Home Malware Programs Potentially Unwanted Programs (PUPs) Traffic Exchange

Traffic Exchange

Posted: November 11, 2016

Threat Metric

Ranking: 53
Threat Level: 1/10
Infected PCs: 2,350,792
First Seen: November 11, 2016
Last Seen: October 17, 2023
OS(es) Affected: Windows


The Traffic Exchange is a Potentially Unwanted Program (PUP) whose installation might cause undesired side effects to your computer's behavior. The original purpose of the application appears to be to help small-time webmasters to exchange traffic by submitting their website & contact information and then running the Traffic Exchange, which will generate traffic for other registered parties automatically. While this might look like an easy way to boost a page's traffic artificially, you should know that the Traffic Exchange's Privacy Policy includes some concerning details. The publishers of the Traffic Exchange state that they may provide the e-mail address used for registration to 3rd-parties and, in addition to this, they might collect additional browsing information, which might be used for marketing purposes.

We advise against using software that does not respect your privacy, especially when it has nothing of value to offer in return. The Traffic Exchange PUP should be removed as soon as you see it on your computer. This task can be completed either manually or with the help of a trustworthy anti-malware software suite.

Technical Details

File System Modifications

Tutorials: If you wish to learn how to remove malware components manually, you can read the tutorials on how to find malware, kill unwanted processes, remove malicious DLLs and delete other harmful files. Always be sure to back up your PC before making any changes.

The following files were created in the system:



file.exe File name: file.exe
Size: 199.86 KB (199864 bytes)
MD5: 68ceb16a7351390eb1c5a4cb759a3dcb
Detection count: 5,080
File type: Executable File
Mime Type: unknown/exe
Group: Malware file
Last Updated: May 10, 2023
%PROGRAMFILES(x86)%\Microleaves\Online Special Application\Version 2.6.0\Online-Guardian.exe File name: Online-Guardian.exe
Size: 632.96 KB (632960 bytes)
MD5: eaeac3df96a3510d2de7e0b007523baa
Detection count: 86
File type: Executable File
Mime Type: unknown/exe
Path: %PROGRAMFILES(x86)%\Microleaves\Online Special Application\Version 2.6.0
Group: Malware file
Last Updated: August 5, 2017
%PROGRAMFILES%\Microleaves\Online Special Application\Version 2.6.0\Online-Guardian.exe File name: Online-Guardian.exe
Size: 561.78 KB (561788 bytes)
MD5: 5fa33586c809418cc9c3a2a0eae3ec38
Detection count: 85
File type: Executable File
Mime Type: unknown/exe
Path: %PROGRAMFILES%\Microleaves\Online Special Application\Version 2.6.0
Group: Malware file
Last Updated: August 5, 2017
%PROGRAMFILES(x86)%\Microleaves\Online Application\Version 2.6.0\Online-Guardian.exe File name: Online-Guardian.exe
Size: 633.39 KB (633399 bytes)
MD5: 54f9436ef25d477de78b4a9f18f66346
Detection count: 76
File type: Executable File
Mime Type: unknown/exe
Path: %PROGRAMFILES(x86)%\Microleaves\Online Application\Version 2.6.0
Group: Malware file
Last Updated: August 5, 2017
file.exe File name: file.exe
Size: 921.47 KB (921472 bytes)
MD5: f4e4f42c67b203581ad6078384bc4ca5
Detection count: 63
File type: Executable File
Mime Type: unknown/exe
Group: Malware file
file.exe File name: file.exe
Size: 921.45 KB (921456 bytes)
MD5: 9a3715a18e4a0e988895c5bd8363d5d6
Detection count: 63
File type: Executable File
Mime Type: unknown/exe
Group: Malware file
file.exe File name: file.exe
Size: 921.45 KB (921456 bytes)
MD5: 1ae34060ed111aec2e3c914270ef6131
Detection count: 63
File type: Executable File
Mime Type: unknown/exe
Group: Malware file
file.exe File name: file.exe
Size: 637.5 KB (637501 bytes)
MD5: 706341e3da40e89afc3cc28982f5d4f6
Detection count: 62
File type: Executable File
Mime Type: unknown/exe
Group: Malware file
file.exe File name: file.exe
Size: 624.75 KB (624752 bytes)
MD5: 36364ac694259372f98cda97b4cf3bf6
Detection count: 62
File type: Executable File
Mime Type: unknown/exe
Group: Malware file
file.exe File name: file.exe
Size: 555.12 KB (555120 bytes)
MD5: f9ea9d53ced081dfaaaca7de2af97070
Detection count: 62
File type: Executable File
Mime Type: unknown/exe
Group: Malware file
file.exe File name: file.exe
Size: 633.38 KB (633383 bytes)
MD5: 826bc01269c5ff5dfdb932d04ca8785e
Detection count: 62
File type: Executable File
Mime Type: unknown/exe
Group: Malware file
file.exe File name: file.exe
Size: 633.27 KB (633271 bytes)
MD5: 10a5006704bd57c75ef592704e9c916c
Detection count: 62
File type: Executable File
Mime Type: unknown/exe
Group: Malware file
file.exe File name: file.exe
Size: 879.98 KB (879984 bytes)
MD5: b65ce73e28cb291a327bbe3314017d06
Detection count: 62
File type: Executable File
Mime Type: unknown/exe
Group: Malware file
file.exe File name: file.exe
Size: 1.46 MB (1461248 bytes)
MD5: fa5373f0c81960ec7a58ef75cbd04878
Detection count: 62
File type: Executable File
Mime Type: unknown/exe
Group: Malware file
file.exe File name: file.exe
Size: 633.39 KB (633399 bytes)
MD5: 52dd542eeadf3ba7cd4a4c93a9202041
Detection count: 62
File type: Executable File
Mime Type: unknown/exe
Group: Malware file
file.exe File name: file.exe
Size: 633.39 KB (633399 bytes)
MD5: 42dddffbf0061cc69c35dc8766aea3c6
Detection count: 62
File type: Executable File
Mime Type: unknown/exe
Group: Malware file
%PROGRAMFILES(x86)%\Microleaves\Online Application\Online Application Updater.exe File name: Online Application Updater.exe
Size: 962.92 KB (962928 bytes)
MD5: 016ce1783d079384774fb3ffee95c169
Detection count: 61
File type: Executable File
Mime Type: unknown/exe
Path: %PROGRAMFILES(x86)%\Microleaves\Online Application
Group: Malware file
Last Updated: August 5, 2017
file.exe File name: file.exe
Size: 554.99 KB (554992 bytes)
MD5: a245cce70a4d34a928af302561cb6f77
Detection count: 61
File type: Executable File
Mime Type: unknown/exe
Group: Malware file
%PROGRAMFILES%\Microleaves\Online Application\Version 2.6.0\Online-Guardian.exe File name: Online-Guardian.exe
Size: 624.75 KB (624752 bytes)
MD5: f4d9dc69cef89815ce21a5a4286b29b9
Detection count: 55
File type: Executable File
Mime Type: unknown/exe
Path: %PROGRAMFILES%\Microleaves\Online Application\Version 2.6.0
Group: Malware file
Last Updated: August 5, 2017
%PROGRAMFILES(x86)%\Microleaves\Online Application\Version 2.6.0\Online-Guardian.exe File name: Online-Guardian.exe
Size: 633.39 KB (633399 bytes)
MD5: 86638a648d262f44e86f98c3a259feba
Detection count: 34
File type: Executable File
Mime Type: unknown/exe
Path: %PROGRAMFILES(x86)%\Microleaves\Online Application\Version 2.6.0
Group: Malware file
Last Updated: August 5, 2017
%PROGRAMFILES%\Microleaves\Online Application\Version 2.6.0\Online-Guardian.exe File name: Online-Guardian.exe
Size: 555.12 KB (555120 bytes)
MD5: e2ff45dbd8c1301942569abab2c4986e
Detection count: 16
File type: Executable File
Mime Type: unknown/exe
Path: %PROGRAMFILES%\Microleaves\Online Application\Version 2.6.0
Group: Malware file
Last Updated: June 27, 2018
%PROGRAMFILES%\Microleaves\Online Application\Version 2.6.0\Online-Guardian.exe File name: Online-Guardian.exe
Size: 555.52 KB (555520 bytes)
MD5: afce36dd1047fd9f6c321d20b5587590
Detection count: 14
File type: Executable File
Mime Type: unknown/exe
Path: %PROGRAMFILES%\Microleaves\Online Application\Version 2.6.0
Group: Malware file
Last Updated: August 5, 2017
%PROGRAMFILES%\Microleaves\Online Application\Version 2.6.0\Online-Guardian.exe File name: Online-Guardian.exe
Size: 555.12 KB (555120 bytes)
MD5: fb9ba70b32188c1dc720437f18827c59
Detection count: 5
File type: Executable File
Mime Type: unknown/exe
Path: %PROGRAMFILES%\Microleaves\Online Application\Version 2.6.0
Group: Malware file
Last Updated: August 5, 2017
%PROGRAMFILES(x86)%\Microleaves\Online Application\Version 2.6.0\Online-Guardian.exe File name: Online-Guardian.exe
Size: 633.39 KB (633399 bytes)
MD5: 2c732b6f40c8c9572fcd56e13849fe04
Detection count: 5
File type: Executable File
Mime Type: unknown/exe
Path: %PROGRAMFILES(x86)%\Microleaves\Online Application\Version 2.6.0
Group: Malware file
Last Updated: August 5, 2017
%PROGRAMFILES(x86)%\Microleaves\Online Application\Version 2.6.0\Online-Guardian.exe File name: Online-Guardian.exe
Size: 555.12 KB (555120 bytes)
MD5: bb86c068ca095caa219c161a5f75d6a8
Detection count: 5
File type: Executable File
Mime Type: unknown/exe
Path: %PROGRAMFILES(x86)%\Microleaves\Online Application\Version 2.6.0
Group: Malware file
Last Updated: August 5, 2017
%PROGRAMFILES(x86)%\Microleaves\Online Application\Version 2.6.0\Online-Guardian.exe File name: Online-Guardian.exe
Size: 633.39 KB (633399 bytes)
MD5: b1956bcc37f7b28bc8ad2efd16060c87
Detection count: 5
File type: Executable File
Mime Type: unknown/exe
Path: %PROGRAMFILES(x86)%\Microleaves\Online Application\Version 2.6.0
Group: Malware file
Last Updated: August 5, 2017

More files

Registry Modifications

The following newly produced Registry Values are:

Regexp file mask%TEMP%\ww-Online.IO-installer.exe%WINDIR%\Installer\{010F762A-8645-4AAE-9E69-40254D5147F9}\online.exe%WINDIR%\Installer\{92C1F287-B8A1-415C-B872-4000F57C055A}\online.exe%WINDIR%\System32\Tasks\Online Application V2Gd%WINDIR%\System32\Tasks\Online Special Application[RANDOM CHARACTERS]%WINDIR%\System32\Tasks\Traffic Exchange[RANDOM CHARACTERS]%WINDIR%\System32\Tasks\Updater_Online_Application%WINDIR%\System32\Tasks\Updater_Online_Special_Application[RANDOM CHARACTERS]%WINDIR%\Tasks\Online Application V2Gd.job%WINDIR%\Tasks\Online Special Application[RANDOM CHARACTERS].job%WINDIR%\Tasks\Traffic Exchange[RANDOM CHARACTERS].job%WINDIR%\Tasks\Updater_Online_Application.job%WINDIR%\Tasks\Updater_Online_Special_Application[RANDOM CHARACTERS].jobHKEY..\..\..\..{RegistryKeys}SOFTWARE\Caphyon\Advanced Installer\LZMA\{010F762A-8645-4AAE-9E69-40254D5147F9}SOFTWARE\Caphyon\Advanced Installer\LZMA\{438465C5-D78D-4958-B31D-60374B5042F4}SOFTWARE\Caphyon\Advanced Installer\LZMA\{5266F634-7B7D-4537-BDDC-98DD6CFCBAA1}SOFTWARE\Caphyon\Advanced Installer\LZMA\{52F7BE5C-2C3B-4C7B-A96D-F19B9EC1992D}SOFTWARE\Caphyon\Advanced Installer\LZMA\{92C1F287-B8A1-415C-B872-4000F57C055A}SOFTWARE\Caphyon\Advanced Installer\LZMA\{DBABED16-1BB7-4805-B24B-7424A372AB0F}SOFTWARE\Caphyon\Advanced Installer\LZMA\{F0847AE0-465A-4D7B-A555-AABB43B550F0}SOFTWARE\Caphyon\Advanced Installer\Scheduled Tasks\{F039D4A9-14D3-4425-A4FA-F2F9D5B0E014}SOFTWARE\Classes\Installer\Products\436F6625D7B77354DBCD89DDC6CFAB1ASOFTWARE\Classes\Installer\Products\5C564834D87D85943BD10673B405244FSOFTWARE\Classes\Installer\Products\61DEBABD7BB150842BB447423A27BAF0SOFTWARE\Classes\Installer\Products\6F4136C48ED2453458A6876797EA4F70SOFTWARE\Classes\Installer\Products\782F1C291A8BC5148B2704005FC750A5SOFTWARE\Classes\Installer\Products\A267F0105468EAA4E9960452D415749FSOFTWARE\Classes\Installer\Products\C5EB7F25B3C2B7C49AD61FB9E91C99D2SOFTWARE\Classes\Installer\UpgradeCodes\A3B7F0A2A2BF143479D11833E902B61FSOFTWARE\MicroleavesSOFTWARE\Microsoft\Tracing\Online Application Updater_RASAPI32SOFTWARE\Microsoft\Tracing\Online Application Updater_RASMANCSSOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tree\Online Special Application V2G1SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tree\Online Special Application V2G2SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tree\Online Special Application V2G3SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tree\Traffic Exchange UpdaterSOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tree\Updater_Online_ApplicationSOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tree\Updater_Online_Special_ApplicationSOFTWARE\WOW6432Node\Caphyon\Advanced Installer\LZMA\{5266F634-7B7D-4537-BDDC-98DD6CFCBAA1}SOFTWARE\Wow6432Node\Caphyon\Advanced Installer\Scheduled Tasks\{F039D4A9-14D3-4425-A4FA-F2F9D5B0E014}SOFTWARE\WOW6432Node\MicroleavesHKEY_LOCAL_MACHINE\Software\[APPLICATION]\Microsoft\Windows\CurrentVersion\Uninstall..{Uninstaller}Online.IO{010F762A-8645-4AAE-9E69-40254D5147F9}{102BD58E-AC7E-47DB-B2AB-4A444FFF82CF}{438465C5-D78D-4958-B31D-60374B5042F4}{44FE85D7-4C36-4A76-A3CF-2BFFEBB76C09}{4C6314F6-2DE8-4354-856A-787679AEF407}{5266F634-7B7D-4537-BDDC-98DD6CFCBAA1}{52F7BE5C-2C3B-4C7B-A96D-F19B9EC1992D}{57281722-3238-4A30-AAE7-85D93977E0FE}{57629D30-3D4C-4BA3-9EE2-D38E56D7221E}{5C2B5FB4-B961-4BA8-AAC5-11381225A8FA}{804C6085-8AFA-452E-8567-55FE1BF21FBF}{92C1F287-B8A1-415C-B872-4000F57C055A}{A91EEA9B-DCAA-4B2D-B62A-50B8EA351561}{DBABED16-1BB7-4805-B24B-7424A372AB0F}{E7B046D6-CF45-4063-9BB8-DE124614885C}{F0847AE0-465A-4D7B-A555-AABB43B550F0}{F972E1E6-EE44-4BE6-8264-4B88ED176BDA}

Additional Information

The following directories were created:
%ALLUSERSPROFILE%\Microleaves%APPDATA%\Microleaves%HOMEDRIVE%\AppData\Roaming\Microleaves%HOMEDRIVE%\Users\Default\AppData\Local\AdvinstAnalytics%LOCALAPPDATA%\AdvinstAnalytics%PROGRAMFILES%\Microleaves%PROGRAMFILES%\Online-IO%PROGRAMFILES%\Online.IO%PROGRAMFILES(x86)%\Microleaves%PROGRAMFILES(x86)%\Online-IO%PROGRAMFILES(x86)%\Online.IO%USERPROFILE%\Local Settings\Application Data\AdvinstAnalytics%WINDIR%\INSTALLER\{52F7BE5C-2C3B-4C7B-A96D-F19B9EC1992D}%WINDIR%\INSTALLER\{F0847AE0-465A-4D7B-A555-AABB43B550F0}%WINDIR%\Installer\{438465C5-D78D-4958-B31D-60374B5042F4}%WINDIR%\Installer\{5266F634-7B7D-4537-BDDC-98DD6CFCBAA1}%WINDIR%\SysWOW64\config\systemprofile\AppData\Local\AdvinstAnalytics%WINDIR%\System32\config\systemprofile\AppData\Local\AdvinstAnalytics%WINDIR%\system32\config\systemprofile\AppData\Roaming\Microleaves%WINDIR%\syswow64\config\systemprofile\AppData\Roaming\Microleaves
Loading...