File name:

Setup_WebCompanion.exe

Full analysis: https://app.any.run/tasks/4f624e98-4186-46f1-a867-31e102c6d4ed
Verdict: Malicious activity
Threats:

Adware is a form of malware that targets users with unwanted advertisements, often disrupting their browsing experience. It typically infiltrates systems through software bundling, malicious websites, or deceptive downloads. Once installed, it may track user activity, collect sensitive data, and display intrusive ads, including pop-ups or banners. Some advanced adware variants can bypass security measures and establish persistence on devices, making removal challenging. Additionally, adware can create vulnerabilities that other malware can exploit, posing a significant risk to user privacy and system security.

Analysis date: December 10, 2025, 18:20:45
OS: Windows 7 Professional Service Pack 1 (build: 7601, 32 bit)
Tags:
adware
adaware
webcompanion
tool
arch-scr
Indicators:
MIME: application/vnd.microsoft.portable-executable
File info: PE32 executable (GUI) Intel 80386, for MS Windows, 5 sections
MD5:

BAAAE88074273E75505C073215CF24EE

SHA1:

8FC218E1E6F1FA103048D091671773BB4D358440

SHA256:

6DE25D09F4E405BD52E81D21C6DB3C080A7CE49F907CF335DEF0E2728BD3104D

SSDEEP:

12288:VG5knZfFKefG90j92I6qg/hZL4kIwGoqeBzY//OJ1:VG50ZfFKYGw2IVg5ZL4klGg1

ANY.RUN is an interactive service which provides full access to the guest system. Information in this report could be distorted by user actions and is provided for user acknowledgement as it is. ANY.RUN does not guarantee maliciousness or safety of the content.
  • MALICIOUS

    • ADAWARE has been detected (SURICATA)

      • WebCompanion.exe (PID: 2224)
    • Changes the autorun value in the registry

      • WebCompanion.exe (PID: 2024)
      • WebCompanion.exe (PID: 2224)
    • Changes settings of System certificates

      • WebCompanionInstaller.exe (PID: 2744)
  • SUSPICIOUS

    • Executable content was dropped or overwritten

      • Setup_WebCompanion.exe (PID: 3504)
      • WebCompanionInstaller.exe (PID: 3672)
    • Searches for installed software

      • WebCompanionInstaller.exe (PID: 3672)
      • WebCompanion.exe (PID: 2224)
      • WebCompanion.exe (PID: 2024)
      • WebCompanionInstaller.exe (PID: 2744)
    • Reads the Internet Settings

      • WebCompanionInstaller.exe (PID: 3672)
      • WebCompanion.exe (PID: 2224)
      • WebCompanion.exe (PID: 2024)
      • WebCompanionInstaller.exe (PID: 2744)
    • Reads settings of System Certificates

      • WebCompanionInstaller.exe (PID: 3672)
      • WebCompanion.exe (PID: 2024)
      • WebCompanion.exe (PID: 2224)
      • WebCompanionInstaller.exe (PID: 2744)
    • Drops 7-zip archiver for unpacking

      • WebCompanionInstaller.exe (PID: 3672)
    • The process drops C-runtime libraries

      • WebCompanionInstaller.exe (PID: 3672)
    • Process drops legitimate windows executable

      • WebCompanionInstaller.exe (PID: 3672)
    • Starts CMD.EXE for commands execution

      • WebCompanionInstaller.exe (PID: 3672)
    • Changes internet zones settings

      • WebCompanionInstaller.exe (PID: 3672)
    • Suspicious use of NETSH.EXE

      • cmd.exe (PID: 1464)
    • Access to an unwanted program domain was detected

      • WebCompanion.exe (PID: 2224)
    • Reads security settings of Internet Explorer

      • WebCompanion.exe (PID: 2224)
      • WebCompanionInstaller.exe (PID: 3672)
      • WebCompanion.exe (PID: 2024)
    • The process verifies whether the antivirus software is installed

      • WebCompanion.exe (PID: 2224)
      • WebCompanion.exe (PID: 2024)
    • There is functionality for taking screenshot (YARA)

      • WebCompanion.exe (PID: 2024)
    • Adds/modifies Windows certificates

      • WebCompanionInstaller.exe (PID: 2744)
  • INFO

    • Checks supported languages

      • Setup_WebCompanion.exe (PID: 3504)
      • WebCompanionInstaller.exe (PID: 3672)
      • WebCompanion.exe (PID: 2224)
      • WebCompanion.exe (PID: 2024)
      • WebCompanionInstaller.exe (PID: 2744)
    • Reads the computer name

      • WebCompanionInstaller.exe (PID: 3672)
      • WebCompanion.exe (PID: 2224)
      • WebCompanion.exe (PID: 2024)
      • WebCompanionInstaller.exe (PID: 2744)
    • The sample compiled with english language support

      • Setup_WebCompanion.exe (PID: 3504)
      • WebCompanionInstaller.exe (PID: 3672)
    • Reads the machine GUID from the registry

      • WebCompanionInstaller.exe (PID: 3672)
      • WebCompanion.exe (PID: 2224)
      • WebCompanion.exe (PID: 2024)
      • WebCompanionInstaller.exe (PID: 2744)
    • Create files in a temporary directory

      • Setup_WebCompanion.exe (PID: 3504)
      • WebCompanionInstaller.exe (PID: 3672)
    • Reads Environment values

      • WebCompanionInstaller.exe (PID: 3672)
      • WebCompanion.exe (PID: 2224)
      • WebCompanion.exe (PID: 2024)
      • WebCompanionInstaller.exe (PID: 2744)
    • Creates files or folders in the user directory

      • WebCompanionInstaller.exe (PID: 3672)
      • WebCompanion.exe (PID: 2224)
      • WebCompanion.exe (PID: 2024)
    • Disables trace logs

      • WebCompanionInstaller.exe (PID: 3672)
      • WebCompanion.exe (PID: 2224)
      • WebCompanion.exe (PID: 2024)
      • WebCompanionInstaller.exe (PID: 2744)
    • SQLite executable

      • WebCompanionInstaller.exe (PID: 3672)
    • Creates a software uninstall entry

      • WebCompanionInstaller.exe (PID: 3672)
    • Launching a file from a Registry key

      • WebCompanion.exe (PID: 2224)
      • WebCompanion.exe (PID: 2024)
    • Creates files in the program directory

      • WebCompanion.exe (PID: 2224)
      • WebCompanionInstaller.exe (PID: 2744)
    • Reads product name

      • WebCompanion.exe (PID: 2224)
      • WebCompanion.exe (PID: 2024)
    • Application launched itself

      • chrome.exe (PID: 1856)
    • ADAWAREWEBCOMPANION mutex has been found

      • WebCompanion.exe (PID: 2024)
Find more information about signature artifacts and mapping to MITRE ATT&CK™ MATRIX at the full report
No Malware configuration.

TRiD

.exe | InstallShield setup (33)
.exe | Win32 Executable MS Visual C++ (generic) (23.9)
.exe | Win64 Executable (generic) (21.2)
.scr | Windows screen saver (10)
.dll | Win32 Dynamic Link Library (generic) (5)

EXIF

EXE

MachineType: Intel 386 or later, and compatibles
TimeStamp: 2011:04:18 18:54:06+00:00
ImageFileCharacteristics: No relocs, Executable, No line numbers, No symbols, Large address aware, 32-bit
PEType: PE32
LinkerVersion: 6
CodeSize: 104448
InitializedDataSize: 60416
UninitializedDataSize: -
EntryPoint: 0x148d4
OSVersion: 4
ImageVersion: -
SubsystemVersion: 4
Subsystem: Windows GUI
FileVersionNumber: 11.904.0.689
ProductVersionNumber: 11.904.0.689
FileFlagsMask: 0x003f
FileFlags: (none)
FileOS: Windows NT 32-bit
ObjectFileType: Executable application
FileSubtype: -
LanguageCode: English (U.S.)
CharacterSet: Unicode
FileVersion: 11.904.0.689
ProductVersion: 11.904.0.689
CompanyName: Lavasoft
FileDescription: Web Companion Installer
InternalName: Installer.exe
LegalCopyright: c Lavasoft Limited. All Rights Reserved.
OriginalFileName: Installer.exe
ProductName: Web Companion Installer
No data.
screenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshot
All screenshots are available in the full report
All screenshots are available in the full report
Total processes
72
Monitored processes
25
Malicious processes
4
Suspicious processes
1

Behavior graph

Click at the process to see the details
start setup_webcompanion.exe webcompanioninstaller.exe cmd.exe no specs netsh.exe no specs #ADAWARE webcompanion.exe webcompanion.exe chrome.exe chrome.exe no specs chrome.exe no specs chrome.exe chrome.exe no specs chrome.exe no specs chrome.exe no specs chrome.exe no specs chrome.exe no specs chrome.exe no specs chrome.exe no specs webcompanioninstaller.exe chrome.exe no specs chrome.exe no specs chrome.exe no specs chrome.exe no specs chrome.exe no specs chrome.exe no specs chrome.exe no specs

Process information

PID
CMD
Path
Indicators
Parent process
892"C:\Program Files\Google\Chrome\Application\chrome.exe" --type=utility --utility-sub-type=unzip.mojom.Unzipper --lang=en-US --service-sandbox-type=service --disable-quic --mojo-platform-channel-handle=3716 --field-trial-handle=1224,i,12890370449850471694,17612920667059211280,131072 /prefetch:8C:\Program Files\Google\Chrome\Application\chrome.exechrome.exe
User:
admin
Company:
Google LLC
Integrity Level:
LOW
Description:
Google Chrome
Exit code:
0
Version:
109.0.5414.120
Modules
Images
c:\program files\google\chrome\application\chrome.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\program files\google\chrome\application\109.0.5414.120\chrome_elf.dll
c:\windows\system32\version.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\api-ms-win-core-synch-l1-2-0.dll
c:\windows\system32\advapi32.dll
c:\windows\system32\sechost.dll
1176"C:\Program Files\Google\Chrome\Application\chrome.exe" --type=utility --utility-sub-type=network.mojom.NetworkService --lang=en-US --service-sandbox-type=none --disable-quic --mojo-platform-channel-handle=1416 --field-trial-handle=1224,i,12890370449850471694,17612920667059211280,131072 /prefetch:8C:\Program Files\Google\Chrome\Application\chrome.exe
chrome.exe
User:
admin
Company:
Google LLC
Integrity Level:
MEDIUM
Description:
Google Chrome
Version:
109.0.5414.120
Modules
Images
c:\program files\google\chrome\application\chrome.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\program files\google\chrome\application\109.0.5414.120\chrome_elf.dll
c:\windows\system32\version.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\api-ms-win-core-synch-l1-2-0.dll
c:\windows\system32\advapi32.dll
c:\windows\system32\sechost.dll
1368"C:\Program Files\Google\Chrome\Application\chrome.exe" --type=gpu-process --gpu-preferences=UAAAAAAAAADgAAAYAAAAAAAAAAAAAAAAAABgAAAAAAAwAAAAAAAAAAAAAAAQAAAAAAAAAAAAAAAAAAAAAAAAAEgAAAAAAAAASAAAAAAAAAAYAAAAAgAAABAAAAAAAAAAGAAAAAAAAAAQAAAAAAAAAAAAAAAOAAAAEAAAAAAAAAABAAAADgAAAAgAAAAAAAAACAAAAAAAAAA= --mojo-platform-channel-handle=1096 --field-trial-handle=1224,i,12890370449850471694,17612920667059211280,131072 /prefetch:2C:\Program Files\Google\Chrome\Application\chrome.exechrome.exe
User:
admin
Company:
Google LLC
Integrity Level:
LOW
Description:
Google Chrome
Exit code:
0
Version:
109.0.5414.120
Modules
Images
c:\program files\google\chrome\application\chrome.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\program files\google\chrome\application\109.0.5414.120\chrome_elf.dll
c:\windows\system32\version.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\api-ms-win-core-synch-l1-2-0.dll
c:\windows\system32\advapi32.dll
c:\windows\system32\sechost.dll
1372"C:\Program Files\Google\Chrome\Application\chrome.exe" --type=renderer --extension-process --lang=en-US --device-scale-factor=1 --num-raster-threads=2 --enable-main-frame-before-activation --renderer-client-id=7 --mojo-platform-channel-handle=3104 --field-trial-handle=1224,i,12890370449850471694,17612920667059211280,131072 /prefetch:1C:\Program Files\Google\Chrome\Application\chrome.exechrome.exe
User:
admin
Company:
Google LLC
Integrity Level:
LOW
Description:
Google Chrome
Exit code:
0
Version:
109.0.5414.120
Modules
Images
c:\program files\google\chrome\application\chrome.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\program files\google\chrome\application\109.0.5414.120\chrome_elf.dll
c:\windows\system32\version.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\api-ms-win-core-synch-l1-2-0.dll
c:\windows\system32\advapi32.dll
c:\windows\system32\sechost.dll
1464"C:\Windows\System32\cmd.exe" /C netsh http add urlacl url=http://+:9007/ user=EveryoneC:\Windows\System32\cmd.exeWebCompanionInstaller.exe
User:
admin
Company:
Microsoft Corporation
Integrity Level:
MEDIUM
Description:
Windows Command Processor
Exit code:
1
Version:
6.1.7601.17514 (win7sp1_rtm.101119-1850)
Modules
Images
c:\windows\system32\cmd.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\winbrand.dll
c:\windows\system32\user32.dll
c:\windows\system32\gdi32.dll
c:\windows\system32\lpk.dll
c:\windows\system32\usp10.dll
1856"C:\Program Files\Google\Chrome\Application\chrome.exe" https://webcompanion.com/en/install.php?partner=IN220101&campaign=16075236377C:\Program Files\Google\Chrome\Application\chrome.exe
WebCompanionInstaller.exe
User:
admin
Company:
Google LLC
Integrity Level:
MEDIUM
Description:
Google Chrome
Version:
109.0.5414.120
Modules
Images
c:\program files\google\chrome\application\chrome.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\program files\google\chrome\application\109.0.5414.120\chrome_elf.dll
c:\windows\system32\version.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\api-ms-win-core-synch-l1-2-0.dll
c:\windows\system32\advapi32.dll
c:\windows\system32\sechost.dll
1904"C:\Program Files\Google\Chrome\Application\chrome.exe" --type=utility --utility-sub-type=storage.mojom.StorageService --lang=en-US --service-sandbox-type=service --disable-quic --mojo-platform-channel-handle=1600 --field-trial-handle=1224,i,12890370449850471694,17612920667059211280,131072 /prefetch:8C:\Program Files\Google\Chrome\Application\chrome.exechrome.exe
User:
admin
Company:
Google LLC
Integrity Level:
LOW
Description:
Google Chrome
Version:
109.0.5414.120
Modules
Images
c:\program files\google\chrome\application\chrome.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\program files\google\chrome\application\109.0.5414.120\chrome_elf.dll
c:\windows\system32\version.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\api-ms-win-core-synch-l1-2-0.dll
c:\windows\system32\advapi32.dll
c:\windows\system32\sechost.dll
2024"C:\Users\admin\AppData\Roaming\Lavasoft\Web Companion\Application\WebCompanion.exe" --afterinstall C:\Users\admin\AppData\Roaming\Lavasoft\Web Companion\Application\WebCompanion.exe
WebCompanionInstaller.exe
User:
admin
Company:
Lavasoft
Integrity Level:
MEDIUM
Description:
Web Companion
Exit code:
4294967295
Version:
11.4.0.689
Modules
Images
c:\users\admin\appdata\roaming\lavasoft\web companion\application\webcompanion.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\mscoree.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\advapi32.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\sechost.dll
c:\windows\system32\rpcrt4.dll
c:\windows\microsoft.net\framework\v4.0.30319\mscoreei.dll
2224"C:\Users\admin\AppData\Roaming\Lavasoft\Web Companion\Application\WebCompanion.exe" --install --geo= C:\Users\admin\AppData\Roaming\Lavasoft\Web Companion\Application\WebCompanion.exe
WebCompanionInstaller.exe
User:
admin
Company:
Lavasoft
Integrity Level:
MEDIUM
Description:
Web Companion
Exit code:
0
Version:
11.4.0.689
Modules
Images
c:\users\admin\appdata\roaming\lavasoft\web companion\application\webcompanion.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\mscoree.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\advapi32.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\sechost.dll
c:\windows\system32\rpcrt4.dll
c:\windows\microsoft.net\framework\v4.0.30319\mscoreei.dll
2392"C:\Program Files\Google\Chrome\Application\chrome.exe" --type=gpu-process --gpu-preferences=UAAAAAAAAADgAAAYAAAAAAAAAAAAAAAAAABgAAAAAAAwAAAAAAAAAAAAAAAQAAAAAAAAAAAAAAAAAAAAAAAAAEgAAAAAAAAASAAAAAAAAAAYAAAAAgAAABAAAAAAAAAAGAAAAAAAAAAQAAAAAAAAAAAAAAAOAAAAEAAAAAAAAAABAAAADgAAAAgAAAAAAAAACAAAAAAAAAA= --use-gl=angle --use-angle=swiftshader-webgl --mojo-platform-channel-handle=1528 --field-trial-handle=1224,i,12890370449850471694,17612920667059211280,131072 /prefetch:2C:\Program Files\Google\Chrome\Application\chrome.exechrome.exe
User:
admin
Company:
Google LLC
Integrity Level:
LOW
Description:
Google Chrome
Version:
109.0.5414.120
Modules
Images
c:\program files\google\chrome\application\chrome.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\program files\google\chrome\application\109.0.5414.120\chrome_elf.dll
c:\windows\system32\version.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\api-ms-win-core-synch-l1-2-0.dll
c:\windows\system32\advapi32.dll
c:\windows\system32\sechost.dll
Total events
24 018
Read events
23 836
Write events
179
Delete events
3

Modification events

(PID) Process:(3672) WebCompanionInstaller.exeKey:HKEY_CURRENT_USER\Software\Lavasoft\Web Companion
Operation:writeName:MachineId
Value:
8569aaff-63aa-a71d-8040-0e2571e89667
(PID) Process:(3672) WebCompanionInstaller.exeKey:HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Tracing\WebCompanionInstaller_RASAPI32
Operation:writeName:EnableFileTracing
Value:
0
(PID) Process:(3672) WebCompanionInstaller.exeKey:HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Tracing\WebCompanionInstaller_RASAPI32
Operation:writeName:EnableConsoleTracing
Value:
0
(PID) Process:(3672) WebCompanionInstaller.exeKey:HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Tracing\WebCompanionInstaller_RASAPI32
Operation:writeName:FileTracingMask
Value:
(PID) Process:(3672) WebCompanionInstaller.exeKey:HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Tracing\WebCompanionInstaller_RASAPI32
Operation:writeName:ConsoleTracingMask
Value:
(PID) Process:(3672) WebCompanionInstaller.exeKey:HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Tracing\WebCompanionInstaller_RASAPI32
Operation:writeName:MaxFileSize
Value:
1048576
(PID) Process:(3672) WebCompanionInstaller.exeKey:HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Tracing\WebCompanionInstaller_RASAPI32
Operation:writeName:FileDirectory
Value:
%windir%\tracing
(PID) Process:(3672) WebCompanionInstaller.exeKey:HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Tracing\WebCompanionInstaller_RASMANCS
Operation:writeName:EnableFileTracing
Value:
0
(PID) Process:(3672) WebCompanionInstaller.exeKey:HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Tracing\WebCompanionInstaller_RASMANCS
Operation:writeName:EnableConsoleTracing
Value:
0
(PID) Process:(3672) WebCompanionInstaller.exeKey:HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Tracing\WebCompanionInstaller_RASMANCS
Operation:writeName:FileTracingMask
Value:
Executable files
98
Suspicious files
126
Text files
83
Unknown types
0

Dropped files

PID
Process
Filename
Type
3504Setup_WebCompanion.exeC:\Users\admin\AppData\Local\Temp\7zS0BD3C65F\WebCompanionInstaller.exe.configxml
MD5:634D2D29F0ECFEE31F2D1E3C0FE6832D
SHA256:9825E2E2AACB7F01BC779101E6141F1ABFE71E23F69B1B0ED434B1F5DFF7615C
3504Setup_WebCompanion.exeC:\Users\admin\AppData\Local\Temp\7zS0BD3C65F\en-US\WebCompanionInstaller.resources.dllexecutable
MD5:8D42954DD718AB37335ED0FB2D18164D
SHA256:D70F2C75A00890453EEA09DAD0A7E0B0AD0F65899B41A8D455BF7A991CAA1866
3504Setup_WebCompanion.exeC:\Users\admin\AppData\Local\Temp\7zS0BD3C65F\fr-CA\WebCompanionInstaller.resources.dllexecutable
MD5:93338D11C67D649A2EEDF5A2CACC4AC1
SHA256:6491BB8426F8761E36E8A6CD5AA9363DE09D5D495A9A894E87C37F07C09AF107
3504Setup_WebCompanion.exeC:\Users\admin\AppData\Local\Temp\7zS0BD3C65F\ICSharpCode.SharpZipLib.dllexecutable
MD5:88831780ABDAAD0E70D643DF3226D312
SHA256:656DFCD0F02278C7F4ABA97996D1D6BA06D7D463D0139C29C6507A518EBC5CEC
3672WebCompanionInstaller.exeC:\Users\admin\AppData\Roaming\Lavasoft\Web Companion\Application\7za.exeexecutable
MD5:AD61692E5258AE709796D67D8CDD252E
SHA256:2383E73D0A6174B929195509C95909FE69197FBDCCC8DFA5C98B0A0D169976E8
3672WebCompanionInstaller.exeC:\Users\admin\AppData\Roaming\Lavasoft\Web Companion\Application\acs17.dllexecutable
MD5:F93843D229446C9DBF66F703BBEF9003
SHA256:3F3F583C5D0EF2A0A81DBF85D42BCBE8B5CCA521BD2607012AC3EEC43291151D
3504Setup_WebCompanion.exeC:\Users\admin\AppData\Local\Temp\7zS0BD3C65F\de-DE\WebCompanionInstaller.resources.dllexecutable
MD5:FD407782A62399C21588100C830A609D
SHA256:64B8242A3178E4D71AF140791DCD5DCE2309C5A960AA2025F51946609D1197E9
3504Setup_WebCompanion.exeC:\Users\admin\AppData\Local\Temp\7zS0BD3C65F\it-IT\WebCompanionInstaller.resources.dllexecutable
MD5:449C45BC1F350488B843C472996222A1
SHA256:0191552F49FE45AD89128D496BD9F9837BC5BB5B68C0FA9A0D0D08775B45069F
3504Setup_WebCompanion.exeC:\Users\admin\AppData\Local\Temp\7zS0BD3C65F\es-ES\WebCompanionInstaller.resources.dllexecutable
MD5:79E5C8F8681E07E0438B0A7A0CD63249
SHA256:E66BBBF54CEA7DB58DE5B3F4DF8B1D6ADB3B30B2D72DEF616F46BEB2635DDBB6
3504Setup_WebCompanion.exeC:\Users\admin\AppData\Local\Temp\7zS0BD3C65F\Newtonsoft.Json.dllexecutable
MD5:B4C13884516B327C813F7B3E7C5D8135
SHA256:B1A466D22198D9B04A8943083A08BA26336D8D9A6757F1E59A94344D368E4272
Download PCAP, analyze network streams, HTTP content and a lot more at the full report
HTTP(S) requests
15
TCP/UDP connections
74
DNS requests
87
Threats
56

HTTP requests

PID
Process
Method
HTTP Code
IP
URL
CN
Type
Size
Reputation
3672
WebCompanionInstaller.exe
GET
200
104.16.148.130:80
http://geo.lavasoft.com/
US
binary
70 b
whitelisted
2224
WebCompanion.exe
GET
200
64.18.87.81:80
http://wc-partners.lavasoft.com/Partner.svc/GetPartnerInfo?partner=IN220101_ab
CA
binary
205 b
whitelisted
2224
WebCompanion.exe
GET
200
64.18.87.81:80
http://wc-partners.lavasoft.com/Partner.svc/GetPartnerInfo?partner=IN220101_wb
CA
binary
205 b
whitelisted
2224
WebCompanion.exe
GET
200
104.16.148.130:80
http://geo.lavasoft.com/
US
binary
70 b
whitelisted
2224
WebCompanion.exe
GET
200
64.18.87.81:80
http://wc-partners.lavasoft.com/Partner.svc/GetPartnerInfo?partner=IN220101_ac
CA
binary
205 b
whitelisted
2224
WebCompanion.exe
GET
200
104.19.208.152:80
http://webcompanion.com/version_logs?json=true&version=11.4.0.689
US
text
344 b
unknown
2024
WebCompanion.exe
GET
200
104.19.208.152:80
http://webcompanion.com/version_logs?json=true&version=13.901.0.1133
US
text
344 b
unknown
3672
WebCompanionInstaller.exe
GET
104.16.148.130:80
http://wcdownloadercdn.lavasoft.com/11.4.0.689/WebCompanion-11.4.0.689-prod.zip
US
whitelisted
2224
WebCompanion.exe
GET
200
104.16.148.130:80
http://geo.lavasoft.com/
US
binary
70 b
whitelisted
2224
WebCompanion.exe
GET
200
64.18.87.81:80
http://wc-partners.lavasoft.com/Partner.svc/GetPartnerInfo?partner=IN220101
CA
binary
197 b
whitelisted
Download PCAP, analyze network streams, HTTP content and a lot more at the full report

Connections

PID
Process
IP
Domain
ASN
CN
Reputation
4
System
192.168.100.255:137
Not routed
whitelisted
224.0.0.252:5355
whitelisted
4
System
192.168.100.255:138
Not routed
whitelisted
3672
WebCompanionInstaller.exe
104.16.148.130:80
geo.lavasoft.com
CLOUDFLARENET
US
whitelisted
1092
svchost.exe
224.0.0.252:5355
whitelisted
3672
WebCompanionInstaller.exe
104.16.148.130:443
geo.lavasoft.com
CLOUDFLARENET
US
whitelisted
3672
WebCompanionInstaller.exe
104.18.26.149:443
flwadw.com
CLOUDFLARENET
US
whitelisted
2224
WebCompanion.exe
104.16.148.130:80
geo.lavasoft.com
CLOUDFLARENET
US
whitelisted
2224
WebCompanion.exe
104.16.148.130:443
geo.lavasoft.com
CLOUDFLARENET
US
whitelisted
2224
WebCompanion.exe
104.18.26.149:443
flwadw.com
CLOUDFLARENET
US
whitelisted

DNS requests

Domain
IP
Reputation
google.com
  • 142.250.186.174
whitelisted
geo.lavasoft.com
  • 104.16.148.130
  • 104.16.149.130
whitelisted
featureflags.lavasoft.com
  • 104.16.148.130
  • 104.16.149.130
whitelisted
flwadw.com
  • 104.18.26.149
  • 104.18.27.149
unknown
wcdownloadercdn.lavasoft.com
  • 104.16.148.130
  • 104.16.149.130
whitelisted
wc-partners.lavasoft.com
  • 64.18.87.81
  • 64.18.87.82
whitelisted
webcompanion.com
  • 104.19.208.152
  • 104.19.159.224
unknown
clientservices.googleapis.com
  • 192.178.170.94
whitelisted
accounts.google.com
  • 108.177.15.84
whitelisted
sg-bitmask.adaware.com
  • 104.16.212.94
  • 104.16.213.94
whitelisted

Threats

PID
Process
Class
Message
Possibly Unwanted Program Detected
ADWARE [ANY.RUN] Adaware Web Companion
Possibly Unwanted Program Detected
ADWARE [ANY.RUN] Adaware Web Companion
Possibly Unwanted Program Detected
ADWARE [ANY.RUN] Adaware Web Companion
Possibly Unwanted Program Detected
ADWARE [ANY.RUN] Adaware Web Companion
Possibly Unwanted Program Detected
ADWARE [ANY.RUN] Adaware Web Companion
Possibly Unwanted Program Detected
ADWARE [ANY.RUN] Adaware Web Companion
Possibly Unwanted Program Detected
ADWARE [ANY.RUN] Adaware Web Companion
3672
WebCompanionInstaller.exe
Potentially Bad Traffic
ET HUNTING Terse Request for Zip File (GET)
Possibly Unwanted Program Detected
ADWARE [ANY.RUN] Adaware Web Companion
Possibly Unwanted Program Detected
ADWARE [ANY.RUN] Adaware Web Companion
Process
Message
WebCompanionInstaller.exe
Failed to OpenWcfHost: System.ServiceModel.AddressAccessDeniedException: HTTP could not register URL http://+:9008/webcompanion/. Your process does not have access rights to this namespace (see http://go.microsoft.com/fwlink/?LinkId=70353 for details). ---> System.Net.HttpListenerException: Access is denied at System.Net.HttpListener.AddAllPrefixes() at System.Net.HttpListener.Start() at System.ServiceModel.Channels.SharedHttpTransportManager.OnOpen() --- End of inner exception stack trace --- at System.ServiceModel.Channels.SharedHttpTransportManager.OnOpen() at System.ServiceModel.Channels.TransportManager.Open(TransportChannelListener channelListener) at System.ServiceModel.Channels.TransportManagerContainer.Open(SelectTransportManagersCallback selectTransportManagerCallback) at System.ServiceModel.Channels.TransportChannelListener.OnOpen(TimeSpan timeout) at System.ServiceModel.Channels.HttpChannelListener`1.OnOpen(TimeSpan timeout) at System.ServiceModel.Channels.CommunicationObject.Open(TimeSpan timeout) at System.ServiceModel.Dispatcher.ChannelDispatcher.OnOpen(TimeSpan timeout) at System.ServiceModel.Channels.CommunicationObject.Open(TimeSpan timeout) at System.ServiceModel.ServiceHostBase.OnOpen(TimeSpan timeout) at System.ServiceModel.Channels.CommunicationObject.Open(TimeSpan timeout) at WebCompanionInstaller.App.OpenInstallerWcfHost()
WebCompanionInstaller.exe
Detecting windows culture
WebCompanionInstaller.exe
Preparing request for featureflag: {"Geo":"DE","Partner":"IN220101","Campaign":"16075236377","InstallDate":"20251210","TriggerType":"install","TriggerEvent":"installer","Version":"11.904.0.689","featurewp":true,"featureal":true}
WebCompanionInstaller.exe
Getting response from featureflag: [{"sectionCode":"WAC","code":"WAC","configuration":"{\"Icon\": \"https://webcompanion.com/images/favicon.ico\", \"color\": \"25FFFF\", \"AppName\": \"Web Companion\", \"Settings\": [\"WCAutoUpdate\", \"EnableGranularity\", \"PostRunV2Action\", \"PostRunTimerAction\", \"EnableTelemetryScan\", \"EnableWebProtection\", \"EnableDynamicNotification\"], \"darkmode\": false, \"CompanyName\": \"Lavasoft\", \"ConfigVersion\": \"v1\", \"CurrentVersion\": \"9.3.0\", \"IsNewUpdaterService\": true}","targetId":301},{"sectionCode":"WFAI","code":"WCP","configuration":"{\"Version\": \"3.0.2.12\", \"FilePath\": \"https://rt.webcompanion.com/notifications/download/rt/dci/latest/Webprotection.zip\", \"BlackList\": \"https://acs.lavasoft.com/api/v2/url/blacklist\", \"WhiteList\": \"https://acs.lavasoft.com/api/v2/url/permanentwhitelist\", \"DisplayName\": \"Web Protection\", \"FeatureName\": \"WebProtection\"}","targetId":241}]
WebCompanionInstaller.exe
12/10/2025 6:20:52 PM :-> Starting installer 11.904.0.689 with: .\WebCompanionInstaller.exe --savename=Setup_WebCompanion.exe --partner=IN220101 --nonadmin --direct --tych --campaign=16075236377 --version=11.904.0.689, Run as admin: False
WebCompanionInstaller.exe
Preparing for installing Web Companion
WebCompanionInstaller.exe
12/10/2025 6:20:54 PM :-> Generating Machine and Install Id ...
WebCompanionInstaller.exe
12/10/2025 6:20:54 PM :-> Machine Id and Install Id has been generated
WebCompanionInstaller.exe
12/10/2025 6:20:54 PM :-> Checking prerequisites ...
WebCompanionInstaller.exe
12/10/2025 6:20:54 PM :-> Antivirus not detected