File name:

Setup_WebCompanion.exe

Full analysis: https://app.any.run/tasks/a939e134-15c8-41b1-b92e-e207c8a07349
Verdict: Malicious activity
Analysis date: August 04, 2023, 13:59:20
OS: Windows 7 Professional Service Pack 1 (build: 7601, 32 bit)
Tags:
installer
Indicators:
MIME: application/x-dosexec
File info: PE32 executable (GUI) Intel 80386, for MS Windows
MD5:

BAAAE88074273E75505C073215CF24EE

SHA1:

8FC218E1E6F1FA103048D091671773BB4D358440

SHA256:

6DE25D09F4E405BD52E81D21C6DB3C080A7CE49F907CF335DEF0E2728BD3104D

SSDEEP:

12288:VG5knZfFKefG90j92I6qg/hZL4kIwGoqeBzY//OJ1:VG50ZfFKYGw2IVg5ZL4klGg1

ANY.RUN is an interactive service which provides full access to the guest system. Information in this report could be distorted by user actions and is provided for user acknowledgement as it is. ANY.RUN does not guarantee maliciousness or safety of the content.
  • MALICIOUS

    • Application was dropped or rewritten from another process

      • WebCompanionInstaller.exe (PID: 3864)
      • WebCompanion.exe (PID: 768)
    • Loads dropped or rewritten executable

      • WebCompanionInstaller.exe (PID: 3864)
      • WebCompanion.exe (PID: 768)
  • SUSPICIOUS

    • Executable content was dropped or overwritten

      • Setup_WebCompanion.exe (PID: 2880)
      • WebCompanionInstaller.exe (PID: 3864)
    • Searches for installed software

      • WebCompanionInstaller.exe (PID: 3864)
      • WebCompanion.exe (PID: 768)
    • Reads the Internet Settings

      • WebCompanionInstaller.exe (PID: 3864)
      • WebCompanion.exe (PID: 768)
    • Changes internet zones settings

      • WebCompanionInstaller.exe (PID: 3864)
    • The process creates files with name similar to system file names

      • WebCompanionInstaller.exe (PID: 3864)
    • Starts CMD.EXE for commands execution

      • WebCompanionInstaller.exe (PID: 3864)
    • Suspicious use of NETSH.EXE

      • cmd.exe (PID: 2628)
    • Reads settings of System Certificates

      • WebCompanionInstaller.exe (PID: 3864)
      • WebCompanion.exe (PID: 768)
    • Reads security settings of Internet Explorer

      • WebCompanion.exe (PID: 768)
    • Checks Windows Trust Settings

      • WebCompanion.exe (PID: 768)
  • INFO

    • Checks supported languages

      • Setup_WebCompanion.exe (PID: 2880)
      • WebCompanionInstaller.exe (PID: 3864)
      • WebCompanion.exe (PID: 768)
      • wmpnscfg.exe (PID: 1048)
    • Create files in a temporary directory

      • Setup_WebCompanion.exe (PID: 2880)
      • WebCompanionInstaller.exe (PID: 3864)
    • Reads the computer name

      • WebCompanionInstaller.exe (PID: 3864)
      • WebCompanion.exe (PID: 768)
      • wmpnscfg.exe (PID: 1048)
    • Reads the machine GUID from the registry

      • WebCompanionInstaller.exe (PID: 3864)
      • wmpnscfg.exe (PID: 1048)
      • WebCompanion.exe (PID: 768)
    • The process checks LSA protection

      • WebCompanionInstaller.exe (PID: 3864)
      • netsh.exe (PID: 312)
      • wisptis.exe (PID: 3832)
      • wmpnscfg.exe (PID: 1048)
      • WebCompanion.exe (PID: 768)
    • Reads Environment values

      • WebCompanionInstaller.exe (PID: 3864)
      • WebCompanion.exe (PID: 768)
    • Creates files or folders in the user directory

      • WebCompanionInstaller.exe (PID: 3864)
      • WebCompanion.exe (PID: 768)
    • [YARA] HTTP manipulation strings were found

      • WebCompanionInstaller.exe (PID: 3864)
    • Manual execution by a user

      • wmpnscfg.exe (PID: 1048)
    • Creates files in the program directory

      • WebCompanion.exe (PID: 768)
Find more information about signature artifacts and mapping to MITRE ATT&CK™ MATRIX at the full report
No Malware configuration.

TRiD

.exe | InstallShield setup (33)
.exe | Win32 Executable MS Visual C++ (generic) (23.9)
.exe | Win64 Executable (generic) (21.2)
.scr | Windows screen saver (10)
.dll | Win32 Dynamic Link Library (generic) (5)

EXIF

EXE

ProductName: Web Companion Installer
OriginalFileName: Installer.exe
LegalCopyright: c Lavasoft Limited. All Rights Reserved.
InternalName: Installer.exe
FileDescription: Web Companion Installer
CompanyName: Lavasoft
ProductVersion: 11.904.0.689
FileVersion: 11.904.0.689
CharacterSet: Unicode
LanguageCode: English (U.S.)
FileSubtype: -
ObjectFileType: Executable application
FileOS: Windows NT 32-bit
FileFlags: (none)
FileFlagsMask: 0x003f
ProductVersionNumber: 11.904.0.689
FileVersionNumber: 11.904.0.689
Subsystem: Windows GUI
SubsystemVersion: 4
ImageVersion: -
OSVersion: 4
EntryPoint: 0x148d4
UninitializedDataSize: -
InitializedDataSize: 60416
CodeSize: 104448
LinkerVersion: 6
PEType: PE32
ImageFileCharacteristics: No relocs, Executable, No line numbers, No symbols, Large address aware, 32-bit
TimeStamp: 2011:04:18 18:54:06+00:00
MachineType: Intel 386 or later, and compatibles
No data.
screenshotscreenshotscreenshot
All screenshots are available in the full report
All screenshots are available in the full report
Total processes
45
Monitored processes
8
Malicious processes
3
Suspicious processes
0

Behavior graph

Click at the process to see the details
drop and start start drop and start setup_webcompanion.exe webcompanioninstaller.exe wisptis.exe no specs wisptis.exe wmpnscfg.exe no specs cmd.exe no specs netsh.exe no specs webcompanion.exe

Process information

PID
CMD
Path
Indicators
Parent process
312netsh http add urlacl url=http://+:9007/ user=EveryoneC:\Windows\System32\netsh.execmd.exe
User:
admin
Company:
Microsoft Corporation
Integrity Level:
MEDIUM
Description:
Network Command Shell
Exit code:
1
Version:
6.1.7600.16385 (win7_rtm.090713-1255)
Modules
Images
c:\windows\system32\netsh.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\sechost.dll
c:\windows\system32\advapi32.dll
c:\windows\system32\rpcrt4.dll
c:\windows\system32\user32.dll
c:\windows\system32\gdi32.dll
768"C:\Users\admin\AppData\Roaming\Lavasoft\Web Companion\Application\WebCompanion.exe" --install --geo= C:\Users\admin\AppData\Roaming\Lavasoft\Web Companion\Application\WebCompanion.exe
WebCompanionInstaller.exe
User:
admin
Company:
Lavasoft
Integrity Level:
MEDIUM
Description:
Web Companion
Exit code:
0
Version:
11.4.0.689
Modules
Images
c:\users\admin\appdata\roaming\lavasoft\web companion\application\webcompanion.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\mscoree.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\advapi32.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\sechost.dll
c:\windows\system32\rpcrt4.dll
c:\windows\microsoft.net\framework\v4.0.30319\mscoreei.dll
1048"C:\Program Files\Windows Media Player\wmpnscfg.exe"C:\Program Files\Windows Media Player\wmpnscfg.exeexplorer.exe
User:
admin
Company:
Microsoft Corporation
Integrity Level:
MEDIUM
Description:
Windows Media Player Network Sharing Service Configuration Application
Exit code:
0
Version:
12.0.7600.16385 (win7_rtm.090713-1255)
Modules
Images
c:\program files\windows media player\wmpnscfg.exe
c:\windows\system32\kernelbase.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\ntdll.dll
c:\windows\system32\advapi32.dll
c:\windows\system32\sechost.dll
c:\windows\system32\rpcrt4.dll
c:\windows\system32\sspicli.dll
c:\windows\system32\ole32.dll
1368"C:\Windows\SYSTEM32\WISPTIS.EXE" /ManualLaunch;C:\Windows\System32\wisptis.exeWebCompanionInstaller.exe
User:
admin
Company:
Microsoft Corporation
Integrity Level:
MEDIUM
Description:
Microsoft Pen and Touch Input Component
Exit code:
3221226540
Version:
6.1.7600.16385 (win7_rtm.090713-1255)
Modules
Images
c:\windows\system32\ntdll.dll
c:\windows\system32\wisptis.exe
2628"C:\Windows\System32\cmd.exe" /C netsh http add urlacl url=http://+:9007/ user=EveryoneC:\Windows\System32\cmd.exeWebCompanionInstaller.exe
User:
admin
Company:
Microsoft Corporation
Integrity Level:
MEDIUM
Description:
Windows Command Processor
Exit code:
1
Version:
6.1.7601.17514 (win7sp1_rtm.101119-1850)
Modules
Images
c:\windows\system32\cmd.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\winbrand.dll
c:\windows\system32\user32.dll
c:\windows\system32\lpk.dll
c:\windows\system32\gdi32.dll
c:\windows\system32\usp10.dll
2880"C:\Users\admin\AppData\Local\Temp\Setup_WebCompanion.exe" C:\Users\admin\AppData\Local\Temp\Setup_WebCompanion.exe
explorer.exe
User:
admin
Company:
Lavasoft
Integrity Level:
MEDIUM
Description:
Web Companion Installer
Exit code:
0
Version:
11.904.0.689
Modules
Images
c:\users\admin\appdata\local\temp\setup_webcompanion.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\oleaut32.dll
c:\windows\system32\ole32.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\user32.dll
c:\windows\system32\usp10.dll
c:\windows\system32\gdi32.dll
3832"C:\Windows\SYSTEM32\WISPTIS.EXE" /ManualLaunch;C:\Windows\System32\wisptis.exe
WebCompanionInstaller.exe
User:
admin
Company:
Microsoft Corporation
Integrity Level:
HIGH
Description:
Microsoft Pen and Touch Input Component
Exit code:
24
Version:
6.1.7600.16385 (win7_rtm.090713-1255)
Modules
Images
c:\windows\system32\wisptis.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\user32.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\gdi32.dll
c:\windows\system32\lpk.dll
c:\windows\system32\ole32.dll
c:\windows\system32\usp10.dll
3864.\WebCompanionInstaller.exe --savename=Setup_WebCompanion.exe --partner=IN220101 --nonadmin --direct --tych --campaign=16075236377 --version=11.904.0.689C:\Users\admin\AppData\Local\Temp\7zS04B85B56\WebCompanionInstaller.exe
Setup_WebCompanion.exe
User:
admin
Company:
Lavasoft
Integrity Level:
MEDIUM
Description:
Web Companion
Exit code:
0
Version:
11.904.0.689
Modules
Images
c:\users\admin\appdata\local\temp\7zs04b85b56\webcompanioninstaller.exe
c:\windows\system32\mscoree.dll
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\advapi32.dll
c:\windows\system32\sechost.dll
c:\windows\microsoft.net\framework\v4.0.30319\mscoreei.dll
c:\windows\system32\rpcrt4.dll
Total events
8 495
Read events
8 399
Write events
93
Delete events
3

Modification events

(PID) Process:(3864) WebCompanionInstaller.exeKey:HKEY_CLASSES_ROOT\Local Settings\MuiCache\178\52C64B7E
Operation:writeName:LanguageList
Value:
en-US
(PID) Process:(3864) WebCompanionInstaller.exeKey:HKEY_CURRENT_USER\Software\Microsoft\Direct3D\MostRecentApplication
Operation:writeName:Name
Value:
Explorer.EXE
(PID) Process:(3864) WebCompanionInstaller.exeKey:HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap
Operation:writeName:ProxyBypass
Value:
1
(PID) Process:(3864) WebCompanionInstaller.exeKey:HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap
Operation:writeName:IntranetName
Value:
1
(PID) Process:(3864) WebCompanionInstaller.exeKey:HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap
Operation:writeName:UNCAsIntranet
Value:
1
(PID) Process:(3864) WebCompanionInstaller.exeKey:HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap
Operation:writeName:AutoDetect
Value:
0
(PID) Process:(3832) wisptis.exeKey:HKEY_CURRENT_USER\Software\Microsoft\Direct3D\MostRecentApplication
Operation:writeName:Name
Value:
WebCompanionInstaller.exe
(PID) Process:(1048) wmpnscfg.exeKey:HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows Media Player NSS\3.0\Events\{A21DCCE1-8099-454C-BE99-698B990959FA}\{D4BD1867-0ADD-46D9-ACD3-6924BE086355}
Operation:delete keyName:(default)
Value:
(PID) Process:(1048) wmpnscfg.exeKey:HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows Media Player NSS\3.0\Events\{A21DCCE1-8099-454C-BE99-698B990959FA}
Operation:delete keyName:(default)
Value:
(PID) Process:(1048) wmpnscfg.exeKey:HKEY_CURRENT_USER\Software\Microsoft\MediaPlayer\Health\{C1D6A2C0-977F-47E6-92EE-B69FBB6F53C5}
Operation:delete keyName:(default)
Value:
Executable files
94
Suspicious files
14
Text files
17
Unknown types
0

Dropped files

PID
Process
Filename
Type
2880Setup_WebCompanion.exeC:\Users\admin\AppData\Local\Temp\7zS04B85B56\de-DE\WebCompanionInstaller.resources.dllexecutable
MD5:FD407782A62399C21588100C830A609D
SHA256:64B8242A3178E4D71AF140791DCD5DCE2309C5A960AA2025F51946609D1197E9
2880Setup_WebCompanion.exeC:\Users\admin\AppData\Local\Temp\7zS04B85B56\es-ES\WebCompanionInstaller.resources.dllexecutable
MD5:79E5C8F8681E07E0438B0A7A0CD63249
SHA256:E66BBBF54CEA7DB58DE5B3F4DF8B1D6ADB3B30B2D72DEF616F46BEB2635DDBB6
3864WebCompanionInstaller.exeC:\Users\admin\AppData\Roaming\Lavasoft\Web Companion\Options\Statistics.txtbinary
MD5:9D895A1961610182A0B2FCF00C28EC80
SHA256:73495ED390F5F67B08DE06AE11CDF8A43834C6D07E2BB0CCD9D608B650BD62C2
2880Setup_WebCompanion.exeC:\Users\admin\AppData\Local\Temp\7zS04B85B56\en-US\WebCompanionInstaller.resources.dllexecutable
MD5:8D42954DD718AB37335ED0FB2D18164D
SHA256:D70F2C75A00890453EEA09DAD0A7E0B0AD0F65899B41A8D455BF7A991CAA1866
2880Setup_WebCompanion.exeC:\Users\admin\AppData\Local\Temp\7zS04B85B56\Newtonsoft.Json.dllexecutable
MD5:B4C13884516B327C813F7B3E7C5D8135
SHA256:B1A466D22198D9B04A8943083A08BA26336D8D9A6757F1E59A94344D368E4272
2880Setup_WebCompanion.exeC:\Users\admin\AppData\Local\Temp\7zS04B85B56\fr-CA\WebCompanionInstaller.resources.dllexecutable
MD5:93338D11C67D649A2EEDF5A2CACC4AC1
SHA256:6491BB8426F8761E36E8A6CD5AA9363DE09D5D495A9A894E87C37F07C09AF107
2880Setup_WebCompanion.exeC:\Users\admin\AppData\Local\Temp\7zS04B85B56\ICSharpCode.SharpZipLib.dllexecutable
MD5:88831780ABDAAD0E70D643DF3226D312
SHA256:656DFCD0F02278C7F4ABA97996D1D6BA06D7D463D0139C29C6507A518EBC5CEC
2880Setup_WebCompanion.exeC:\Users\admin\AppData\Local\Temp\7zS04B85B56\pt-BR\WebCompanionInstaller.resources.dllexecutable
MD5:0BBC570FBD0304EC4BF4185D8616816B
SHA256:4B5613BD7C4AF5CFF9038DC44D63232C016CF673D0F0245B1BE0A635FC9F87AA
2880Setup_WebCompanion.exeC:\Users\admin\AppData\Local\Temp\7zS04B85B56\ja-JP\WebCompanionInstaller.resources.dllexecutable
MD5:D315FD206AAE3DF3489E7863A949E518
SHA256:C59560241CCA5D8F7CFAD2C8434CDDF366A501A3BA0DB119CB663EA3E7270DFF
2880Setup_WebCompanion.exeC:\Users\admin\AppData\Local\Temp\7zS04B85B56\it-IT\WebCompanionInstaller.resources.dllexecutable
MD5:449C45BC1F350488B843C472996222A1
SHA256:0191552F49FE45AD89128D496BD9F9837BC5BB5B68C0FA9A0D0D08775B45069F
Download PCAP, analyze network streams, HTTP content and a lot more at the full report
HTTP(S) requests
3
TCP/UDP connections
13
DNS requests
7
Threats
1

HTTP requests

PID
Process
Method
HTTP Code
IP
URL
CN
Type
Size
Reputation
3864
WebCompanionInstaller.exe
GET
104.17.8.52:80
http://geo.lavasoft.com/
US
malicious
3864
WebCompanionInstaller.exe
GET
200
104.17.8.52:80
http://wcdownloadercdn.lavasoft.com/11.4.0.689/WebCompanion-11.4.0.689-prod.zip
US
compressed
18.6 Mb
whitelisted
768
WebCompanion.exe
GET
200
104.17.8.52:80
http://geo.lavasoft.com/
US
binary
49 b
malicious
Download PCAP, analyze network streams, HTTP content and a lot more at the full report

Connections

PID
Process
IP
Domain
ASN
CN
Reputation
768
WebCompanion.exe
104.18.12.11:443
flwadw.com
CLOUDFLARENET
suspicious
2640
svchost.exe
239.255.255.250:1900
whitelisted
1088
svchost.exe
224.0.0.252:5355
unknown
4
System
192.168.100.255:137
whitelisted
4
System
192.168.100.255:138
whitelisted
3864
WebCompanionInstaller.exe
104.17.8.52:80
geo.lavasoft.com
CLOUDFLARENET
shared
3864
WebCompanionInstaller.exe
104.17.8.52:443
geo.lavasoft.com
CLOUDFLARENET
shared
3864
WebCompanionInstaller.exe
104.18.13.11:443
flwadw.com
CLOUDFLARENET
suspicious
768
WebCompanion.exe
104.17.8.52:443
geo.lavasoft.com
CLOUDFLARENET
shared
768
WebCompanion.exe
104.18.13.11:443
flwadw.com
CLOUDFLARENET
suspicious

DNS requests

Domain
IP
Reputation
geo.lavasoft.com
  • 104.17.8.52
  • 104.17.9.52
malicious
featureflags.lavasoft.com
  • 104.17.8.52
  • 104.17.9.52
malicious
flwadw.com
  • 104.18.13.11
  • 104.18.12.11
suspicious
dns.msftncsi.com
  • 131.107.255.255
shared
wcdownloadercdn.lavasoft.com
  • 104.17.8.52
  • 104.17.9.52
whitelisted

Threats

PID
Process
Class
Message
3864
WebCompanionInstaller.exe
Potentially Bad Traffic
ET HUNTING Terse Request for Zip File (GET)
Process
Message
WebCompanionInstaller.exe
Detecting windows culture
WebCompanionInstaller.exe
Failed to OpenWcfHost: System.ServiceModel.AddressAccessDeniedException: HTTP could not register URL http://+:9008/webcompanion/. Your process does not have access rights to this namespace (see http://go.microsoft.com/fwlink/?LinkId=70353 for details). ---> System.Net.HttpListenerException: Access is denied at System.Net.HttpListener.AddAllPrefixes() at System.Net.HttpListener.Start() at System.ServiceModel.Channels.SharedHttpTransportManager.OnOpen() --- End of inner exception stack trace --- at System.ServiceModel.Channels.SharedHttpTransportManager.OnOpen() at System.ServiceModel.Channels.TransportManager.Open(TransportChannelListener channelListener) at System.ServiceModel.Channels.TransportManagerContainer.Open(SelectTransportManagersCallback selectTransportManagerCallback) at System.ServiceModel.Channels.TransportChannelListener.OnOpen(TimeSpan timeout) at System.ServiceModel.Channels.HttpChannelListener`1.OnOpen(TimeSpan timeout) at System.ServiceModel.Channels.CommunicationObject.Open(TimeSpan timeout) at System.ServiceModel.Dispatcher.ChannelDispatcher.OnOpen(TimeSpan timeout) at System.ServiceModel.Channels.CommunicationObject.Open(TimeSpan timeout) at System.ServiceModel.ServiceHostBase.OnOpen(TimeSpan timeout) at System.ServiceModel.Channels.CommunicationObject.Open(TimeSpan timeout) at WebCompanionInstaller.App.OpenInstallerWcfHost()
WebCompanionInstaller.exe
Failed to get geo..System.Net.WebException: The operation has timed out at System.Net.HttpWebRequest.GetResponse() at WebCompanionInstaller.Utils.RestUtils.SendGetRequest(String url, IList`1 parameters) at WebCompanionInstaller.Utils.GeoIPService.GetGeo() at WebCompanionInstaller.Utils.GeoIPService.GetCountryISO()
WebCompanionInstaller.exe
Preparing request for featureflag: {"Geo":"US","Partner":"IN220101","Campaign":"16075236377","InstallDate":"20230804","TriggerType":"install","TriggerEvent":"installer","Version":"11.904.0.689","featurewp":true,"featureal":true}
WebCompanionInstaller.exe
Getting response from featureflag: [{"sectionCode":"WAC","code":"WAC","configuration":"{\"Icon\":\"https://webcompanion.com/images/favicon.ico\",\"AppName\":\"Web Companion\",\"Settings\":[\"WCAutoUpdate\",\"EnableGranularity\",\"PostRunV2Action\",\"PostRunTimerAction\",\"EnableTelemetryScan\",\"EnableWebProtection\",\"EnableDynamicNotification\"],\"CompanyName\":\"Lavasoft\",\"ConfigVersion\":\"v1\",\"CurrentVersion\":\"9.3.0\"}","targetId":301},{"sectionCode":"WFAI","code":"WCP","configuration":"{\"Version\": \"3.0.2.12\", \"FilePath\": \"https://rt.webcompanion.com/notifications/download/rt/dci/latest/Webprotection.zip\", \"BlackList\": \"https://acs.lavasoft.com/api/v2/url/blacklist\", \"WhiteList\": \"https://acs.lavasoft.com/api/v2/url/permanentwhitelist\", \"DisplayName\": \"Web Protection\", \"FeatureName\": \"WebProtection\"}","targetId":241}]
WebCompanionInstaller.exe
8/4/2023 3:01:16 PM :-> Starting installer 11.904.0.689 with: .\WebCompanionInstaller.exe --savename=Setup_WebCompanion.exe --partner=IN220101 --nonadmin --direct --tych --campaign=16075236377 --version=11.904.0.689, Run as admin: False
WebCompanionInstaller.exe
Preparing for installing Web Companion
WebCompanionInstaller.exe
8/4/2023 3:02:13 PM :-> Generating Machine and Install Id ...
WebCompanionInstaller.exe
8/4/2023 3:02:13 PM :-> Machine Id and Install Id has been generated
WebCompanionInstaller.exe
8/4/2023 3:02:15 PM :-> Antivirus not detected