download:

lsop.exe

Full analysis: https://app.any.run/tasks/b371bea2-a3bd-4915-837a-f6b419a102ab
Verdict: Malicious activity
Threats:

Adware is a form of malware that targets users with unwanted advertisements, often disrupting their browsing experience. It typically infiltrates systems through software bundling, malicious websites, or deceptive downloads. Once installed, it may track user activity, collect sensitive data, and display intrusive ads, including pop-ups or banners. Some advanced adware variants can bypass security measures and establish persistence on devices, making removal challenging. Additionally, adware can create vulnerabilities that other malware can exploit, posing a significant risk to user privacy and system security.

Analysis date: October 16, 2019, 10:23:47
OS: Windows 7 Professional Service Pack 1 (build: 7601, 32 bit)
Tags:
installer
adware
pua
lavasoft
loader
Indicators:
MIME: application/x-dosexec
File info: PE32 executable (GUI) Intel 80386, for MS Windows
MD5:

119BDE97A29C1F21B5247E3E2A98FB5E

SHA1:

66CA8C7043A37DC4CDD053CDBAB45E8E9B05ABFC

SHA256:

AAB1FCA8AD2EE36C655B04CBC3473E01FB8BA18F70E9FFE10010779F5963ED0A

SSDEEP:

24576:4G50ZfFK+Oc5YK33r9tOBVXM0qWEiOxH0pn+k1TfpDsgxqjuv:4G5Ufgzc5DbOBVXnqWEz+p+uT11xQuv

ANY.RUN is an interactive service which provides full access to the guest system. Information in this report could be distorted by user actions and is provided for user acknowledgement as it is. ANY.RUN does not guarantee maliciousness or safety of the content.
  • MALICIOUS

    • Application was dropped or rewritten from another process

      • GenericSetup.exe (PID: 3796)
      • installer.exe (PID: 1296)
      • installer.exe (PID: 2396)
      • OfferInstaller.exe (PID: 2968)
      • pecbfbgt.fgh.exe (PID: 1712)
      • pecbfbgt.fgh.exe (PID: 2580)
      • pecbfbgt.fgh.exe (PID: 2556)
      • WebCompanionInstaller.exe (PID: 408)
      • WebCompanion.exe (PID: 4060)
      • Lavasoft.WCAssistant.WinService.exe (PID: 2144)
    • Loads dropped or rewritten executable

      • GenericSetup.exe (PID: 3796)
      • OfferInstaller.exe (PID: 2968)
      • WebCompanionInstaller.exe (PID: 408)
      • WebCompanion.exe (PID: 4060)
    • LAVASOFT was detected

      • installer.exe (PID: 1296)
    • Downloads executable files from the Internet

      • OfferInstaller.exe (PID: 2968)
    • Changes internet zones settings

      • WebCompanionInstaller.exe (PID: 408)
    • Changes the autorun value in the registry

      • WebCompanion.exe (PID: 4060)
  • SUSPICIOUS

    • Executable content was dropped or overwritten

      • lsop.exe (PID: 1556)
      • OfferInstaller.exe (PID: 2968)
      • pecbfbgt.fgh.exe (PID: 2556)
      • WebCompanionInstaller.exe (PID: 408)
    • Reads Environment values

      • GenericSetup.exe (PID: 3796)
      • OfferInstaller.exe (PID: 2968)
    • Reads the Windows organization settings

      • GenericSetup.exe (PID: 3796)
      • OfferInstaller.exe (PID: 2968)
    • Reads Windows owner or organization settings

      • GenericSetup.exe (PID: 3796)
      • OfferInstaller.exe (PID: 2968)
    • Starts CMD.EXE for commands execution

      • OfferInstaller.exe (PID: 2968)
      • WebCompanionInstaller.exe (PID: 408)
    • Creates files in the user directory

      • WebCompanionInstaller.exe (PID: 408)
    • Creates a software uninstall entry

      • WebCompanionInstaller.exe (PID: 408)
    • Creates files in the program directory

      • WebCompanionInstaller.exe (PID: 408)
      • WebCompanion.exe (PID: 4060)
    • Starts SC.EXE for service management

      • WebCompanionInstaller.exe (PID: 408)
    • Executed as Windows Service

      • Lavasoft.WCAssistant.WinService.exe (PID: 2144)
    • Creates files in the Windows directory

      • Lavasoft.WCAssistant.WinService.exe (PID: 2144)
    • Uses NETSH.EXE for network configuration

      • cmd.exe (PID: 1428)
    • Searches for installed software

      • GenericSetup.exe (PID: 3796)
  • INFO

    • Manual execution by user

      • lsop.exe (PID: 2108)
      • explorer.exe (PID: 3916)
    • Dropped object may contain Bitcoin addresses

      • WebCompanionInstaller.exe (PID: 408)
Find more information about signature artifacts and mapping to MITRE ATT&CK™ MATRIX at the full report
No Malware configuration.

TRiD

.exe | InstallShield setup (36.8)
.exe | Win32 Executable MS Visual C++ (generic) (26.6)
.exe | Win64 Executable (generic) (23.6)
.dll | Win32 Dynamic Link Library (generic) (5.6)
.exe | Win32 Executable (generic) (3.8)

EXIF

EXE

MachineType: Intel 386 or later, and compatibles
TimeStamp: 2011:04:18 20:54:06+02:00
PEType: PE32
LinkerVersion: 6
CodeSize: 104448
InitializedDataSize: 36864
UninitializedDataSize: -
EntryPoint: 0x148d4
OSVersion: 4
ImageVersion: -
SubsystemVersion: 4
Subsystem: Windows GUI
FileVersionNumber: 2.5.2.6324
ProductVersionNumber: 2.5.2.6324
FileFlagsMask: 0x003f
FileFlags: (none)
FileOS: Windows NT 32-bit
ObjectFileType: Executable application
FileSubtype: -
LanguageCode: English (U.S.)
CharacterSet: Unicode
FileVersion: 2.5.2.6324
ProductVersion: 2.5.2.6324
CompanyName: pdfforge GmbH
FileDescription: PDFCreator is the easy way of creating PDFs.
InternalName: PDFCreator.exe
LegalCopyright: \A9 pdfforge GmbH
OriginalFileName: PDFCreator.exe
ProductName: PDFCreator
No data.
screenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshot
All screenshots are available in the full report
All screenshots are available in the full report
Total processes
65
Monitored processes
19
Malicious processes
9
Suspicious processes
0

Behavior graph

Click at the process to see the details
drop and start start drop and start drop and start lsop.exe #LAVASOFT installer.exe genericsetup.exe explorer.exe no specs lsop.exe no specs installer.exe no specs offerinstaller.exe cmd.exe no specs pecbfbgt.fgh.exe no specs pecbfbgt.fgh.exe no specs pecbfbgt.fgh.exe webcompanioninstaller.exe sc.exe no specs sc.exe no specs sc.exe no specs cmd.exe no specs netsh.exe no specs webcompanion.exe lavasoft.wcassistant.winservice.exe

Process information

PID
CMD
Path
Indicators
Parent process
408.\WebCompanionInstaller.exe --partner=PF170501 --version=4.8.2078.3950 --prod --silent --homepage=1 --search=1 --partner=PF170501C:\Users\admin\AppData\Local\Temp\7zS2FE.tmp\WebCompanionInstaller.exe
pecbfbgt.fgh.exe
User:
admin
Company:
Lavasoft
Integrity Level:
HIGH
Description:
Web Companion
Exit code:
0
Version:
4.8.2078.3950
Modules
Images
c:\users\admin\appdata\local\temp\7zs2fe.tmp\webcompanioninstaller.exe
c:\systemroot\system32\ntdll.dll
c:\windows\system32\mscoree.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\apphelp.dll
c:\windows\apppatch\acgenral.dll
c:\windows\system32\sechost.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\rpcrt4.dll
1296.\installer.exeC:\Users\admin\AppData\Local\Temp\7zS41644AA9\installer.exe
lsop.exe
User:
admin
Company:
adaware
Integrity Level:
MEDIUM
Description:
PDFCreator is the easy way of creating PDFs.
Exit code:
0
Version:
2.7.2.1576
Modules
Images
c:\users\admin\appdata\local\temp\7zs41644aa9\installer.exe
c:\systemroot\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\ws2_32.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\rpcrt4.dll
c:\windows\system32\nsi.dll
c:\windows\system32\gdi32.dll
c:\windows\system32\lpk.dll
1428"C:\Windows\System32\cmd.exe" /C netsh http add urlacl url=http://+:9007/ user=EveryoneC:\Windows\System32\cmd.exeWebCompanionInstaller.exe
User:
admin
Company:
Microsoft Corporation
Integrity Level:
HIGH
Description:
Windows Command Processor
Exit code:
0
Version:
6.1.7601.17514 (win7sp1_rtm.101119-1850)
Modules
Images
c:\windows\system32\cmd.exe
c:\systemroot\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\winbrand.dll
c:\windows\system32\user32.dll
c:\windows\system32\gdi32.dll
c:\windows\system32\lpk.dll
c:\windows\system32\usp10.dll
1556"C:\Users\admin\AppData\Local\Temp\lsop.exe" C:\Users\admin\AppData\Local\Temp\lsop.exe
explorer.exe
User:
admin
Company:
pdfforge GmbH
Integrity Level:
MEDIUM
Description:
PDFCreator is the easy way of creating PDFs.
Exit code:
0
Version:
2.5.2.6324
Modules
Images
c:\users\admin\appdata\local\temp\lsop.exe
c:\systemroot\system32\ntdll.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\oleaut32.dll
c:\windows\system32\ole32.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\gdi32.dll
c:\windows\system32\user32.dll
c:\windows\system32\lpk.dll
1712"C:\Users\admin\AppData\Local\Temp\pecbfbgt.fgh.exe" --silent --homepage=1 --search=1 --partner=PF170501C:\Users\admin\AppData\Local\Temp\pecbfbgt.fgh.execmd.exe
User:
admin
Company:
Lavasoft
Integrity Level:
MEDIUM
Description:
Web Companion Installer
Exit code:
3221226540
Version:
4.8.2078.3950
Modules
Images
c:\users\admin\appdata\local\temp\pecbfbgt.fgh.exe
c:\systemroot\system32\ntdll.dll
1784netsh http add urlacl url=http://+:9007/ user=EveryoneC:\Windows\system32\netsh.execmd.exe
User:
admin
Company:
Microsoft Corporation
Integrity Level:
HIGH
Description:
Network Command Shell
Exit code:
0
Version:
6.1.7600.16385 (win7_rtm.090713-1255)
Modules
Images
c:\windows\system32\netsh.exe
c:\systemroot\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\advapi32.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\sechost.dll
c:\windows\system32\rpcrt4.dll
c:\windows\system32\credui.dll
c:\windows\system32\user32.dll
2108"C:\Users\admin\AppData\Local\Temp\lsop.exe" C:\Users\admin\AppData\Local\Temp\lsop.exeexplorer.exe
User:
admin
Company:
pdfforge GmbH
Integrity Level:
MEDIUM
Description:
PDFCreator is the easy way of creating PDFs.
Exit code:
0
Version:
2.5.2.6324
Modules
Images
c:\users\admin\appdata\local\temp\lsop.exe
c:\systemroot\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\oleaut32.dll
c:\windows\system32\ole32.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\gdi32.dll
c:\windows\system32\user32.dll
c:\windows\system32\lpk.dll
2144"C:\Program Files\Lavasoft\Web Companion\Application\Lavasoft.WCAssistant.WinService.exe"C:\Program Files\Lavasoft\Web Companion\Application\Lavasoft.WCAssistant.WinService.exe
services.exe
User:
SYSTEM
Integrity Level:
SYSTEM
Description:
SPWindowsService
Exit code:
0
Version:
1.0.0.0
Modules
Images
c:\program files\lavasoft\web companion\application\lavasoft.wcassistant.winservice.exe
c:\systemroot\system32\ntdll.dll
c:\windows\system32\mscoree.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\advapi32.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\sechost.dll
c:\windows\system32\rpcrt4.dll
c:\windows\microsoft.net\framework\v4.0.30319\mscoreei.dll
2396.\installer.exeC:\Users\admin\AppData\Local\Temp\7zSC387516A\installer.exelsop.exe
User:
admin
Integrity Level:
MEDIUM
Exit code:
0
Modules
Images
c:\users\admin\appdata\local\temp\7zsc387516a\installer.exe
c:\systemroot\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\ws2_32.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\rpcrt4.dll
c:\windows\system32\nsi.dll
c:\windows\system32\user32.dll
c:\windows\system32\gdi32.dll
2400"sc.exe" description "WCAssistantService" "Ad-Aware Web Companion Internet security service"C:\Windows\system32\sc.exeWebCompanionInstaller.exe
User:
admin
Company:
Microsoft Corporation
Integrity Level:
HIGH
Description:
A tool to aid in developing services for WindowsNT
Exit code:
0
Version:
6.1.7600.16385 (win7_rtm.090713-1255)
Modules
Images
c:\windows\system32\sc.exe
c:\systemroot\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\advapi32.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\sechost.dll
c:\windows\system32\rpcrt4.dll
c:\windows\system32\apphelp.dll
Total events
7 082
Read events
6 899
Write events
183
Delete events
0

Modification events

(PID) Process:(3796) GenericSetup.exeKey:HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap
Operation:writeName:UNCAsIntranet
Value:
0
(PID) Process:(3796) GenericSetup.exeKey:HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap
Operation:writeName:AutoDetect
Value:
1
(PID) Process:(3796) GenericSetup.exeKey:HKEY_CLASSES_ROOT\Local Settings\MuiCache\12B\52C64B7E
Operation:writeName:LanguageList
Value:
en-US
(PID) Process:(3796) GenericSetup.exeKey:HKEY_CLASSES_ROOT\Local Settings\MuiCache\12B\52C64B7E
Operation:writeName:@%SystemRoot%\system32\p2pcollab.dll,-8042
Value:
Peer to Peer Trust
(PID) Process:(3796) GenericSetup.exeKey:HKEY_CLASSES_ROOT\Local Settings\MuiCache\12B\52C64B7E
Operation:writeName:@%SystemRoot%\system32\qagentrt.dll,-10
Value:
System Health Authentication
(PID) Process:(3796) GenericSetup.exeKey:HKEY_CLASSES_ROOT\Local Settings\MuiCache\12B\52C64B7E
Operation:writeName:@%SystemRoot%\system32\dnsapi.dll,-103
Value:
Domain Name System (DNS) Server Trust
(PID) Process:(3796) GenericSetup.exeKey:HKEY_CLASSES_ROOT\Local Settings\MuiCache\12B\52C64B7E
Operation:writeName:@%SystemRoot%\System32\fveui.dll,-843
Value:
BitLocker Drive Encryption
(PID) Process:(3796) GenericSetup.exeKey:HKEY_CLASSES_ROOT\Local Settings\MuiCache\12B\52C64B7E
Operation:writeName:@%SystemRoot%\System32\fveui.dll,-844
Value:
BitLocker Data Recovery Agent
(PID) Process:(2968) OfferInstaller.exeKey:HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap
Operation:writeName:UNCAsIntranet
Value:
0
(PID) Process:(2968) OfferInstaller.exeKey:HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap
Operation:writeName:AutoDetect
Value:
1
Executable files
91
Suspicious files
5
Text files
144
Unknown types
3

Dropped files

PID
Process
Filename
Type
2108lsop.exeC:\Users\admin\AppData\Local\Temp\7zSC387516A\BundleConfig.xml
MD5:
SHA256:
2108lsop.exeC:\Users\admin\AppData\Local\Temp\7zSC387516A\GenericSetup.exe.config
MD5:
SHA256:
2108lsop.exeC:\Users\admin\AppData\Local\Temp\7zSC387516A\OfferInstaller.exe.config
MD5:
SHA256:
2108lsop.exeC:\Users\admin\AppData\Local\Temp\7zSC387516A\GenericSetup.exe
MD5:
SHA256:
2108lsop.exeC:\Users\admin\AppData\Local\Temp\7zSC387516A\installer.exe
MD5:
SHA256:
2108lsop.exeC:\Users\admin\AppData\Local\Temp\7zSC387516A\OfferInstaller.exe
MD5:
SHA256:
2108lsop.exeC:\Users\admin\AppData\Local\Temp\7zSC387516A\DevLib.dll
MD5:
SHA256:
2108lsop.exeC:\Users\admin\AppData\Local\Temp\7zSC387516A\en\DevLib.resources.dll
MD5:
SHA256:
2108lsop.exeC:\Users\admin\AppData\Local\Temp\7zSC387516A\fr\DevLib.resources.dll
MD5:
SHA256:
2108lsop.exeC:\Users\admin\AppData\Local\Temp\7zSC387516A\de\DevLib.resources.dll
MD5:
SHA256:
Download PCAP, analyze network streams, HTTP content and a lot more at the full report
HTTP(S) requests
34
TCP/UDP connections
19
DNS requests
15
Threats
4

HTTP requests

PID
Process
Method
HTTP Code
IP
URL
CN
Type
Size
Reputation
3796
GenericSetup.exe
POST
200
104.16.236.79:80
http://sos.adaware.com/v1/bundle/list/?bundleId=PF002
US
text
6.70 Kb
whitelisted
408
WebCompanionInstaller.exe
POST
200
64.18.87.82:80
http://wc-update-service.lavasoft.com/update.asmx
CA
xml
1.45 Kb
whitelisted
408
WebCompanionInstaller.exe
GET
200
104.18.87.101:80
http://wcdownloadercdn.lavasoft.com/4.8.2078.3950/WebCompanion-4.8.2078.3950-prod.zip
US
compressed
9.91 Mb
whitelisted
1296
installer.exe
POST
200
104.18.88.101:80
http://flow.lavasoft.com/v1/event-stat?ProductID=IS&Type=StubStart
US
text
29 b
whitelisted
408
WebCompanionInstaller.exe
POST
200
64.18.87.82:80
http://wc-tracking.lavasoft.com/Install.asmx
CA
xml
294 b
whitelisted
408
WebCompanionInstaller.exe
POST
200
64.18.87.82:80
http://wc-tracking.lavasoft.com/Install.asmx
CA
xml
294 b
whitelisted
1296
installer.exe
POST
200
104.18.88.101:80
http://flow.lavasoft.com/v1/event-stat?ProductID=IS&Type=StubBundleStart
US
text
29 b
whitelisted
408
WebCompanionInstaller.exe
POST
200
64.18.87.82:80
http://wc-tracking.lavasoft.com/Install.asmx
CA
xml
294 b
whitelisted
408
WebCompanionInstaller.exe
POST
200
64.18.87.82:80
http://wc-tracking.lavasoft.com/Install.asmx
CA
xml
294 b
whitelisted
408
WebCompanionInstaller.exe
POST
200
64.18.87.82:80
http://wc-tracking.lavasoft.com/Install.asmx
CA
xml
294 b
whitelisted
Download PCAP, analyze network streams, HTTP content and a lot more at the full report

Connections

PID
Process
IP
Domain
ASN
CN
Reputation
1296
installer.exe
104.18.88.101:80
flow.lavasoft.com
Cloudflare Inc
US
shared
3796
GenericSetup.exe
104.18.87.101:443
flow.lavasoft.com
Cloudflare Inc
US
shared
3796
GenericSetup.exe
104.16.236.79:443
sos.adaware.com
Cloudflare Inc
US
shared
3796
GenericSetup.exe
104.16.236.79:80
sos.adaware.com
Cloudflare Inc
US
shared
3796
GenericSetup.exe
104.16.235.79:443
sos.adaware.com
Cloudflare Inc
US
shared
2968
OfferInstaller.exe
104.18.87.101:443
flow.lavasoft.com
Cloudflare Inc
US
shared
2968
OfferInstaller.exe
104.17.178.102:80
webcompanion.com
Cloudflare Inc
US
shared
408
WebCompanionInstaller.exe
64.18.87.82:80
wc-tracking.lavasoft.com
COGECODATA
CA
unknown
408
WebCompanionInstaller.exe
104.18.87.101:80
flow.lavasoft.com
Cloudflare Inc
US
shared
4060
WebCompanion.exe
104.17.177.102:80
webcompanion.com
Cloudflare Inc
US
shared

DNS requests

Domain
IP
Reputation
flow.lavasoft.com
  • 104.18.88.101
  • 104.18.87.101
whitelisted
www.google.com
  • 216.58.207.68
malicious
sos.adaware.com
  • 104.16.236.79
  • 104.16.235.79
whitelisted
dns.msftncsi.com
  • 131.107.255.255
shared
webcompanion.com
  • 104.17.178.102
  • 104.17.177.102
malicious
wc-tracking.lavasoft.com
  • 64.18.87.82
  • 64.18.87.81
whitelisted
wc-update-service.lavasoft.com
  • 64.18.87.82
  • 64.18.87.81
whitelisted
wcdownloadercdn.lavasoft.com
  • 104.18.87.101
  • 104.18.88.101
whitelisted
rt.webcompanion.com
  • 104.17.177.102
  • 104.17.178.102
malicious
wc-partners.lavasoft.com
  • 64.18.87.82
  • 64.18.87.81
whitelisted

Threats

PID
Process
Class
Message
1296
installer.exe
A Network Trojan was detected
ET MALWARE Lavasoft PUA/Adware Client Install
2968
OfferInstaller.exe
Potential Corporate Privacy Violation
ET POLICY PE EXE or DLL Windows file download HTTP
2968
OfferInstaller.exe
Potentially Bad Traffic
ET INFO Executable Retrieved With Minimal HTTP Headers - Potential Second Stage Download
2968
OfferInstaller.exe
Misc activity
ET INFO EXE - Served Attached HTTP
Process
Message
GenericSetup.exe
*** Status originated: -1072365543 *** Source File: d:\iso_whid\x86fre\base\isolation\id_parser.cpp, line 352
GenericSetup.exe
*** Status propagated: -1072365543 *** Source File: d:\iso_whid\x86fre\base\isolation\com\identityauthority.cpp, line 147
WebCompanionInstaller.exe
Detecting windows culture
WebCompanionInstaller.exe
10/16/2019 11:25:39 AM :-> Starting installer 4.8.2078.3950 with: .\WebCompanionInstaller.exe --partner=PF170501 --version=4.8.2078.3950 --prod --silent --homepage=1 --search=1 --partner=PF170501, Run as admin: True
WebCompanionInstaller.exe
Preparing for installing Web Companion
WebCompanionInstaller.exe
10/16/2019 11:25:39 AM :-> Generating Machine and Install Id ...
WebCompanionInstaller.exe
10/16/2019 11:25:39 AM :-> Machine Id and Install Id has been generated
WebCompanionInstaller.exe
10/16/2019 11:25:40 AM :-> Checking prerequisites ...
WebCompanionInstaller.exe
10/16/2019 11:25:40 AM :-> Antivirus not detected
WebCompanionInstaller.exe
10/16/2019 11:25:40 AM :-> vm_check False