Technical Information
- [HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings\Zones\2] '1406' = '00000000'
- [HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings\Zones\2] '2301' = '00000003'
- %TEMP%\7zs84253fd2\webcompanion-installer.exe.config
- %APPDATA%\lavasoft\web companion\application\de-de\webcompanion-installer.resources.dll
- %APPDATA%\lavasoft\web companion\application\wpfanimatedgif.dll
- %APPDATA%\lavasoft\web companion\application\webcompanionicon_pro.ico
- %APPDATA%\lavasoft\web companion\application\webcompanionicon.ico
- %APPDATA%\lavasoft\web companion\application\webcompanion.exe.config
- %APPDATA%\lavasoft\web companion\application\webcompanion.exe
- %APPDATA%\lavasoft\web companion\application\webcompanion-installer.pdb
- %APPDATA%\lavasoft\web companion\application\webcompanion-installer.exe.config
- %APPDATA%\lavasoft\web companion\application\webcompanion-installer.exe
- %APPDATA%\lavasoft\web companion\application\vpnservicewcf.dll.config
- %APPDATA%\lavasoft\web companion\application\vpnservicewcf.dll
- %APPDATA%\lavasoft\web companion\application\vpnservicehost.exe.config
- %APPDATA%\lavasoft\web companion\application\vpnservicehost.exe
- %APPDATA%\lavasoft\web companion\application\vcruntime140d.dll
- %APPDATA%\lavasoft\web companion\application\ucrtbased.dll
- %APPDATA%\lavasoft\web companion\application\system.data.sqlite.dll
- %APPDATA%\lavasoft\web companion\application\newtonsoft.json.dll
- %APPDATA%\lavasoft\web companion\application\ncalc.dll
- %APPDATA%\lavasoft\web companion\application\mozcompressor.dll
- %APPDATA%\lavasoft\web companion\application\de-de\webcompanion.resources.dll
- %APPDATA%\lavasoft\web companion\application\en-us\webcompanion-installer.resources.dll
- %APPDATA%\lavasoft\web companion\application\en-us\webcompanion.resources.dll
- %APPDATA%\lavasoft\web companion\application\es-es\webcompanion-installer.resources.dll
- %APPDATA%\lavasoft\web companion\options\updateserver.txt
- %APPDATA%\lavasoft\web companion\options\partner.txt
- %APPDATA%\lavasoft\web companion\application\zh-hans\webcompanion.resources.dll
- %APPDATA%\lavasoft\web companion\application\zh-chs\webcompanion-installer.resources.dll
- %APPDATA%\lavasoft\web companion\application\x86\sqlite.interop.dll
- %APPDATA%\lavasoft\web companion\application\x64\sqlite.interop.dll
- %APPDATA%\lavasoft\web companion\application\tr-tr\webcompanion.resources.dll
- %APPDATA%\lavasoft\web companion\application\tr-tr\webcompanion-installer.resources.dll
- %APPDATA%\lavasoft\web companion\application\ru-ru\webcompanion.resources.dll
- %APPDATA%\lavasoft\web companion\application\pt-br\webcompanion.resources.dll
- %APPDATA%\lavasoft\web companion\application\ru-ru\webcompanion-installer.resources.dll
- %APPDATA%\lavasoft\web companion\application\pt-br\webcompanion-installer.resources.dll
- %APPDATA%\lavasoft\web companion\application\ja-jp\webcompanion.resources.dll
- %APPDATA%\lavasoft\web companion\application\ja-jp\webcompanion-installer.resources.dll
- %APPDATA%\lavasoft\web companion\application\it-it\webcompanion.resources.dll
- %APPDATA%\lavasoft\web companion\application\it-it\webcompanion-installer.resources.dll
- %APPDATA%\lavasoft\web companion\application\fr-ca\webcompanion.resources.dll
- %APPDATA%\lavasoft\web companion\application\fr-ca\webcompanion-installer.resources.dll
- %APPDATA%\lavasoft\web companion\application\extension\@wcextensionff.xpi
- %APPDATA%\lavasoft\web companion\application\es-es\webcompanion.resources.dll
- %APPDATA%\lavasoft\web companion\options\language.txt
- %APPDATA%\lavasoft\web companion\application\microsoft.mshtml.dll
- %APPDATA%\lavasoft\web companion\application\lz4.dll
- %APPDATA%\lavasoft\web companion\application\log4net.dll
- %APPDATA%\lavasoft\web companion\application\bcuengines.dll
- %APPDATA%\lavasoft\web companion\application\acs17.dll
- %APPDATA%\lavasoft\web companion\application\7za.exe
- %TEMP%\webcompanion.zip
- %APPDATA%\lavasoft\web companion\options\statistics.txt
- %TEMP%\wcinstaller.log
- %TEMP%\7zs84253fd2\zh-chs\webcompanion-installer.resources.dll
- %TEMP%\7zs84253fd2\webcompanion-installer.exe
- %TEMP%\7zs84253fd2\tr-tr\webcompanion-installer.resources.dll
- %TEMP%\7zs84253fd2\ru-ru\webcompanion-installer.resources.dll
- %TEMP%\7zs84253fd2\pt-br\webcompanion-installer.resources.dll
- %TEMP%\7zs84253fd2\newtonsoft.json.dll
- %TEMP%\7zs84253fd2\ja-jp\webcompanion-installer.resources.dll
- %TEMP%\7zs84253fd2\it-it\webcompanion-installer.resources.dll
- %TEMP%\7zs84253fd2\icsharpcode.sharpziplib.dll
- %TEMP%\7zs84253fd2\fr-ca\webcompanion-installer.resources.dll
- %TEMP%\7zs84253fd2\es-es\webcompanion-installer.resources.dll
- %TEMP%\7zs84253fd2\en-us\webcompanion-installer.resources.dll
- %TEMP%\7zs84253fd2\de-de\webcompanion-installer.resources.dll
- %APPDATA%\lavasoft\web companion\application\bcusdk.dll
- %APPDATA%\lavasoft\web companion\application\dotnetzip.dll
- %APPDATA%\lavasoft\web companion\application\esent.interop.dll
- %APPDATA%\lavasoft\web companion\application\featurecomponent.dll
- %APPDATA%\lavasoft\web companion\application\lavasoft.wcassistant.winservice.exe.config
- %APPDATA%\lavasoft\web companion\application\lavasoft.wcassistant.winservice.exe
- %APPDATA%\lavasoft\web companion\application\lavasoft.wcassistant.wcfservice.dll
- %APPDATA%\lavasoft\web companion\application\lavasoft.wcassistant.service.logger.dll
- %APPDATA%\lavasoft\web companion\application\lavasoft.utils.sqllite.dll
- %APPDATA%\lavasoft\web companion\application\lavasoft.utils.dll
- %APPDATA%\lavasoft\web companion\application\lavasoft.sysinfo.dll
- %APPDATA%\lavasoft\web companion\application\lavasoft.events.dll
- %APPDATA%\lavasoft\web companion\application\lavasoft.csharp.utilities.dll
- %APPDATA%\lavasoft\web companion\application\ionic.zip.dll
- %APPDATA%\lavasoft\web companion\application\lavasoft.appcore.dll
- %APPDATA%\lavasoft\web companion\application\interop.wuapilib.dll
- %APPDATA%\lavasoft\web companion\application\interop.shell32.dll
- %APPDATA%\lavasoft\web companion\application\interop.shdocvw.dll
- %APPDATA%\lavasoft\web companion\application\interop.iwshruntimelibrary.dll
- %APPDATA%\lavasoft\web companion\application\icsharpcode.sharpziplib.dll
- %APPDATA%\lavasoft\web companion\application\featuremaincomponent.exe.config
- %APPDATA%\lavasoft\web companion\application\featuremaincomponent.exe
- %APPDATA%\lavasoft\web companion\application\featureinstaller.exe.config
- %APPDATA%\lavasoft\web companion\application\featureinstaller.exe
- %APPDATA%\lavasoft\web companion\application\liblz4.dll
- %LOCALAPPDATA%\lavasoft\web companion\logs\webcompanion\webcompanion.log
- 'ge#.##vasoft.com':80
- 'fe######lags.lavasoft.com':443
- 'pk#.goog':80
- 'fl##dw.com':443
- 'wc#######dercdn.lavasoft.com':443
- http://ge#.##vasoft.com/
- http://pk#.goog/gsr1/gsr1.crt
- 'ge#.##vasoft.com':443
- 'fl##dw.com':443
- DNS ASK ge#.##vasoft.com
- DNS ASK fe######lags.lavasoft.com
- DNS ASK pk#.goog
- DNS ASK fl##dw.com
- DNS ASK wc#######dercdn.lavasoft.com
- '%TEMP%\7zs84253fd2\webcompanion-installer.exe' --savename=Setup.exe --partner=IN230901 --nonadmin --direct --tych --campaign=19733658126 --version=12.901.5.1061
- '%APPDATA%\lavasoft\web companion\application\webcompanion.exe' --install --geo=
- '%WINDIR%\syswow64\cmd.exe' /C netsh http add urlacl url=http://+:9007/ user=Everyone' (with hidden window)
- '%WINDIR%\syswow64\cmd.exe' /C netsh http add urlacl url=http://+:9007/ user=Everyone
- '%WINDIR%\syswow64\netsh.exe' http add urlacl url=http://+:9007/ user=Everyone