLOUDFLARENET
US
whitelisted

DNS requests

Domain
IP
Reputation
google.com
  • 142.250.186.174
whitelisted
geo.lavasoft.com
  • 104.16.148.130
  • 104.16.149.130
whitelisted
featureflags.lavasoft.com
  • 104.16.148.130
  • 104.16.149.130
whitelisted
flwadw.com
  • 104.18.26.149
  • 104.18.27.149
unknown
wcdownloadercdn.lavasoft.com
  • 104.16.148.130
  • 104.16.149.130
whitelisted
wc-partners.lavasoft.com
  • 64.18.87.81
  • 64.18.87.82
whitelisted
webcompanion.com
  • 104.19.208.152
  • 104.19.159.224
unknown
clientservices.googleapis.com
  • 192.178.170.94
whitelisted
accounts.google.com
  • 108.177.15.84
whitelisted
sg-bitmask.adaware.com
  • 104.16.212.94
  • 104.16.213.94
whitelisted

Threats

PID
Process
Class
Message
Possibly Unwanted Program Detected
ADWARE [ANY.RUN] Adaware Web Companion
Possibly Unwanted Program Detected
ADWARE [ANY.RUN] Adaware Web Companion
Possibly Unwanted Program Detected
ADWARE [ANY.RUN] Adaware Web Companion
Possibly Unwanted Program Detected
ADWARE [ANY.RUN] Adaware Web Companion
Possibly Unwanted Program Detected
ADWARE [ANY.RUN] Adaware Web Companion
Possibly Unwanted Program Detected
ADWARE [ANY.RUN] Adaware Web Companion
Possibly Unwanted Program Detected
ADWARE [ANY.RUN] Adaware Web Companion
3672
WebCompanionInstaller.exe
Potentially Bad Traffic
ET HUNTING Terse Request for Zip File (GET)
Possibly Unwanted Program Detected
ADWARE [ANY.RUN] Adaware Web Companion
Possibly Unwanted Program Detected
ADWARE [ANY.RUN] Adaware Web Companion
Process
Message
WebCompanionInstaller.exe
Failed to OpenWcfHost: System.ServiceModel.AddressAccessDeniedException: HTTP could not register URL http://+:9008/webcompanion/. Your process does not have access rights to this namespace (see http://go.microsoft.com/fwlink/?LinkId=70353 for details). ---> System.Net.HttpListenerException: Access is denied at System.Net.HttpListener.AddAllPrefixes() at System.Net.HttpListener.Start() at System.ServiceModel.Channels.SharedHttpTransportManager.OnOpen() --- End of inner exception stack trace --- at System.ServiceModel.Channels.SharedHttpTransportManager.OnOpen() at System.ServiceModel.Channels.TransportManager.Open(TransportChannelListener channelListener) at System.ServiceModel.Channels.TransportManagerContainer.Open(SelectTransportManagersCallback selectTransportManagerCallback) at System.ServiceModel.Channels.TransportChannelListener.OnOpen(TimeSpan timeout) at System.ServiceModel.Channels.HttpChannelListener`1.OnOpen(TimeSpan timeout) at System.ServiceModel.Channels.CommunicationObject.Open(TimeSpan timeout) at System.ServiceModel.Dispatcher.ChannelDispatcher.OnOpen(TimeSpan timeout) at System.ServiceModel.Channels.CommunicationObject.Open(TimeSpan timeout) at System.ServiceModel.ServiceHostBase.OnOpen(TimeSpan timeout) at System.ServiceModel.Channels.CommunicationObject.Open(TimeSpan timeout) at WebCompanionInstaller.App.OpenInstallerWcfHost()
WebCompanionInstaller.exe
Detecting windows culture
WebCompanionInstaller.exe
Preparing request for featureflag: {"Geo":"DE","Partner":"IN220101","Campaign":"16075236377","InstallDate":"20251210","TriggerType":"install","TriggerEvent":"installer","Version":"11.904.0.689","featurewp":true,"featureal":true}
WebCompanionInstaller.exe
Getting response from featureflag: [{"sectionCode":"WAC","code":"WAC","configuration":"{\"Icon\": \"https://webcompanion.com/images/favicon.ico\", \"color\": \"25FFFF\", \"AppName\": \"Web Companion\", \"Settings\": [\"WCAutoUpdate\", \"EnableGranularity\", \"PostRunV2Action\", \"PostRunTimerAction\", \"EnableTelemetryScan\", \"EnableWebProtection\", \"EnableDynamicNotification\"], \"darkmode\": false, \"CompanyName\": \"Lavasoft\", \"ConfigVersion\": \"v1\", \"CurrentVersion\": \"9.3.0\", \"IsNewUpdaterService\": true}","targetId":301},{"sectionCode":"WFAI","code":"WCP","configuration":"{\"Version\": \"3.0.2.12\", \"FilePath\": \"https://rt.webcompanion.com/notifications/download/rt/dci/latest/Webprotection.zip\", \"BlackList\": \"https://acs.lavasoft.com/api/v2/url/blacklist\", \"WhiteList\": \"https://acs.lavasoft.com/api/v2/url/permanentwhitelist\", \"DisplayName\": \"Web Protection\", \"FeatureName\": \"WebProtection\"}","targetId":241}]
WebCompanionInstaller.exe
12/10/2025 6:20:52 PM :-> Starting installer 11.904.0.689 with: .\WebCompanionInstaller.exe --savename=Setup_WebCompanion.exe --partner=IN220101 --nonadmin --direct --tych --campaign=16075236377 --version=11.904.0.689, Run as admin: False
WebCompanionInstaller.exe
Preparing for installing Web Companion
WebCompanionInstaller.exe
12/10/2025 6:20:54 PM :-> Generating Machine and Install Id ...
WebCompanionInstaller.exe
12/10/2025 6:20:54 PM :-> Machine Id and Install Id has been generated
WebCompanionInstaller.exe
12/10/2025 6:20:54 PM :-> Checking prerequisites ...
WebCompanionInstaller.exe
12/10/2025 6:20:54 PM :-> Antivirus not detected