Home Malware Programs Potentially Unwanted Programs (PUPs) Traffic Exchange

Traffic Exchange

Posted: November 11, 2016

Threat Metric

Ranking: 45
Threat Level: 1/10
Infected PCs: 2,473,468
First Seen: November 11, 2016
Last Seen: March 10, 2025
OS(es) Affected: Windows


The Traffic Exchange is a Potentially Unwanted Program (PUP) whose installation might cause undesired side effects to your computer's behavior. The original purpose of the application appears to be to help small-time webmasters to exchange traffic by submitting their website & contact information and then running the Traffic Exchange, which will generate traffic for other registered parties automatically. While this might look like an easy way to boost a page's traffic artificially, you should know that the Traffic Exchange's Privacy Policy includes some concerning details. The publishers of the Traffic Exchange state that they may provide the e-mail address used for registration to 3rd-parties and, in addition to this, they might collect additional browsing information, which might be used for marketing purposes.

We advise against using software that does not respect your privacy, especially when it has nothing of value to offer in return. The Traffic Exchange PUP should be removed as soon as you see it on your computer. This task can be completed either manually or with the help of a trustworthy anti-malware software suite.

Technical Details

File System Modifications

Tutorials: If you wish to learn how to remove malware components manually, you can read the tutorials on how to find malware, kill unwanted processes, remove malicious DLLs and delete other harmful files. Always be sure to back up your PC before making any changes.

The following files were created in the system:



file.exe File name: file.exe
Size: 921.45 KB (921456 bytes)
MD5: 1ae34060ed111aec2e3c914270ef6131
Detection count: 63
File type: Executable File
Mime Type: unknown/exe
Group: Malware file
%PROGRAMFILES(x86)%\Microleaves\Online Application\Online Application Updater.exe File name: Online Application Updater.exe
Size: 962.92 KB (962928 bytes)
MD5: 016ce1783d079384774fb3ffee95c169
Detection count: 61
File type: Executable File
Mime Type: unknown/exe
Path: %PROGRAMFILES(x86)%\Microleaves\Online Application
Group: Malware file
Last Updated: August 5, 2017
%PROGRAMFILES(x86)%\Microleaves\Traffic Exchange\Online-Guardian-v2.0.9.exe File name: Online-Guardian-v2.0.9.exe
Size: 633.38 KB (633383 bytes)
MD5: ab0e97b4881076a20461f49bcafa1d57
Detection count: 46
File type: Executable File
Mime Type: unknown/exe
Path: %PROGRAMFILES(x86)%\Microleaves\Traffic Exchange
Group: Malware file
Last Updated: April 15, 2017
%PROGRAMFILES(x86)%\Microleaves\Traffic Exchange\OnlineGuardian-v2.exe File name: OnlineGuardian-v2.exe
Size: 633.27 KB (633271 bytes)
MD5: f4d0dd1537ebebd0a8daa73f60e160be
Detection count: 44
File type: Executable File
Mime Type: unknown/exe
Path: %PROGRAMFILES(x86)%\Microleaves\Traffic Exchange
Group: Malware file
Last Updated: April 15, 2017
C:\Users\<username>\AppData\Roaming\ZHP\Quarantine\Microleaves\Online Application Installer\prerequisites\aipackagechainer.exe File name: aipackagechainer.exe
Size: 385.41 KB (385416 bytes)
MD5: 625151080b293da9ccb7f2100e43255f
Detection count: 14
File type: Executable File
Mime Type: unknown/exe
Path: C:\Users\<username>\AppData\Roaming\ZHP\Quarantine\Microleaves\Online Application Installer\prerequisites\aipackagechainer.exe
Group: Malware file
Last Updated: April 7, 2023
%PROGRAMFILES%\Microleaves\Traffic Exchange\Online-Guardian-v2.exe File name: Online-Guardian-v2.exe
Size: 622.17 KB (622176 bytes)
MD5: b62f3eee71d915df81c040007955b6b9
Detection count: 9
File type: Executable File
Mime Type: unknown/exe
Path: %PROGRAMFILES%\Microleaves\Traffic Exchange
Group: Malware file
Last Updated: February 17, 2017
%PROGRAMFILES(x86)%\Microleaves\Online Application\Version 2.6.0\Online-Guardian.exe File name: Online-Guardian.exe
Size: 633.39 KB (633399 bytes)
MD5: b1956bcc37f7b28bc8ad2efd16060c87
Detection count: 5
File type: Executable File
Mime Type: unknown/exe
Path: %PROGRAMFILES(x86)%\Microleaves\Online Application\Version 2.6.0
Group: Malware file
Last Updated: August 5, 2017

More files

Registry Modifications

The following newly produced Registry Values are:

Regexp file mask%TEMP%\ww-Online.IO-installer.exe%WINDIR%\Installer\{010F762A-8645-4AAE-9E69-40254D5147F9}\online.exe%WINDIR%\Installer\{92C1F287-B8A1-415C-B872-4000F57C055A}\online.exe%WINDIR%\System32\Tasks\Online Application V2Gd%WINDIR%\System32\Tasks\Online Special Application[RANDOM CHARACTERS]%WINDIR%\System32\Tasks\Traffic Exchange[RANDOM CHARACTERS]%WINDIR%\System32\Tasks\Updater_Online_Application%WINDIR%\System32\Tasks\Updater_Online_Special_Application[RANDOM CHARACTERS]%WINDIR%\Tasks\Online Application V2Gd.job%WINDIR%\Tasks\Online Special Application[RANDOM CHARACTERS].job%WINDIR%\Tasks\Traffic Exchange[RANDOM CHARACTERS].job%WINDIR%\Tasks\Updater_Online_Application.job%WINDIR%\Tasks\Updater_Online_Special_Application[RANDOM CHARACTERS].jobHKEY..\..\..\..{RegistryKeys}SOFTWARE\Caphyon\Advanced Installer\LZMA\{010F762A-8645-4AAE-9E69-40254D5147F9}SOFTWARE\Caphyon\Advanced Installer\LZMA\{438465C5-D78D-4958-B31D-60374B5042F4}SOFTWARE\Caphyon\Advanced Installer\LZMA\{5266F634-7B7D-4537-BDDC-98DD6CFCBAA1}SOFTWARE\Caphyon\Advanced Installer\LZMA\{52F7BE5C-2C3B-4C7B-A96D-F19B9EC1992D}SOFTWARE\Caphyon\Advanced Installer\LZMA\{92C1F287-B8A1-415C-B872-4000F57C055A}SOFTWARE\Caphyon\Advanced Installer\LZMA\{DBABED16-1BB7-4805-B24B-7424A372AB0F}SOFTWARE\Caphyon\Advanced Installer\LZMA\{F0847AE0-465A-4D7B-A555-AABB43B550F0}SOFTWARE\Caphyon\Advanced Installer\Scheduled Tasks\{F039D4A9-14D3-4425-A4FA-F2F9D5B0E014}SOFTWARE\Classes\Installer\Products\436F6625D7B77354DBCD89DDC6CFAB1ASOFTWARE\Classes\Installer\Products\5C564834D87D85943BD10673B405244FSOFTWARE\Classes\Installer\Products\61DEBABD7BB150842BB447423A27BAF0SOFTWARE\Classes\Installer\Products\6F4136C48ED2453458A6876797EA4F70SOFTWARE\Classes\Installer\Products\782F1C291A8BC5148B2704005FC750A5SOFTWARE\Classes\Installer\Products\A267F0105468EAA4E9960452D415749FSOFTWARE\Classes\Installer\Products\C5EB7F25B3C2B7C49AD61FB9E91C99D2SOFTWARE\Classes\Installer\UpgradeCodes\A3B7F0A2A2BF143479D11833E902B61FSOFTWARE\MicroleavesSOFTWARE\Microsoft\Tracing\Online Application Updater_RASAPI32SOFTWARE\Microsoft\Tracing\Online Application Updater_RASMANCSSOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tree\Online Special Application V2G1SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tree\Online Special Application V2G2SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tree\Online Special Application V2G3SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tree\Traffic Exchange UpdaterSOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tree\Updater_Online_ApplicationSOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tree\Updater_Online_Special_ApplicationSOFTWARE\WOW6432Node\Caphyon\Advanced Installer\LZMA\{5266F634-7B7D-4537-BDDC-98DD6CFCBAA1}SOFTWARE\Wow6432Node\Caphyon\Advanced Installer\Scheduled Tasks\{F039D4A9-14D3-4425-A4FA-F2F9D5B0E014}SOFTWARE\WOW6432Node\MicroleavesHKEY_LOCAL_MACHINE\Software\[APPLICATION]\Microsoft\Windows\CurrentVersion\Uninstall..{Uninstaller}Online.IO{010F762A-8645-4AAE-9E69-40254D5147F9}{102BD58E-AC7E-47DB-B2AB-4A444FFF82CF}{438465C5-D78D-4958-B31D-60374B5042F4}{44FE85D7-4C36-4A76-A3CF-2BFFEBB76C09}{4C6314F6-2DE8-4354-856A-787679AEF407}{5266F634-7B7D-4537-BDDC-98DD6CFCBAA1}{52F7BE5C-2C3B-4C7B-A96D-F19B9EC1992D}{57281722-3238-4A30-AAE7-85D93977E0FE}{57629D30-3D4C-4BA3-9EE2-D38E56D7221E}{5C2B5FB4-B961-4BA8-AAC5-11381225A8FA}{804C6085-8AFA-452E-8567-55FE1BF21FBF}{92C1F287-B8A1-415C-B872-4000F57C055A}{A91EEA9B-DCAA-4B2D-B62A-50B8EA351561}{DBABED16-1BB7-4805-B24B-7424A372AB0F}{E7B046D6-CF45-4063-9BB8-DE124614885C}{F0847AE0-465A-4D7B-A555-AABB43B550F0}{F972E1E6-EE44-4BE6-8264-4B88ED176BDA}

Additional Information

The following directories were created:
%ALLUSERSPROFILE%\Microleaves%APPDATA%\Microleaves%HOMEDRIVE%\AppData\Roaming\Microleaves%HOMEDRIVE%\Users\Default\AppData\Local\AdvinstAnalytics%LOCALAPPDATA%\AdvinstAnalytics%PROGRAMFILES%\Microleaves%PROGRAMFILES%\Online-IO%PROGRAMFILES%\Online.IO%PROGRAMFILES(x86)%\Microleaves%PROGRAMFILES(x86)%\Online-IO%PROGRAMFILES(x86)%\Online.IO%USERPROFILE%\Local Settings\Application Data\AdvinstAnalytics%WINDIR%\INSTALLER\{52F7BE5C-2C3B-4C7B-A96D-F19B9EC1992D}%WINDIR%\INSTALLER\{F0847AE0-465A-4D7B-A555-AABB43B550F0}%WINDIR%\Installer\{438465C5-D78D-4958-B31D-60374B5042F4}%WINDIR%\Installer\{5266F634-7B7D-4537-BDDC-98DD6CFCBAA1}%WINDIR%\SysWOW64\config\systemprofile\AppData\Local\AdvinstAnalytics%WINDIR%\System32\config\systemprofile\AppData\Local\AdvinstAnalytics%WINDIR%\system32\config\systemprofile\AppData\Roaming\Microleaves%WINDIR%\syswow64\config\systemprofile\AppData\Roaming\Microleaves
Loading...