File name:

Setup_WebCompanion.exe

Full analysis: https://app.any.run/tasks/a939e134-15c8-41b1-b92e-e207c8a07349
Verdict: Malicious activity
Analysis date: August 04, 2023, 13:59:20
OS: Windows 7 Professional Service Pack 1 (build: 7601, 32 bit)
Tags:
installer
Indicators:
MIME: application/x-dosexec
File info: PE32 executable (GUI) Intel 80386, for MS Windows
MD5:

BAAAE88074273E75505C073215CF24EE

SHA1:

8FC218E1E6F1FA103048D091671773BB4D358440

SHA256:

6DE25D09F4E405BD52E81D21C6DB3C080A7CE49F907CF335DEF0E2728BD3104D

SSDEEP:

12288:VG5knZfFKefG90j92I6qg/hZL4kIwGoqeBzY//OJ1:VG50ZfFKYGw2IVg5ZL4klGg1

ANY.RUN is an interactive service which provides full access to the guest system. Information in this report could be distorted by user actions and is provided for user acknowledgement as it is. ANY.RUN does not guarantee maliciousness or safety of the content.
  • MALICIOUS

    • Application was dropped or rewritten from another process

      • WebCompanionInstaller.exe (PID: 3864)
      • WebCompanion.exe (PID: 768)
    • Loads dropped or rewritten executable

      • WebCompanionInstaller.exe (PID: 3864)
      • WebCompanion.exe (PID: 768)
  • SUSPICIOUS

    • Executable content was dropped or overwritten

      • Setup_WebCompanion.exe (PID: 2880)
      • WebCompanionInstaller.exe (PID: 3864)
    • Searches for installed software

      • WebCompanionInstaller.exe (PID: 3864)
      • WebCompanion.exe (PID: 768)
    • Reads the Internet Settings

      • WebCompanionInstaller.exe (PID: 3864)
      • WebCompanion.exe (PID: 768)
    • Reads settings of System Certificates

      • WebCompanionInstaller.exe (PID: 3864)
      • WebCompanion.exe (PID: 768)
    • The process creates files with name similar to system file names

      • WebCompanionInstaller.exe (PID: 3864)
    • Starts CMD.EXE for commands execution

      • WebCompanionInstaller.exe (PID: 3864)
    • Changes internet zones settings

      • WebCompanionInstaller.exe (PID: 3864)
    • Suspicious use of NETSH.EXE

      • cmd.exe (PID: 2628)
    • Checks Windows Trust Settings

      • WebCompanion.exe (PID: 768)
    • Reads security settings of Internet Explorer

      • WebCompanion.exe (PID: 768)
  • INFO

    • Checks supported languages

      • Setup_WebCompanion.exe (PID: 2880)
      • WebCompanionInstaller.exe (PID: 3864)
      • wmpnscfg.exe (PID: 1048)
      • WebCompanion.exe (PID: 768)
    • Reads the computer name

      • WebCompanionInstaller.exe (PID: 3864)
      • wmpnscfg.exe (PID: 1048)
      • WebCompanion.exe (PID: 768)
    • The process checks LSA protection

      • WebCompanionInstaller.exe (PID: 3864)
      • wisptis.exe (PID: 3832)
      • wmpnscfg.exe (PID: 1048)
      • netsh.exe (PID: 312)
      • WebCompanion.exe (PID: 768)
    • Reads Environment values

      • WebCompanionInstaller.exe (PID: 3864)
      • WebCompanion.exe (PID: 768)
    • Create files in a temporary directory

      • Setup_WebCompanion.exe (PID: 2880)
      • WebCompanionInstaller.exe (PID: 3864)
    • [YARA] HTTP manipulation strings were found

      • WebCompanionInstaller.exe (PID: 3864)
    • Creates files or folders in the user directory

      • WebCompanionInstaller.exe (PID: 3864)
      • WebCompanion.exe (PID: 768)
    • Reads the machine GUID from the registry

      • WebCompanionInstaller.exe (PID: 3864)
      • wmpnscfg.exe (PID: 1048)
      • WebCompanion.exe (PID: 768)
    • Manual execution by a user

      • wmpnscfg.exe (PID: 1048)
    • Creates files in the program directory

      • WebCompanion.exe (PID: 768)
Find more information about signature artifacts and mapping to MITRE ATT&CK™ MATRIX at the full report
No Malware configuration.

TRiD

.exe | InstallShield setup (33)
.exe | Win32 Executable MS Visual C++ (generic) (23.9)
.exe | Win64 Executable (generic) (21.2)
.scr | Windows screen saver (10)
.dll | Win32 Dynamic Link Library (generic) (5)

EXIF

EXE

ProductName: Web Companion Installer
OriginalFileName: Installer.exe
LegalCopyright: c Lavasoft Limited. All Rights Reserved.
InternalName: Installer.exe
FileDescription: Web Companion Installer
CompanyName: Lavasoft
ProductVersion: 11.904.0.689
FileVersion: 11.904.0.689
CharacterSet: Unicode
LanguageCode: English (U.S.)
FileSubtype: -
ObjectFileType: Executable application
FileOS: Windows NT 32-bit
FileFlags: (none)
FileFlagsMask: 0x003f
ProductVersionNumber: 11.904.0.689
FileVersionNumber: 11.904.0.689
Subsystem: Windows GUI
SubsystemVersion: 4
ImageVersion: -
OSVersion: 4
EntryPoint: 0x148d4
UninitializedDataSize: -
InitializedDataSize: 60416
CodeSize: 104448
LinkerVersion: 6
PEType: PE32
ImageFileCharacteristics: No relocs, Executable, No line numbers, No symbols, Large address aware, 32-bit
TimeStamp: 2011:04:18 18:54:06+00:00
MachineType: Intel 386 or later, and compatibles
No data.
screenshotscreenshotscreenshot
All screenshots are available in the full report
All screenshots are available in the full report
Total processes
45
Monitored processes
8
Malicious processes
3
Suspicious processes
0

Behavior graph

Click at the process to see the details
drop and start start drop and start setup_webcompanion.exe webcompanioninstaller.exe wisptis.exe no specs wisptis.exe wmpnscfg.exe no specs cmd.exe no specs netsh.exe no specs webcompanion.exe

Process information

PID
CMD
Path
Indicators
Parent process
312netsh http add urlacl url=http://+:9007/ user=EveryoneC:\Windows\System32\netsh.execmd.exe
User:
admin
Company:
Microsoft Corporation
Integrity Level:
MEDIUM
Description:
Network Command Shell
Exit code:
1
Version:
6.1.7600.16385 (win7_rtm.090713-1255)
Modules
Images
c:\windows\system32\netsh.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\sechost.dll
c:\windows\system32\advapi32.dll
c:\windows\system32\rpcrt4.dll
c:\windows\system32\user32.dll
c:\windows\system32\gdi32.dll
768"C:\Users\admin\AppData\Roaming\Lavasoft\Web Companion\Application\WebCompanion.exe" --install --geo= C:\Users\admin\AppData\Roaming\Lavasoft\Web Companion\Application\WebCompanion.exe
WebCompanionInstaller.exe
User:
admin
Company:
Lavasoft
Integrity Level:
MEDIUM
Description:
Web Companion
Exit code:
0
Version:
11.4.0.689
Modules
Images
c:\users\admin\appdata\roaming\lavasoft\web companion\application\webcompanion.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\mscoree.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\advapi32.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\sechost.dll
c:\windows\system32\rpcrt4.dll
c:\windows\microsoft.net\framework\v4.0.30319\mscoreei.dll
1048"C:\Program Files\Windows Media Player\wmpnscfg.exe"C:\Program Files\Windows Media Player\wmpnscfg.exeexplorer.exe
User:
admin
Company:
Microsoft Corporation
Integrity Level:
MEDIUM
Description:
Windows Media Player Network Sharing Service Configuration Application
Exit code:
0
Version:
12.0.7600.16385 (win7_rtm.090713-1255)
Modules
Images
c:\program files\windows media player\wmpnscfg.exe
c:\windows\system32\kernelbase.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\ntdll.dll
c:\windows\system32\advapi32.dll
c:\windows\system32\sechost.dll
c:\windows\system32\rpcrt4.dll
c:\windows\system32\sspicli.dll
c:\windows\system32\ole32.dll
1368"C:\Windows\SYSTEM32\WISPTIS.EXE" /ManualLaunch;C:\Windows\System32\wisptis.exeWebCompanionInstaller.exe
User:
admin
Company:
Microsoft Corporation
Integrity Level:
MEDIUM
Description:
Microsoft Pen and Touch Input Component
Exit code:
3221226540
Version:
6.1.7600.16385 (win7_rtm.090713-1255)
Modules
Images
c:\windows\system32\ntdll.dll
c:\windows\system32\wisptis.exe
2628"C:\Windows\System32\cmd.exe" /C netsh http add urlacl url=http://+:9007/ user=EveryoneC:\Windows\System32\cmd.exeWebCompanionInstaller.exe
User:
admin
Company:
Microsoft Corporation
Integrity Level:
MEDIUM
Description:
Windows Command Processor
Exit code:
1
Version:
6.1.7601.17514 (win7sp1_rtm.101119-1850)
Modules
Images
c:\windows\system32\cmd.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\winbrand.dll
c:\windows\system32\user32.dll
c:\windows\system32\lpk.dll
c:\windows\system32\gdi32.dll
c:\windows\system32\usp10.dll
2880"C:\Users\admin\AppData\Local\Temp\Setup_WebCompanion.exe" C:\Users\admin\AppData\Local\Temp\Setup_WebCompanion.exe
explorer.exe
User:
admin
Company:
Lavasoft
Integrity Level:
MEDIUM
Description:
Web Companion Installer
Exit code:
0
Version:
11.904.0.689
Modules
Images
c:\users\admin\appdata\local\temp\setup_webcompanion.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\oleaut32.dll
c:\windows\system32\ole32.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\user32.dll
c:\windows\system32\usp10.dll
c:\windows\system32\gdi32.dll
3832"C:\Windows\SYSTEM32\WISPTIS.EXE" /ManualLaunch;C:\Windows\System32\wisptis.exe
WebCompanionInstaller.exe
User:
admin
Company:
Microsoft Corporation
Integrity Level:
HIGH
Description:
Microsoft Pen and Touch Input Component
Exit code:
24
Version:
6.1.7600.16385 (win7_rtm.090713-1255)
Modules
Images
c:\windows\system32\wisptis.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\user32.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\gdi32.dll
c:\windows\system32\lpk.dll
c:\windows\system32\ole32.dll
c:\windows\system32\usp10.dll
3864.\WebCompanionInstaller.exe --savename=Setup_WebCompanion.exe --partner=IN220101 --nonadmin --direct --tych --campaign=16075236377 --version=11.904.0.689C:\Users\admin\AppData\Local\Temp\7zS04B85B56\WebCompanionInstaller.exe
Setup_WebCompanion.exe
User:
admin
Company:
Lavasoft
Integrity Level:
MEDIUM
Description:
Web Companion
Exit code:
0
Version:
11.904.0.689
Modules
Images
c:\users\admin\appdata\local\temp\7zs04b85b56\webcompanioninstaller.exe
c:\windows\system32\mscoree.dll
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\advapi32.dll
c:\windows\system32\sechost.dll
c:\windows\microsoft.net\framework\v4.0.30319\mscoreei.dll
c:\windows\system32\rpcrt4.dll
Total events
8 495
Read events
8 399
Write events
93
Delete events
3

Modification events

(PID) Process:(3864) WebCompanionInstaller.exeKey:HKEY_CLASSES_ROOT\Local Settings\MuiCache\178\52C64B7E
Operation:writeName:LanguageList
Value:
en-US
(PID) Process:(3864) WebCompanionInstaller.exeKey:HKEY_CURRENT_USER\Software\Microsoft\Direct3D\MostRecentApplication
Operation:writeName:Name
Value:
Explorer.EXE
(PID) Process:(3864) WebCompanionInstaller.exeKey:HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap
Operation:writeName:ProxyBypass
Value:
1
(PID) Process:(3864) WebCompanionInstaller.exeKey:HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap
Operation:writeName:IntranetName
Value:
1
(PID) Process:(3864) WebCompanionInstaller.exeKey:HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap
Operation:writeName:UNCAsIntranet
Value:
1
(PID) Process:(3864) WebCompanionInstaller.exeKey:HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap
Operation:writeName:AutoDetect
Value:
0
(PID) Process:(3832) wisptis.exeKey:HKEY_CURRENT_USER\Software\Microsoft\Direct3D\MostRecentApplication
Operation:writeName:Name
Value:
WebCompanionInstaller.exe
(PID) Process:(1048) wmpnscfg.exeKey:HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows Media Player NSS\3.0\Events\{A21DCCE1-8099-454C-BE99-698B990959FA}\{D4BD1867-0ADD-46D9-ACD3-6924BE086355}
Operation:delete keyName:(default)
Value:
(PID) Process:(1048) wmpnscfg.exeKey:HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows Media Player NSS\3.0\Events\{A21DCCE1-8099-454C-BE99-698B990959FA}
Operation:delete keyName:(default)
Value:
(PID) Process:(1048) wmpnscfg.exeKey:HKEY_CURRENT_USER\Software\Microsoft\MediaPlayer\Health\{C1D6A2C0-977F-47E6-92EE-B69FBB6F53C5}
Operation:delete keyName:(default)
Value:
Executable files
94
Suspicious files
14
Text files
17
Unknown types
0

Dropped files

PID
Process
Filename
Type
2880Setup_WebCompanion.exeC:\Users\admin\AppData\Local\Temp\7zS04B85B56\WebCompanionInstaller.exe.configxml
MD5:634D2D29F0ECFEE31F2D1E3C0FE6832D
SHA256:9825E2E2AACB7F01BC779101E6141F1ABFE71E23F69B1B0ED434B1F5DFF7615C
2880Setup_WebCompanion.exeC:\Users\admin\AppData\Local\Temp\7zS04B85B56\WebCompanionInstaller.exeexecutable
MD5:2376204BA2EBE92158D45FA8D7A6C9BF
SHA256:A89679885457ED266DB3C8BD50220CFBE0229BABE84BE4334EF2A01CB219D755
2880Setup_WebCompanion.exeC:\Users\admin\AppData\Local\Temp\7zS04B85B56\ru-RU\WebCompanionInstaller.resources.dllexecutable
MD5:8F15E3AADB5032A2D4C677EDD2117522
SHA256:6ECE4F64535618D51F3357E8763DE232A1903BD1D6A7D338692E992E9786132D
2880Setup_WebCompanion.exeC:\Users\admin\AppData\Local\Temp\7zS04B85B56\tr-TR\WebCompanionInstaller.resources.dllexecutable
MD5:ABD17C89314092FE77C41F8955D43575
SHA256:9337801ABAE112DC677763E67B976796422CCC8B998F29EDD96F1BD93E512169
2880Setup_WebCompanion.exeC:\Users\admin\AppData\Local\Temp\7zS04B85B56\pt-BR\WebCompanionInstaller.resources.dllexecutable
MD5:0BBC570FBD0304EC4BF4185D8616816B
SHA256:4B5613BD7C4AF5CFF9038DC44D63232C016CF673D0F0245B1BE0A635FC9F87AA
2880Setup_WebCompanion.exeC:\Users\admin\AppData\Local\Temp\7zS04B85B56\zh-CHS\WebCompanionInstaller.resources.dllexecutable
MD5:15648622E734510A7DFB2C72888D73EB
SHA256:5A6FFB98E59C82B5EAD46D60D421886F57A11EAAEA4DF4190118FA27667828D1
3864WebCompanionInstaller.exeC:\Users\admin\AppData\Roaming\Lavasoft\Web Companion\Options\Statistics.txtbinary
MD5:9D895A1961610182A0B2FCF00C28EC80
SHA256:73495ED390F5F67B08DE06AE11CDF8A43834C6D07E2BB0CCD9D608B650BD62C2
3864WebCompanionInstaller.exeC:\Users\admin\AppData\Roaming\Lavasoft\Web Companion\Application\acs17.dllexecutable
MD5:F93843D229446C9DBF66F703BBEF9003
SHA256:3F3F583C5D0EF2A0A81DBF85D42BCBE8B5CCA521BD2607012AC3EEC43291151D
3864WebCompanionInstaller.exeC:\Users\admin\AppData\Local\Temp\WebCompanion.zipcompressed
MD5:002CE0B816596F04AFA87451AADE6FB3
SHA256:5577DA4415665135EC16C1D65A9982E67EBC11EE53DAF98AA260815DBFF33B4C
3864WebCompanionInstaller.exeC:\Users\admin\AppData\Roaming\Lavasoft\Web Companion\Application\BCUEngineS.dllexecutable
MD5:517FB375923551E1E6F6377D1CC1C177
SHA256:49372E9F62C6AB31EECEA79FE9E67F33098FE7CA877A423005F1C8D388E1561B
Download PCAP, analyze network streams, HTTP content and a lot more at the full report
HTTP(S) requests
3
TCP/UDP connections
13
DNS requests
7
Threats
1

HTTP requests

PID
Process
Method
HTTP Code
IP
URL
CN
Type
Size
Reputation
3864
WebCompanionInstaller.exe
GET
104.17.8.52:80
http://geo.lavasoft.com/
US
malicious
3864
WebCompanionInstaller.exe
GET
200
104.17.8.52:80
http://wcdownloadercdn.lavasoft.com/11.4.0.689/WebCompanion-11.4.0.689-prod.zip
US
compressed
18.6 Mb
whitelisted
768
WebCompanion.exe
GET
200
104.17.8.52:80
http://geo.lavasoft.com/
US
binary
49 b
malicious
Download PCAP, analyze network streams, HTTP content and a lot more at the full report

Connections

PID
Process
IP
Domain
ASN
CN
Reputation
2640
svchost.exe
239.255.255.250:1900
whitelisted
768
WebCompanion.exe
104.18.13.11:443
flwadw.com
CLOUDFLARENET
suspicious
768
WebCompanion.exe
104.18.12.11:443
flwadw.com
CLOUDFLARENET
suspicious
1088
svchost.exe
224.0.0.252:5355
unknown
4
System
192.168.100.255:137
whitelisted
4
System
192.168.100.255:138
whitelisted
3864
WebCompanionInstaller.exe
104.17.8.52:80
geo.lavasoft.com
CLOUDFLARENET
shared
3864
WebCompanionInstaller.exe
104.17.8.52:443
geo.lavasoft.com
CLOUDFLARENET
shared
3864
WebCompanionInstaller.exe
104.18.13.11:443
flwadw.com
CLOUDFLARENET
suspicious
768
WebCompanion.exe
104.17.8.52:443
geo.lavasoft.com
CLOUDFLARENET
shared

DNS requests

Domain
IP
Reputation
geo.lavasoft.com
  • 104.17.8.52
  • 104.17.9.52
malicious
featureflags.lavasoft.com
  • 104.17.8.52
  • 104.17.9.52
malicious
flwadw.com
  • 104.18.13.11
  • 104.18.12.11
suspicious
dns.msftncsi.com
  • 131.107.255.255
shared
wcdownloadercdn.lavasoft.com
  • 104.17.8.52
  • 104.17.9.52
whitelisted

Threats

PID
Process
Class
Message
3864
WebCompanionInstaller.exe
Potentially Bad Traffic
ET HUNTING Terse Request for Zip File (GET)
Process
Message
WebCompanionInstaller.exe
Detecting windows culture
WebCompanionInstaller.exe
Failed to OpenWcfHost: System.ServiceModel.AddressAccessDeniedException: HTTP could not register URL http://+:9008/webcompanion/. Your process does not have access rights to this namespace (see http://go.microsoft.com/fwlink/?LinkId=70353 for details). ---> System.Net.HttpListenerException: Access is denied at System.Net.HttpListener.AddAllPrefixes() at System.Net.HttpListener.Start() at System.ServiceModel.Channels.SharedHttpTransportManager.OnOpen() --- End of inner exception stack trace --- at System.ServiceModel.Channels.SharedHttpTransportManager.OnOpen() at System.ServiceModel.Channels.TransportManager.Open(TransportChannelListener channelListener) at System.ServiceModel.Channels.TransportManagerContainer.Open(SelectTransportManagersCallback selectTransportManagerCallback) at System.ServiceModel.Channels.TransportChannelListener.OnOpen(TimeSpan timeout) at System.ServiceModel.Channels.HttpChannelListener`1.OnOpen(TimeSpan timeout) at System.ServiceModel.Channels.CommunicationObject.Open(TimeSpan timeout) at System.ServiceModel.Dispatcher.ChannelDispatcher.OnOpen(TimeSpan timeout) at System.ServiceModel.Channels.CommunicationObject.Open(TimeSpan timeout) at System.ServiceModel.ServiceHostBase.OnOpen(TimeSpan timeout) at System.ServiceModel.Channels.CommunicationObject.Open(TimeSpan timeout) at WebCompanionInstaller.App.OpenInstallerWcfHost()
WebCompanionInstaller.exe
Failed to get geo..System.Net.WebException: The operation has timed out at System.Net.HttpWebRequest.GetResponse() at WebCompanionInstaller.Utils.RestUtils.SendGetRequest(String url, IList`1 parameters) at WebCompanionInstaller.Utils.GeoIPService.GetGeo() at WebCompanionInstaller.Utils.GeoIPService.GetCountryISO()
WebCompanionInstaller.exe
Preparing request for featureflag: {"Geo":"US","Partner":"IN220101","Campaign":"16075236377","InstallDate":"20230804","TriggerType":"install","TriggerEvent":"installer","Version":"11.904.0.689","featurewp":true,"featureal":true}
WebCompanionInstaller.exe
Getting response from featureflag: [{"sectionCode":"WAC","code":"WAC","configuration":"{\"Icon\":\"https://webcompanion.com/images/favicon.ico\",\"AppName\":\"Web Companion\",\"Settings\":[\"WCAutoUpdate\",\"EnableGranularity\",\"PostRunV2Action\",\"PostRunTimerAction\",\"EnableTelemetryScan\",\"EnableWebProtection\",\"EnableDynamicNotification\"],\"CompanyName\":\"Lavasoft\",\"ConfigVersion\":\"v1\",\"CurrentVersion\":\"9.3.0\"}","targetId":301},{"sectionCode":"WFAI","code":"WCP","configuration":"{\"Version\": \"3.0.2.12\", \"FilePath\": \"https://rt.webcompanion.com/notifications/download/rt/dci/latest/Webprotection.zip\", \"BlackList\": \"https://acs.lavasoft.com/api/v2/url/blacklist\", \"WhiteList\": \"https://acs.lavasoft.com/api/v2/url/permanentwhitelist\", \"DisplayName\": \"Web Protection\", \"FeatureName\": \"WebProtection\"}","targetId":241}]
WebCompanionInstaller.exe
8/4/2023 3:01:16 PM :-> Starting installer 11.904.0.689 with: .\WebCompanionInstaller.exe --savename=Setup_WebCompanion.exe --partner=IN220101 --nonadmin --direct --tych --campaign=16075236377 --version=11.904.0.689, Run as admin: False
WebCompanionInstaller.exe
Preparing for installing Web Companion
WebCompanionInstaller.exe
8/4/2023 3:02:13 PM :-> Generating Machine and Install Id ...
WebCompanionInstaller.exe
8/4/2023 3:02:13 PM :-> Machine Id and Install Id has been generated
WebCompanionInstaller.exe
8/4/2023 3:02:15 PM :-> Antivirus not detected