File name:

DESKTOP_O6JC5PB_2026-03-03_09_39_30.616.zip

Full analysis: https://app.any.run/tasks/4eef7615-cad9-4f6a-b8a8-dbfda78092f3
Verdict: Malicious activity
Threats:

Adware is a form of malware that targets users with unwanted advertisements, often disrupting their browsing experience. It typically infiltrates systems through software bundling, malicious websites, or deceptive downloads. Once installed, it may track user activity, collect sensitive data, and display intrusive ads, including pop-ups or banners. Some advanced adware variants can bypass security measures and establish persistence on devices, making removal challenging. Additionally, adware can create vulnerabilities that other malware can exploit, posing a significant risk to user privacy and system security.

Analysis date: March 03, 2026, 09:40:56
OS: Windows 10 Professional (build: 19044, 64 bit)
Tags:
adware
adaware
Indicators:
MIME: application/zip
File info: Zip archive data, at least v4.5 to extract, compression method=deflate
MD5:

A75AB2A57CEA363F94C16D2C60B004F7

SHA1:

F9FF9E2A2FB851A8B6BD4D4F6A0A097088EA978A

SHA256:

94A71593A5F8D601AE8F5F645A9C2D4D859E82AA8B8229084FF9185E0A867094

SSDEEP:

24576:Hzg7um0jKWaO5KMx20tjY71Z0eNsZuCotn+fy25+ersTumNAU1jue:Hzg7um0jKWaO5KMx20tjY71Z0eNsZuCg

ANY.RUN is an interactive service which provides full access to the guest system. Information in this report could be distorted by user actions and is provided for user acknowledgement as it is. ANY.RUN does not guarantee maliciousness or safety of the content.
  • MALICIOUS

    • ADAWARE has been detected (SURICATA)

      • WCInstaller.exe (PID: 8324)
      • WebCompanion.exe (PID: 4644)
    • Changes the autorun value in the registry

      • rundll32.exe (PID: 8684)
      • WebCompanion.exe (PID: 4644)
    • Starts NET.EXE for service management

      • WCInstaller.exe (PID: 8324)
      • net.exe (PID: 8124)
    • Changes settings of System certificates

      • WebCompanion.exe (PID: 4644)
  • SUSPICIOUS

    • Access to an unwanted program domain was detected

      • WCInstaller.exe (PID: 8324)
      • WebCompanion.exe (PID: 4644)
    • Executable content was dropped or overwritten

      • WCInstaller.exe (PID: 8324)
      • rundll32.exe (PID: 8684)
    • Drops a system driver (possible attempt to evade defenses)

      • WCInstaller.exe (PID: 8324)
      • rundll32.exe (PID: 8684)
    • Windows service management via SC.EXE

      • sc.exe (PID: 3192)
      • sc.exe (PID: 3020)
      • sc.exe (PID: 9076)
      • sc.exe (PID: 7988)
      • sc.exe (PID: 1084)
      • sc.exe (PID: 6608)
    • The process drops C-runtime libraries

      • WCInstaller.exe (PID: 8324)
    • Restarts service on failure

      • sc.exe (PID: 6212)
    • Executes as Windows Service

      • CompanionService.WinService.exe (PID: 7820)
      • DCIService.exe (PID: 6668)
    • Uses RUNDLL32.EXE to load library

      • WCInstaller.exe (PID: 8324)
    • Creates or modifies Windows services

      • rundll32.exe (PID: 8684)
    • Uses RUNDLL32.EXE to run a file without a DLL extension

      • rundll32.exe (PID: 8684)
    • Executing commands from ".cmd" file

      • WCInstaller.exe (PID: 8324)
    • Starts CMD.EXE for commands execution

      • WCInstaller.exe (PID: 8324)
    • Creates file in the systems drive root

      • DCIService.exe (PID: 6668)
    • Suspicious use of NETSH.EXE

      • cmd.exe (PID: 8224)
    • Searches for installed software

      • WCInstaller.exe (PID: 8324)
      • WebCompanion.exe (PID: 4644)
    • Adds/modifies Windows certificates

      • WebCompanion.exe (PID: 4644)
  • INFO

    • Reads the computer name

      • WCInstaller.exe (PID: 8324)
      • CompanionService.WinService.exe (PID: 7820)
      • DCIService.exe (PID: 6668)
      • WebCompanion.exe (PID: 4644)
    • Reads security settings of Internet Explorer

      • WinRAR.exe (PID: 1840)
      • WCInstaller.exe (PID: 8324)
      • runonce.exe (PID: 5260)
      • WebCompanion.exe (PID: 4644)
    • Executable content was dropped or overwritten

      • WinRAR.exe (PID: 1840)
    • Checks supported languages

      • WCInstaller.exe (PID: 8324)
      • CompanionService.WinService.exe (PID: 7820)
      • DCIService.exe (PID: 6668)
      • WebCompanion.exe (PID: 4644)
    • Creates files in the program directory

      • WCInstaller.exe (PID: 8324)
      • CompanionService.WinService.exe (PID: 7820)
      • DCIService.exe (PID: 6668)
      • WebCompanion.exe (PID: 4644)
    • Checks proxy server information

      • WCInstaller.exe (PID: 8324)
      • WebCompanion.exe (PID: 4644)
    • Disables trace logs

      • WCInstaller.exe (PID: 8324)
      • CompanionService.WinService.exe (PID: 7820)
      • WebCompanion.exe (PID: 4644)
    • Reads the machine GUID from the registry

      • WCInstaller.exe (PID: 8324)
      • CompanionService.WinService.exe (PID: 7820)
      • WebCompanion.exe (PID: 4644)
      • DCIService.exe (PID: 6668)
    • Create files in a temporary directory

      • WCInstaller.exe (PID: 8324)
    • SQLite executable

      • WCInstaller.exe (PID: 8324)
    • The sample compiled with english language support

      • WCInstaller.exe (PID: 8324)
      • rundll32.exe (PID: 8684)
    • There is functionality for taking screenshot (YARA)

      • WCInstaller.exe (PID: 8324)
    • Drops script file

      • WCInstaller.exe (PID: 8324)
      • cmd.exe (PID: 6232)
      • WebCompanion.exe (PID: 4644)
    • Reads Environment values

      • CompanionService.WinService.exe (PID: 7820)
    • Reads the time zone

      • runonce.exe (PID: 5260)
    • Process checks computer location settings

      • WCInstaller.exe (PID: 8324)
    • Creates files in the driver directory

      • rundll32.exe (PID: 8684)
    • Launching a file from a Registry key

      • rundll32.exe (PID: 8684)
      • WebCompanion.exe (PID: 4644)
    • Creates a software uninstall entry

      • WCInstaller.exe (PID: 8324)
    • Creates files or folders in the user directory

      • DCIService.exe (PID: 6668)
      • WCInstaller.exe (PID: 8324)
      • WebCompanion.exe (PID: 4644)
Find more information about signature artifacts and mapping to MITRE ATT&CK™ MATRIX at the full report
No Malware configuration.

TRiD

.zip | ZIP compressed archive (100)

EXIF

ZIP

ZipRequiredVersion: 20
ZipBitFlag: 0x0801
ZipCompression: Deflated
ZipModifyDate: 1980:00:00 00:00:00
ZipCRC: 0x59ddaec4
ZipCompressedSize: 521364
ZipUncompressedSize: 815824
ZipFileName: Device/HarddiskVolume3/Users/LAB3/AppData/Local/Temp/WCInstaller.exe
No data.
screenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshot
All screenshots are available in the full report
All screenshots are available in the full report
Total processes
178
Monitored processes
31
Malicious processes
4
Suspicious processes
1

Behavior graph

Click at the process to see the details

Process information

PID
CMD
Path
Indicators
Parent process
1084"sc.exe" Create "DCIService" binPath= "C:\Program Files (x86)\Lavasoft\Web Companion\Service\x64\DCIService.exe" DisplayName= "DCIService" start= autoC:\Windows\SysWOW64\sc.exeWCInstaller.exe
User:
admin
Company:
Microsoft Corporation
Integrity Level:
HIGH
Description:
Service Control Manager Configuration Tool
Exit code:
0
Version:
10.0.19041.1 (WinBuild.160101.0800)
Modules
Images
c:\windows\syswow64\sc.exe
c:\windows\system32\ntdll.dll
c:\windows\syswow64\ntdll.dll
c:\windows\system32\wow64.dll
c:\windows\system32\wow64win.dll
c:\windows\system32\wow64cpu.dll
c:\windows\syswow64\kernel32.dll
c:\windows\syswow64\kernelbase.dll
c:\windows\syswow64\apphelp.dll
c:\windows\syswow64\msvcrt.dll
1760C:\WINDOWS\system32\net1 start bddciC:\Windows\System32\net1.exenet.exe
User:
admin
Company:
Microsoft Corporation
Integrity Level:
HIGH
Description:
Net Command
Exit code:
0
Version:
10.0.19041.3636 (WinBuild.160101.0800)
Modules
Images
c:\windows\system32\net1.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\sechost.dll
c:\windows\system32\rpcrt4.dll
c:\windows\system32\samcli.dll
c:\windows\system32\bcrypt.dll
c:\windows\system32\ucrtbase.dll
1840"C:\Program Files\WinRAR\WinRAR.exe" C:\Users\admin\AppData\Local\Temp\DESKTOP_O6JC5PB_2026-03-03_09_39_30.616.zipC:\Program Files\WinRAR\WinRAR.exe
explorer.exe
User:
admin
Company:
Alexander Roshal
Integrity Level:
MEDIUM
Description:
WinRAR archiver
Version:
5.91.0
Modules
Images
c:\program files\winrar\winrar.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\user32.dll
c:\windows\system32\win32u.dll
c:\windows\system32\gdi32.dll
c:\windows\system32\gdi32full.dll
c:\windows\system32\msvcp_win.dll
c:\windows\system32\ucrtbase.dll
2496\??\C:\WINDOWS\system32\conhost.exe 0xffffffff -ForceV1C:\Windows\System32\conhost.exesc.exe
User:
admin
Company:
Microsoft Corporation
Integrity Level:
HIGH
Description:
Console Window Host
Exit code:
0
Version:
10.0.19041.1 (WinBuild.160101.0800)
Modules
Images
c:\windows\system32\conhost.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\msvcp_win.dll
c:\windows\system32\ucrtbase.dll
c:\windows\system32\shcore.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\combase.dll
c:\windows\system32\rpcrt4.dll
3020"sc.exe" description "CompanionService" "Ad-Aware Web Companion Internet security service"C:\Windows\SysWOW64\sc.exeWCInstaller.exe
User:
admin
Company:
Microsoft Corporation
Integrity Level:
HIGH
Description:
Service Control Manager Configuration Tool
Exit code:
0
Version:
10.0.19041.1 (WinBuild.160101.0800)
Modules
Images
c:\windows\syswow64\sc.exe
c:\windows\system32\ntdll.dll
c:\windows\syswow64\ntdll.dll
c:\windows\system32\wow64.dll
c:\windows\system32\wow64win.dll
c:\windows\system32\wow64cpu.dll
c:\windows\syswow64\kernel32.dll
c:\windows\syswow64\kernelbase.dll
c:\windows\syswow64\apphelp.dll
c:\windows\syswow64\msvcrt.dll
3192"sc.exe" Create "CompanionService" binPath= "C:\Program Files (x86)\Lavasoft\Web Companion\Application\CompanionService.WinService.exe" DisplayName= "Companion Service" start= autoC:\Windows\SysWOW64\sc.exeWCInstaller.exe
User:
admin
Company:
Microsoft Corporation
Integrity Level:
HIGH
Description:
Service Control Manager Configuration Tool
Exit code:
0
Version:
10.0.19041.1 (WinBuild.160101.0800)
Modules
Images
c:\windows\syswow64\sc.exe
c:\windows\system32\ntdll.dll
c:\windows\syswow64\ntdll.dll
c:\windows\system32\wow64.dll
c:\windows\system32\wow64win.dll
c:\windows\system32\wow64cpu.dll
c:\windows\syswow64\kernel32.dll
c:\windows\syswow64\kernelbase.dll
c:\windows\syswow64\apphelp.dll
c:\windows\syswow64\msvcrt.dll
4644"C:\Program Files (x86)\Lavasoft\Web Companion\Application\WebCompanion.exe" --install --geo= C:\Program Files (x86)\Lavasoft\Web Companion\Application\WebCompanion.exe
WCInstaller.exe
User:
admin
Company:
Lavasoft
Integrity Level:
HIGH
Description:
Web Companion
Version:
14.2.5.13567
Modules
Images
c:\program files (x86)\lavasoft\web companion\application\webcompanion.exe
c:\windows\system32\ntdll.dll
c:\windows\syswow64\ntdll.dll
c:\windows\system32\wow64.dll
c:\windows\system32\wow64win.dll
c:\windows\system32\wow64cpu.dll
c:\windows\syswow64\mscoree.dll
c:\windows\syswow64\kernel32.dll
c:\windows\syswow64\kernelbase.dll
c:\windows\syswow64\apphelp.dll
4700"C:\Users\admin\AppData\Local\Temp\Rar$EXb1840.1018\Device\HarddiskVolume3\Users\LAB3\AppData\Local\Temp\WCInstaller.exe" C:\Users\admin\AppData\Local\Temp\Rar$EXb1840.1018\Device\HarddiskVolume3\Users\LAB3\AppData\Local\Temp\WCInstaller.exeWinRAR.exe
User:
admin
Company:
Lavasoft
Integrity Level:
MEDIUM
Description:
Web Companion
Exit code:
3221226540
Version:
14.2.5.13567
Modules
Images
c:\users\admin\appdata\local\temp\rar$exb1840.1018\device\harddiskvolume3\users\lab3\appdata\local\temp\wcinstaller.exe
c:\windows\system32\ntdll.dll
c:\windows\syswow64\ntdll.dll
4804\??\C:\WINDOWS\system32\conhost.exe 0xffffffff -ForceV1C:\Windows\System32\conhost.exesc.exe
User:
admin
Company:
Microsoft Corporation
Integrity Level:
HIGH
Description:
Console Window Host
Exit code:
0
Version:
10.0.19041.1 (WinBuild.160101.0800)
Modules
Images
c:\windows\system32\conhost.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\msvcp_win.dll
c:\windows\system32\ucrtbase.dll
c:\windows\system32\shcore.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\combase.dll
c:\windows\system32\rpcrt4.dll
5152\??\C:\WINDOWS\system32\conhost.exe 0xffffffff -ForceV1C:\Windows\System32\conhost.execmd.exe
User:
admin
Company:
Microsoft Corporation
Integrity Level:
HIGH
Description:
Console Window Host
Exit code:
0
Version:
10.0.19041.1 (WinBuild.160101.0800)
Modules
Images
c:\windows\system32\conhost.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\msvcp_win.dll
c:\windows\system32\ucrtbase.dll
c:\windows\system32\shcore.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\combase.dll
c:\windows\system32\rpcrt4.dll
Total events
16 561
Read events
16 456
Write events
100
Delete events
5

Modification events

(PID) Process:(1840) WinRAR.exeKey:HKEY_CURRENT_USER\SOFTWARE\WinRAR\FileList\FileColumnWidths
Operation:writeName:name
Value:
120
(PID) Process:(1840) WinRAR.exeKey:HKEY_CURRENT_USER\SOFTWARE\WinRAR\FileList\FileColumnWidths
Operation:writeName:size
Value:
80
(PID) Process:(1840) WinRAR.exeKey:HKEY_CURRENT_USER\SOFTWARE\WinRAR\FileList\FileColumnWidths
Operation:writeName:type
Value:
120
(PID) Process:(1840) WinRAR.exeKey:HKEY_CURRENT_USER\SOFTWARE\WinRAR\FileList\FileColumnWidths
Operation:writeName:mtime
Value:
100
(PID) Process:(1840) WinRAR.exeKey:HKEY_CURRENT_USER\SOFTWARE\WinRAR\ArcHistory
Operation:writeName:3
Value:
C:\Users\admin\Desktop\chromium_ext.zip
(PID) Process:(1840) WinRAR.exeKey:HKEY_CURRENT_USER\SOFTWARE\WinRAR\ArcHistory
Operation:writeName:2
Value:
C:\Users\admin\Desktop\omni_23_10_2024_.zip
(PID) Process:(1840) WinRAR.exeKey:HKEY_CURRENT_USER\SOFTWARE\WinRAR\ArcHistory
Operation:writeName:1
Value:
C:\Users\admin\Downloads\chromium_build 1.zip
(PID) Process:(1840) WinRAR.exeKey:HKEY_CURRENT_USER\SOFTWARE\WinRAR\ArcHistory
Operation:writeName:0
Value:
C:\Users\admin\AppData\Local\Temp\DESKTOP_O6JC5PB_2026-03-03_09_39_30.616.zip
(PID) Process:(1840) WinRAR.exeKey:HKEY_CURRENT_USER\SOFTWARE\WinRAR\Interface
Operation:writeName:ShowPassword
Value:
0
(PID) Process:(8324) WCInstaller.exeKey:HKEY_LOCAL_MACHINE\SOFTWARE\WOW6432Node\Microsoft\Tracing\WCInstaller_RASAPI32
Operation:writeName:EnableFileTracing
Value:
0
Executable files
187
Suspicious files
103
Text files
66
Unknown types
0

Dropped files

PID
Process
Filename
Type
8324WCInstaller.exeC:\Program Files (x86)\Lavasoft\Web Companion\Application\BCUSDK.dllexecutable
MD5:0B1063C14E21A8B3A07E7D3A4B6C6205
SHA256:33AD8242E6FC6B7C71B1B0972DDB972019257933914A7A3110039F95B85E9CCE
1840WinRAR.exeC:\Users\admin\AppData\Local\Temp\Rar$EXb1840.1018\Device\HarddiskVolume3\Users\LAB3\AppData\Local\Temp\WCInstaller.exeexecutable
MD5:478DEA3E7A6F9D2ECC31419E4D5261F2
SHA256:A34551F564CF7D1B649080203EE32B95E6BA5D7C50E2B2481977FC53D8018117
8324WCInstaller.exeC:\Users\admin\AppData\Local\Temp\WC\App.configxml
MD5:4488D78B4AE19275BE35177D9E818BBA
SHA256:B238E109CEA93140470DE6412D5AFEB8663D1AB1785E7D234AB827291629053C
1840WinRAR.exeC:\Users\admin\AppData\Local\Temp\Rar$EXb1840.1018\manifest.jsontext
MD5:AA54B6D33405829C187DA6C70F7E784B
SHA256:1CD8E0503C953BD3D95AF01948417E6063F5B7DF56529BF812CC6C05193E2325
8324WCInstaller.exeC:\Program Files (x86)\Lavasoft\Web Companion\Application\CompanionService.Wcf.dll.configxml
MD5:FE23C4EB3329EF255BE914714ADBF35D
SHA256:C6DC041A92C38FEFA20299ED91E1B1FC4CA8AB83F07C336B149820D160F2EE05
8324WCInstaller.exeC:\ProgramData\Lavasoft\Web Companion\Options\Statistics.txttext
MD5:083D3049B42702C4D3721C77AAC07527
SHA256:78BE6EB878392710078286DD83B2D30FA949FE4A37E3303E61B42B5B7162128D
8324WCInstaller.exeC:\Program Files (x86)\Lavasoft\Web Companion\Application\BCUEngineS.dllexecutable
MD5:DB11C7E28A2E8A680873232C710504D8
SHA256:68AFDEB99C717BAB1C91E6EFC9DAAA6294B1A8C21FCAE0DDE6D564EB57C617AC
8324WCInstaller.exeC:\Program Files (x86)\Lavasoft\Web Companion\Application\CompanionService.Wcf.dllexecutable
MD5:20FC2A8AA591C6CFCBBEE42B1326BC7F
SHA256:588B93A6AAA0BB38321B02889B11D188B56922B5C5081B30BDFBD134544518B7
8324WCInstaller.exeC:\Program Files (x86)\Lavasoft\Web Companion\Application\CompanionService.WinService.exeexecutable
MD5:9B4797365F0F7257FC83FD0C6D1BAF3E
SHA256:031C4F9753F41C8D25AD76B0DF01E6834BA2CEB795E5E0228D4D79305571D210
8324WCInstaller.exeC:\Program Files (x86)\Lavasoft\Web Companion\Application\CompanionService.WinService.exe.configxml
MD5:B3D25C3859D007758FE56B3CB988577F
SHA256:85E6DB0CDA658F5C1382FFC97BF2FBB9BB796434B0E1205A250D7F407582A26F
Download PCAP, analyze network streams, HTTP content and a lot more at the full report
HTTP(S) requests
47
TCP/UDP connections
35
DNS requests
26
Threats
15

HTTP requests

PID
Process
Method
HTTP Code
IP
URL
CN
Type
Size
Reputation
8324
WCInstaller.exe
GET
204
104.16.148.130:443
https://partner-tracking.lavasoft.com/api/tracking/wc?downloadedDate=2026-03-03T09%3A41%3A16.9360363Z
US
unknown
6768
MoUsoCoreWorker.exe
GET
304
4.231.128.59:443
https://settings-win.data.microsoft.com/settings/v3.0/OneSettings/Client?OSVersionFull=10.0.19045.4046.amd64fre.vb_release.191206-1406&LocalDeviceID=s%3ABAD99146-31D3-4EC6-A1A4-BE76F32BA5D4&FlightRing=Retail&AttrDataVer=186&OSUILocale=en-US&OSSkuId=48&App=WOSC&AppVer=&IsFlightingEnabled=0&TelemetryLevel=1&DeviceFamily=Windows.Desktop
US
whitelisted
7564
svchost.exe
GET
304
4.231.128.59:443
https://settings-win.data.microsoft.com/settings/v3.0/WSD/UpdateHealthTools?os=Windows&osVer=10.0.19041.1.amd64fre.vb_release.191206-&sku=48&deviceClass=Windows.Desktop&locale=en-US&deviceId=s:BAD99146-31D3-4EC6-A1A4-BE76F32BA5D4&sampleId=s:95271487&appVer=10.0.19041.3626&FlightRing=Retail&TelemetryLevel=1&HidOverGattReg=C%3A%5CWINDOWS%5CSystem32%5CDriverStore%5CFileRepository%5Chidbthle.inf_amd64_9610b4821fdf82a5%5CMicrosoft.Bluetooth.Profiles.HidOverGatt.dll&AppVer=&ProcessorIdentifier=AMD64%20Family%2023%20Model%201%20Stepping%202&OEMModel=DELL&UpdateOfferedDays=4294967295&ProcessorManufacturer=AuthenticAMD&InstallDate=1661339444&OEMModelBaseBoard=&BranchReadinessLevel=CB&OEMSubModel=J5CR&IsCloudDomainJoined=0&DeferFeatureUpdatePeriodInDays=30&IsDeviceRetailDemo=0&FlightingBranchName=&OSUILocale=en-US&DeviceFamily=Windows.Desktop&WuClientVer=10.0.19041.3996&UninstallActive=1&IsFlightingEnabled=0&OSSkuId=48&ProcessorClockSpeed=3094&TotalPhysicalRAM=6144&SecureBootCapable=0&App=SedimentPack&ProcessorCores=6&CurrentBranch=vb_release&InstallLanguage=en-US&DeferQualityUpdatePeriodInDays=0&OEMName_Uncleaned=DELL&TPMVersion=0&PrimaryDiskTotalCapacity=262144&InstallationType=Client&AttrDataVer=186&ProcessorModel=AMD%20Ryzen%205%203500%206-Core%20Processor&IsEdgeWithChromiumInstalled=1&OSVersion=10.0.19045.4046&IsMDMEnrolled=0&ActivationChannel=Retail&FirmwareVersion=A.40&TrendInstalledKey=1&OSArchitecture=AMD64&DefaultUserRegion=244&UpdateManagementGroup=2
US
whitelisted
8324
WCInstaller.exe
POST
200
104.16.148.130:443
https://featureflags.lavasoft.com/api/feature/WC
US
text
981 b
unknown
8324
WCInstaller.exe
POST
200
104.18.26.149:443
https://flwadw.com/v1/event-stat?Type=Start&ProductID=wc&EventVersion=1
US
text
29 b
unknown
5568
SearchApp.exe
GET
200
184.30.131.245:80
http://ocsp.digicert.com/MFEwTzBNMEswSTAJBgUrDgMCGgUABBTrjrydRyt%2BApF3GSPypfHBxR5XtQQUs9tIpPmhxdiuNkHMEWNpYim8S8YCEAjTxtAB8my1oj8MfWpz%2F7Y%3D
US
binary
314 b
whitelisted
5568
SearchApp.exe
GET
200
204.79.197.203:80
http://oneocsp.microsoft.com/ocsp/MFQwUjBQME4wTDAJBgUrDgMCGgUABBQ3L3%2F%2Fa6ADK8NraY2GXzVaYrHG4AQUb6t%2B2v%2BXQ3LsO2d33oJhNYhHQoUCEzMAAAAGb6JMMcOVb6sAAAAAAAY%3D
US
binary
959 b
whitelisted
356
svchost.exe
POST
200
20.190.159.0:443
https://login.live.com/RST2.srf
US
11.1 Kb
whitelisted
356
svchost.exe
POST
200
20.190.159.0:443
https://login.live.com/RST2.srf
US
10.3 Kb
whitelisted
356
svchost.exe
GET
200
184.30.131.245:80
http://ocsp.digicert.com/MFEwTzBNMEswSTAJBgUrDgMCGgUABBSAUQYBMq2awn1Rh6Doh%2FsBYgFV7gQUA95QNVbRTLtm8KPiGxvDl7I90VUCEAJ0LqoXyo4hxxe7H%2Fz9DKA%3D
US
binary
471 b
whitelisted
Download PCAP, analyze network streams, HTTP content and a lot more at the full report

Connections

PID
Process
IP
Domain
ASN
CN
Reputation
7564
svchost.exe
51.104.136.2:443
settings-win.data.microsoft.com
MICROSOFT-CORP-MSN-AS-BLOCK
US
whitelisted
4
System
192.168.100.255:137
Not routed
whitelisted
7208
RUXIMICS.exe
51.104.136.2:443
settings-win.data.microsoft.com
MICROSOFT-CORP-MSN-AS-BLOCK
US
whitelisted
6768
MoUsoCoreWorker.exe
51.104.136.2:443
settings-win.data.microsoft.com
MICROSOFT-CORP-MSN-AS-BLOCK
US
whitelisted
5568
SearchApp.exe
2.16.241.218:443
www.bing.com
AKAMAI-ASN1
NL
whitelisted
5568
SearchApp.exe
184.30.131.245:80
ocsp.digicert.com
AKAMAI-AS
US
whitelisted
5568
SearchApp.exe
204.79.197.203:80
oneocsp.microsoft.com
MICROSOFT-CORP-MSN-AS-BLOCK
US
whitelisted
3412
svchost.exe
172.211.123.250:443
client.wns.windows.com
MICROSOFT-CORP-MSN-AS-BLOCK
US
whitelisted
4
System
192.168.100.255:138
Not routed
whitelisted
356
svchost.exe
20.190.159.0:443
login.live.com
MICROSOFT-CORP-MSN-AS-BLOCK
US
whitelisted

DNS requests

Domain
IP
Reputation
www.bing.com
  • 2.16.241.218
  • 2.16.241.221
  • 2.16.241.220
  • 2.16.241.217
  • 2.16.241.214
  • 2.16.241.208
  • 2.16.241.209
  • 2.16.241.215
  • 2.16.241.212
whitelisted
ocsp.digicert.com
  • 184.30.131.245
whitelisted
oneocsp.microsoft.com
  • 204.79.197.203
whitelisted
google.com
  • 142.251.141.14
whitelisted
self.events.data.microsoft.com
  • 52.168.117.169
whitelisted
client.wns.windows.com
  • 172.211.123.250
whitelisted
login.live.com
  • 20.190.159.0
  • 40.126.31.129
  • 40.126.31.130
  • 40.126.31.67
  • 20.190.159.64
  • 40.126.31.69
  • 40.126.31.1
  • 20.190.159.23
whitelisted
settings-win.data.microsoft.com
  • 51.104.136.2
  • 4.231.128.59
whitelisted
crl.microsoft.com
  • 2.16.164.120
  • 2.16.164.49
whitelisted
www.microsoft.com
  • 23.222.86.92
  • 88.221.169.152
whitelisted

Threats

PID
Process
Class
Message
7564
svchost.exe
Unknown Traffic
ET USER_AGENTS Microsoft Dr Watson User-Agent (MSDW)
8324
WCInstaller.exe
Possibly Unwanted Program Detected
ADWARE [ANY.RUN] Adaware Web Companion
8324
WCInstaller.exe
Possibly Unwanted Program Detected
ADWARE [ANY.RUN] Adaware Web Companion
8324
WCInstaller.exe
Possibly Unwanted Program Detected
ADWARE [ANY.RUN] Adaware Web Companion
8324
WCInstaller.exe
Possibly Unwanted Program Detected
ADWARE [ANY.RUN] Adaware Web Companion
8324
WCInstaller.exe
Possibly Unwanted Program Detected
ADWARE [ANY.RUN] Adaware Web Companion
8324
WCInstaller.exe
Possibly Unwanted Program Detected
ADWARE [ANY.RUN] Adaware Web Companion
8324
WCInstaller.exe
Possibly Unwanted Program Detected
ADWARE [ANY.RUN] Adaware Web Companion
8324
WCInstaller.exe
Possibly Unwanted Program Detected
ADWARE [ANY.RUN] Adaware Web Companion
8324
WCInstaller.exe
Possibly Unwanted Program Detected
ADWARE [ANY.RUN] Adaware Web Companion
Process
Message
WebCompanion.exe
Native library pre-loader is trying to load native SQLite library "C:\Program Files (x86)\Lavasoft\Web Companion\Application\x86\SQLite.Interop.dll"...
WebCompanion.exe
WebCompanion.exe Error: 0 :
WebCompanion.exe
System.IO.FileNotFoundException: Could not find file 'C:\ProgramData\Lavasoft\Web Companion\Options\EventSafeguard.txt'. File name: 'C:\ProgramData\Lavasoft\Web Companion\Options\EventSafeguard.txt' at System.IO.__Error.WinIOError(Int32 errorCode, String maybeFullPath) at System.IO.File.InternalMove(String sourceFileName, String destFileName, Boolean checkHost) at System.IO.File.Move(String sourceFileName, String destFileName) at Lavasoft.Events.EventSafeguard.RenameSafeguardFile()