Remove Trafficadvance. Description and removal instructions

 
Title: Trafficadvance

Type: Dialers
Severity scale:Trafficadvance severity is 53  (53 / 100)
 
Trafficadvance is a dialer that connects a compromised computer to the Internet by dialing a high-cost phone number using a modem. The threat is designed to provide access to pornographic web resources. Once executed, Trafficadvance installs itself to the system and displays few messages in Italian. It also creates several desktop shortcuts. The dialer is distributed through ActiveX drive-by downloads and therefore can get into the system while visiting some insecure web sites. Trafficadvance runs on every Windows startup.


Trafficadvance properties:
• Connects itself to the internet
• Hides from the user
• Stays resident in background

Automatic Trafficadvance removal:

remover for Trafficadvance

Trafficadvance manual removal:

Kill processes:
adulti.exe, diari di viaggio.exe, meteo.exe, passe-partout.exe, patente.exe, trucchi e videogiochi.exe
Delete registry values:
HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Run\Quicktime Task
HKEY_CURRENT_USER\S-15-21-329068152-3082236825-839522115\Software\Microsoft\IEAK
HKEY_CURRENT_USER\S-15-21-329068152-3082236825-839522115\Software\Microsoft\Internet Connection Wizard
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\""=ICWhelp 1.0 Type Library
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\""=IICWSystemConfig
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\""=ISmartStart
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\""=IUserInfo
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\""C:\Programs Files\Internet Explorer\Connection Wizard\icwhelp.dll, 1
HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Enum\Root\Legacy_RasAuto\0000\Control\ActiveService=Ras Auto
HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Enum\Root\Legacy_RasMan\0000\Control\ActiveService=Ras Auto
HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Enum\Root\Legacy_TapiSrv\0000\Control\ActiveService=Ras Auto
Delete files:
adulti.exe, diari di viaggio.exe, meteo.exe, passe-partout.exe, patente.exe, trucchi e videogiochi.exe
Delete directories:
C:\Program Files\Start Menu\Programs\NetVision
Misc:
All Trafficadvance files can be found in C:\Windows or C:\Winnt directory.

Other programs to remove Trafficadvance:

• Malwarebytes Anti Malware - Review - Download
• Malwarebytes Anti Malware - Review - Download
• Windows Defender - Review - Download

Information added: 06/10/05
Information updated: 06/10/05

Additional resources related to Trafficadvance:

Attention: If you know or you have a website or page about Trafficadvance removal, feel free to add a link to this list: add url




more resources

Post Comment:

Attention: Use this form only if you have additional information about Trafficadvance parasite, its removal instructions, additional resources or behavior. By clicking "post comment" button you agree not to post any copyrighted, unlawful, harmful, threatening, abusive, harassing, defamatory, vulgar, obscene, profane, hateful, racially, ethnically or otherwise objectionable material of any kind.



Enter security code:

Latest spyware news:
Similar parasites: