File name:

Setup_WebCompanion.exe

Full analysis: https://app.any.run/tasks/a939e134-15c8-41b1-b92e-e207c8a07349
Verdict: Malicious activity
Analysis date: August 04, 2023, 13:59:20
OS: Windows 7 Professional Service Pack 1 (build: 7601, 32 bit)
Tags:
installer
Indicators:
MIME: application/x-dosexec
File info: PE32 executable (GUI) Intel 80386, for MS Windows
MD5:

BAAAE88074273E75505C073215CF24EE

SHA1:

8FC218E1E6F1FA103048D091671773BB4D358440

SHA256:

6DE25D09F4E405BD52E81D21C6DB3C080A7CE49F907CF335DEF0E2728BD3104D

SSDEEP:

12288:VG5knZfFKefG90j92I6qg/hZL4kIwGoqeBzY//OJ1:VG50ZfFKYGw2IVg5ZL4klGg1

ANY.RUN is an interactive service which provides full access to the guest system. Information in this report could be distorted by user actions and is provided for user acknowledgement as it is. ANY.RUN does not guarantee maliciousness or safety of the content.
  • MALICIOUS

    • Loads dropped or rewritten executable

      • WebCompanionInstaller.exe (PID: 3864)
      • WebCompanion.exe (PID: 768)
    • Application was dropped or rewritten from another process

      • WebCompanionInstaller.exe (PID: 3864)
      • WebCompanion.exe (PID: 768)
  • SUSPICIOUS

    • Executable content was dropped or overwritten

      • Setup_WebCompanion.exe (PID: 2880)
      • WebCompanionInstaller.exe (PID: 3864)
    • Searches for installed software

      • WebCompanionInstaller.exe (PID: 3864)
      • WebCompanion.exe (PID: 768)
    • Reads settings of System Certificates

      • WebCompanionInstaller.exe (PID: 3864)
      • WebCompanion.exe (PID: 768)
    • Reads the Internet Settings

      • WebCompanionInstaller.exe (PID: 3864)
      • WebCompanion.exe (PID: 768)
    • The process creates files with name similar to system file names

      • WebCompanionInstaller.exe (PID: 3864)
    • Suspicious use of NETSH.EXE

      • cmd.exe (PID: 2628)
    • Changes internet zones settings

      • WebCompanionInstaller.exe (PID: 3864)
    • Starts CMD.EXE for commands execution

      • WebCompanionInstaller.exe (PID: 3864)
    • Checks Windows Trust Settings

      • WebCompanion.exe (PID: 768)
    • Reads security settings of Internet Explorer

      • WebCompanion.exe (PID: 768)
  • INFO

    • Checks supported languages

      • Setup_WebCompanion.exe (PID: 2880)
      • WebCompanionInstaller.exe (PID: 3864)
      • wmpnscfg.exe (PID: 1048)
      • WebCompanion.exe (PID: 768)
    • Create files in a temporary directory

      • Setup_WebCompanion.exe (PID: 2880)
      • WebCompanionInstaller.exe (PID: 3864)
    • Reads the computer name

      • WebCompanionInstaller.exe (PID: 3864)
      • wmpnscfg.exe (PID: 1048)
      • WebCompanion.exe (PID: 768)
    • The process checks LSA protection

      • WebCompanionInstaller.exe (PID: 3864)
      • wisptis.exe (PID: 3832)
      • wmpnscfg.exe (PID: 1048)
      • netsh.exe (PID: 312)
      • WebCompanion.exe (PID: 768)
    • Reads the machine GUID from the registry

      • WebCompanionInstaller.exe (PID: 3864)
      • wmpnscfg.exe (PID: 1048)
      • WebCompanion.exe (PID: 768)
    • Creates files or folders in the user directory

      • WebCompanionInstaller.exe (PID: 3864)
      • WebCompanion.exe (PID: 768)
    • [YARA] HTTP manipulation strings were found

      • WebCompanionInstaller.exe (PID: 3864)
    • Reads Environment values

      • WebCompanionInstaller.exe (PID: 3864)
      • WebCompanion.exe (PID: 768)
    • Manual execution by a user

      • wmpnscfg.exe (PID: 1048)
    • Creates files in the program directory

      • WebCompanion.exe (PID: 768)
Find more information about signature artifacts and mapping to MITRE ATT&CK™ MATRIX at the full report
No Malware configuration.

TRiD

.exe | InstallShield setup (33)
.exe | Win32 Executable MS Visual C++ (generic) (23.9)
.exe | Win64 Executable (generic) (21.2)
.scr | Windows screen saver (10)
.dll | Win32 Dynamic Link Library (generic) (5)

EXIF

EXE

ProductName: Web Companion Installer
OriginalFileName: Installer.exe
LegalCopyright: c Lavasoft Limited. All Rights Reserved.
InternalName: Installer.exe
FileDescription: Web Companion Installer
CompanyName: Lavasoft
ProductVersion: 11.904.0.689
FileVersion: 11.904.0.689
CharacterSet: Unicode
LanguageCode: English (U.S.)
FileSubtype: -
ObjectFileType: Executable application
FileOS: Windows NT 32-bit
FileFlags: (none)
FileFlagsMask: 0x003f
ProductVersionNumber: 11.904.0.689
FileVersionNumber: 11.904.0.689
Subsystem: Windows GUI
SubsystemVersion: 4
ImageVersion: -
OSVersion: 4
EntryPoint: 0x148d4
UninitializedDataSize: -
InitializedDataSize: 60416
CodeSize: 104448
LinkerVersion: 6
PEType: PE32
ImageFileCharacteristics: No relocs, Executable, No line numbers, No symbols, Large address aware, 32-bit
TimeStamp: 2011:04:18 18:54:06+00:00
MachineType: Intel 386 or later, and compatibles
No data.
screenshotscreenshotscreenshot
All screenshots are available in the full report
All screenshots are available in the full report
Total processes
45
Monitored processes
8
Malicious processes
3
Suspicious processes
0

Behavior graph

Click at the process to see the details
drop and start start drop and start setup_webcompanion.exe webcompanioninstaller.exe wisptis.exe no specs wisptis.exe wmpnscfg.exe no specs cmd.exe no specs netsh.exe no specs webcompanion.exe

Process information

PID
CMD
Path
Indicators
Parent process
312netsh http add urlacl url=http://+:9007/ user=EveryoneC:\Windows\System32\netsh.execmd.exe
User:
admin
Company:
Microsoft Corporation
Integrity Level:
MEDIUM
Description:
Network Command Shell
Exit code:
1
Version:
6.1.7600.16385 (win7_rtm.090713-1255)
Modules
Images
c:\windows\system32\netsh.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\sechost.dll
c:\windows\system32\advapi32.dll
c:\windows\system32\rpcrt4.dll
c:\windows\system32\user32.dll
c:\windows\system32\gdi32.dll
768"C:\Users\admin\AppData\Roaming\Lavasoft\Web Companion\Application\WebCompanion.exe" --install --geo= C:\Users\admin\AppData\Roaming\Lavasoft\Web Companion\Application\WebCompanion.exe
WebCompanionInstaller.exe
User:
admin
Company:
Lavasoft
Integrity Level:
MEDIUM
Description:
Web Companion
Exit code:
0
Version:
11.4.0.689
Modules
Images
c:\users\admin\appdata\roaming\lavasoft\web companion\application\webcompanion.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\mscoree.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\advapi32.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\sechost.dll
c:\windows\system32\rpcrt4.dll
c:\windows\microsoft.net\framework\v4.0.30319\mscoreei.dll
1048"C:\Program Files\Windows Media Player\wmpnscfg.exe"C:\Program Files\Windows Media Player\wmpnscfg.exeexplorer.exe
User:
admin
Company:
Microsoft Corporation
Integrity Level:
MEDIUM
Description:
Windows Media Player Network Sharing Service Configuration Application
Exit code:
0
Version:
12.0.7600.16385 (win7_rtm.090713-1255)
Modules
Images
c:\program files\windows media player\wmpnscfg.exe
c:\windows\system32\kernelbase.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\ntdll.dll
c:\windows\system32\advapi32.dll
c:\windows\system32\sechost.dll
c:\windows\system32\rpcrt4.dll
c:\windows\system32\sspicli.dll
c:\windows\system32\ole32.dll
1368"C:\Windows\SYSTEM32\WISPTIS.EXE" /ManualLaunch;C:\Windows\System32\wisptis.exeWebCompanionInstaller.exe
User:
admin
Company:
Microsoft Corporation
Integrity Level:
MEDIUM
Description:
Microsoft Pen and Touch Input Component
Exit code:
3221226540
Version:
6.1.7600.16385 (win7_rtm.090713-1255)
Modules
Images
c:\windows\system32\ntdll.dll
c:\windows\system32\wisptis.exe
2628"C:\Windows\System32\cmd.exe" /C netsh http add urlacl url=http://+:9007/ user=EveryoneC:\Windows\System32\cmd.exeWebCompanionInstaller.exe
User:
admin
Company:
Microsoft Corporation
Integrity Level:
MEDIUM
Description:
Windows Command Processor
Exit code:
1
Version:
6.1.7601.17514 (win7sp1_rtm.101119-1850)
Modules
Images
c:\windows\system32\cmd.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\winbrand.dll
c:\windows\system32\user32.dll
c:\windows\system32\lpk.dll
c:\windows\system32\gdi32.dll
c:\windows\system32\usp10.dll
2880"C:\Users\admin\AppData\Local\Temp\Setup_WebCompanion.exe" C:\Users\admin\AppData\Local\Temp\Setup_WebCompanion.exe
explorer.exe
User:
admin
Company:
Lavasoft
Integrity Level:
MEDIUM
Description:
Web Companion Installer
Exit code:
0
Version:
11.904.0.689
Modules
Images
c:\users\admin\appdata\local\temp\setup_webcompanion.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\oleaut32.dll
c:\windows\system32\ole32.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\user32.dll
c:\windows\system32\usp10.dll
c:\windows\system32\gdi32.dll
3832"C:\Windows\SYSTEM32\WISPTIS.EXE" /ManualLaunch;C:\Windows\System32\wisptis.exe
WebCompanionInstaller.exe
User:
admin
Company:
Microsoft Corporation
Integrity Level:
HIGH
Description:
Microsoft Pen and Touch Input Component
Exit code:
24
Version:
6.1.7600.16385 (win7_rtm.090713-1255)
Modules
Images
c:\windows\system32\wisptis.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\user32.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\gdi32.dll
c:\windows\system32\lpk.dll
c:\windows\system32\ole32.dll
c:\windows\system32\usp10.dll
3864.\WebCompanionInstaller.exe --savename=Setup_WebCompanion.exe --partner=IN220101 --nonadmin --direct --tych --campaign=16075236377 --version=11.904.0.689C:\Users\admin\AppData\Local\Temp\7zS04B85B56\WebCompanionInstaller.exe
Setup_WebCompanion.exe
User:
admin
Company:
Lavasoft
Integrity Level:
MEDIUM
Description:
Web Companion
Exit code:
0
Version:
11.904.0.689
Modules
Images
c:\users\admin\appdata\local\temp\7zs04b85b56\webcompanioninstaller.exe
c:\windows\system32\mscoree.dll
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\advapi32.dll
c:\windows\system32\sechost.dll
c:\windows\microsoft.net\framework\v4.0.30319\mscoreei.dll
c:\windows\system32\rpcrt4.dll
Total events
8 495
Read events
8 399
Write events
93
Delete events
3

Modification events

(PID) Process:(3864) WebCompanionInstaller.exeKey:HKEY_CLASSES_ROOT\Local Settings\MuiCache\178\52C64B7E
Operation:writeName:LanguageList
Value:
en-US
(PID) Process:(3864) WebCompanionInstaller.exeKey:HKEY_CURRENT_USER\Software\Microsoft\Direct3D\MostRecentApplication
Operation:writeName:Name
Value:
Explorer.EXE
(PID) Process:(3864) WebCompanionInstaller.exeKey:HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap
Operation:writeName:ProxyBypass
Value:
1
(PID) Process:(3864) WebCompanionInstaller.exeKey:HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap
Operation:writeName:IntranetName
Value:
1
(PID) Process:(3864) WebCompanionInstaller.exeKey:HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap
Operation:writeName:UNCAsIntranet
Value:
1
(PID) Process:(3864) WebCompanionInstaller.exeKey:HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap
Operation:writeName:AutoDetect
Value:
0
(PID) Process:(3832) wisptis.exeKey:HKEY_CURRENT_USER\Software\Microsoft\Direct3D\MostRecentApplication
Operation:writeName:Name
Value:
WebCompanionInstaller.exe
(PID) Process:(1048) wmpnscfg.exeKey:HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows Media Player NSS\3.0\Events\{A21DCCE1-8099-454C-BE99-698B990959FA}\{D4BD1867-0ADD-46D9-ACD3-6924BE086355}
Operation:delete keyName:(default)
Value:
(PID) Process:(1048) wmpnscfg.exeKey:HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows Media Player NSS\3.0\Events\{A21DCCE1-8099-454C-BE99-698B990959FA}
Operation:delete keyName:(default)
Value:
(PID) Process:(1048) wmpnscfg.exeKey:HKEY_CURRENT_USER\Software\Microsoft\MediaPlayer\Health\{C1D6A2C0-977F-47E6-92EE-B69FBB6F53C5}
Operation:delete keyName:(default)
Value:
Executable files
94
Suspicious files
14
Text files
17
Unknown types
0

Dropped files

PID
Process
Filename
Type
2880Setup_WebCompanion.exeC:\Users\admin\AppData\Local\Temp\7zS04B85B56\WebCompanionInstaller.exeexecutable
MD5:2376204BA2EBE92158D45FA8D7A6C9BF
SHA256:A89679885457ED266DB3C8BD50220CFBE0229BABE84BE4334EF2A01CB219D755
2880Setup_WebCompanion.exeC:\Users\admin\AppData\Local\Temp\7zS04B85B56\pt-BR\WebCompanionInstaller.resources.dllexecutable
MD5:0BBC570FBD0304EC4BF4185D8616816B
SHA256:4B5613BD7C4AF5CFF9038DC44D63232C016CF673D0F0245B1BE0A635FC9F87AA
2880Setup_WebCompanion.exeC:\Users\admin\AppData\Local\Temp\7zS04B85B56\it-IT\WebCompanionInstaller.resources.dllexecutable
MD5:449C45BC1F350488B843C472996222A1
SHA256:0191552F49FE45AD89128D496BD9F9837BC5BB5B68C0FA9A0D0D08775B45069F
2880Setup_WebCompanion.exeC:\Users\admin\AppData\Local\Temp\7zS04B85B56\de-DE\WebCompanionInstaller.resources.dllexecutable
MD5:FD407782A62399C21588100C830A609D
SHA256:64B8242A3178E4D71AF140791DCD5DCE2309C5A960AA2025F51946609D1197E9
2880Setup_WebCompanion.exeC:\Users\admin\AppData\Local\Temp\7zS04B85B56\ja-JP\WebCompanionInstaller.resources.dllexecutable
MD5:D315FD206AAE3DF3489E7863A949E518
SHA256:C59560241CCA5D8F7CFAD2C8434CDDF366A501A3BA0DB119CB663EA3E7270DFF
2880Setup_WebCompanion.exeC:\Users\admin\AppData\Local\Temp\7zS04B85B56\fr-CA\WebCompanionInstaller.resources.dllexecutable
MD5:93338D11C67D649A2EEDF5A2CACC4AC1
SHA256:6491BB8426F8761E36E8A6CD5AA9363DE09D5D495A9A894E87C37F07C09AF107
2880Setup_WebCompanion.exeC:\Users\admin\AppData\Local\Temp\7zS04B85B56\ru-RU\WebCompanionInstaller.resources.dllexecutable
MD5:8F15E3AADB5032A2D4C677EDD2117522
SHA256:6ECE4F64535618D51F3357E8763DE232A1903BD1D6A7D338692E992E9786132D
2880Setup_WebCompanion.exeC:\Users\admin\AppData\Local\Temp\7zS04B85B56\tr-TR\WebCompanionInstaller.resources.dllexecutable
MD5:ABD17C89314092FE77C41F8955D43575
SHA256:9337801ABAE112DC677763E67B976796422CCC8B998F29EDD96F1BD93E512169
2880Setup_WebCompanion.exeC:\Users\admin\AppData\Local\Temp\7zS04B85B56\WebCompanionInstaller.exe.configxml
MD5:634D2D29F0ECFEE31F2D1E3C0FE6832D
SHA256:9825E2E2AACB7F01BC779101E6141F1ABFE71E23F69B1B0ED434B1F5DFF7615C
2880Setup_WebCompanion.exeC:\Users\admin\AppData\Local\Temp\7zS04B85B56\en-US\WebCompanionInstaller.resources.dllexecutable
MD5:8D42954DD718AB37335ED0FB2D18164D
SHA256:D70F2C75A00890453EEA09DAD0A7E0B0AD0F65899B41A8D455BF7A991CAA1866
Download PCAP, analyze network streams, HTTP content and a lot more at the full report
HTTP(S) requests
3
TCP/UDP connections
13
DNS requests
7
Threats
1

HTTP requests

PID
Process
Method
HTTP Code
IP
URL
CN
Type
Size
Reputation
3864
WebCompanionInstaller.exe
GET
104.17.8.52:80
http://geo.lavasoft.com/
US
malicious
3864
WebCompanionInstaller.exe
GET
200
104.17.8.52:80
http://wcdownloadercdn.lavasoft.com/11.4.0.689/WebCompanion-11.4.0.689-prod.zip
US
compressed
18.6 Mb
whitelisted
768
WebCompanion.exe
GET
200
104.17.8.52:80
http://geo.lavasoft.com/
US
binary
49 b
malicious
Download PCAP, analyze network streams, HTTP content and a lot more at the full report

Connections

PID
Process
IP
Domain
ASN
CN
Reputation
2640
svchost.exe
239.255.255.250:1900
whitelisted
1088
svchost.exe
224.0.0.252:5355
unknown
4
System
192.168.100.255:137
whitelisted
768
WebCompanion.exe
104.17.8.52:443
geo.lavasoft.com
CLOUDFLARENET
shared
768
WebCompanion.exe
104.17.8.52:80
geo.lavasoft.com
CLOUDFLARENET
shared
768
WebCompanion.exe
104.18.13.11:443
flwadw.com
CLOUDFLARENET
suspicious
768
WebCompanion.exe
104.18.12.11:443
flwadw.com
CLOUDFLARENET
suspicious
3864
WebCompanionInstaller.exe
104.18.12.11:443
flwadw.com
CLOUDFLARENET
suspicious
3864
WebCompanionInstaller.exe
104.18.13.11:443
flwadw.com
CLOUDFLARENET
suspicious
4
System
192.168.100.255:138
whitelisted

DNS requests

Domain
IP
Reputation
geo.lavasoft.com
  • 104.17.8.52
  • 104.17.9.52
malicious
featureflags.lavasoft.com
  • 104.17.8.52
  • 104.17.9.52
malicious
flwadw.com
  • 104.18.13.11
  • 104.18.12.11
suspicious
dns.msftncsi.com
  • 131.107.255.255
shared
wcdownloadercdn.lavasoft.com
  • 104.17.8.52
  • 104.17.9.52
whitelisted

Threats

PID
Process
Class
Message
3864
WebCompanionInstaller.exe
Potentially Bad Traffic
ET HUNTING Terse Request for Zip File (GET)
Process
Message
WebCompanionInstaller.exe
Detecting windows culture
WebCompanionInstaller.exe
Failed to OpenWcfHost: System.ServiceModel.AddressAccessDeniedException: HTTP could not register URL http://+:9008/webcompanion/. Your process does not have access rights to this namespace (see http://go.microsoft.com/fwlink/?LinkId=70353 for details). ---> System.Net.HttpListenerException: Access is denied at System.Net.HttpListener.AddAllPrefixes() at System.Net.HttpListener.Start() at System.ServiceModel.Channels.SharedHttpTransportManager.OnOpen() --- End of inner exception stack trace --- at System.ServiceModel.Channels.SharedHttpTransportManager.OnOpen() at System.ServiceModel.Channels.TransportManager.Open(TransportChannelListener channelListener) at System.ServiceModel.Channels.TransportManagerContainer.Open(SelectTransportManagersCallback selectTransportManagerCallback) at System.ServiceModel.Channels.TransportChannelListener.OnOpen(TimeSpan timeout) at System.ServiceModel.Channels.HttpChannelListener`1.OnOpen(TimeSpan timeout) at System.ServiceModel.Channels.CommunicationObject.Open(TimeSpan timeout) at System.ServiceModel.Dispatcher.ChannelDispatcher.OnOpen(TimeSpan timeout) at System.ServiceModel.Channels.CommunicationObject.Open(TimeSpan timeout) at System.ServiceModel.ServiceHostBase.OnOpen(TimeSpan timeout) at System.ServiceModel.Channels.CommunicationObject.Open(TimeSpan timeout) at WebCompanionInstaller.App.OpenInstallerWcfHost()
WebCompanionInstaller.exe
Failed to get geo..System.Net.WebException: The operation has timed out at System.Net.HttpWebRequest.GetResponse() at WebCompanionInstaller.Utils.RestUtils.SendGetRequest(String url, IList`1 parameters) at WebCompanionInstaller.Utils.GeoIPService.GetGeo() at WebCompanionInstaller.Utils.GeoIPService.GetCountryISO()
WebCompanionInstaller.exe
Preparing request for featureflag: {"Geo":"US","Partner":"IN220101","Campaign":"16075236377","InstallDate":"20230804","TriggerType":"install","TriggerEvent":"installer","Version":"11.904.0.689","featurewp":true,"featureal":true}
WebCompanionInstaller.exe
Getting response from featureflag: [{"sectionCode":"WAC","code":"WAC","configuration":"{\"Icon\":\"https://webcompanion.com/images/favicon.ico\",\"AppName\":\"Web Companion\",\"Settings\":[\"WCAutoUpdate\",\"EnableGranularity\",\"PostRunV2Action\",\"PostRunTimerAction\",\"EnableTelemetryScan\",\"EnableWebProtection\",\"EnableDynamicNotification\"],\"CompanyName\":\"Lavasoft\",\"ConfigVersion\":\"v1\",\"CurrentVersion\":\"9.3.0\"}","targetId":301},{"sectionCode":"WFAI","code":"WCP","configuration":"{\"Version\": \"3.0.2.12\", \"FilePath\": \"https://rt.webcompanion.com/notifications/download/rt/dci/latest/Webprotection.zip\", \"BlackList\": \"https://acs.lavasoft.com/api/v2/url/blacklist\", \"WhiteList\": \"https://acs.lavasoft.com/api/v2/url/permanentwhitelist\", \"DisplayName\": \"Web Protection\", \"FeatureName\": \"WebProtection\"}","targetId":241}]
WebCompanionInstaller.exe
8/4/2023 3:01:16 PM :-> Starting installer 11.904.0.689 with: .\WebCompanionInstaller.exe --savename=Setup_WebCompanion.exe --partner=IN220101 --nonadmin --direct --tych --campaign=16075236377 --version=11.904.0.689, Run as admin: False
WebCompanionInstaller.exe
Preparing for installing Web Companion
WebCompanionInstaller.exe
8/4/2023 3:02:13 PM :-> Generating Machine and Install Id ...
WebCompanionInstaller.exe
8/4/2023 3:02:13 PM :-> Machine Id and Install Id has been generated
WebCompanionInstaller.exe
8/4/2023 3:02:15 PM :-> Antivirus not detected