WebRebates Description:
Adware · Browser Helper Object · Downloader
· Toolbar
Also known as: web_rebates, TopRebates,
TrojanDownloader.Win32.Agent.y,
TrojanClicker.Win32.Delf.z,
TrojanSpy.Win32.Spung.a
WebRebates Automatic Removal:
Using Spyware Doctor
to
remove WebRebates AUTOMATICALLY.
Sponsored Links:
Free Download Now:

WebRebates Manual Removal:
Follow these steps to remove WebRebates from your
machine. Begin by backing up your registry and
your system, and/or setting a Restore Point, to
prevent trouble if you make a mistake.
- Kill these running processes with Task
Manager:
arupdate.exe
c:\temp\webrebates_cdt_installsilent.exe
cashback.exe
cb.exe
flash.exe
nls.exe
profilepath+\local settings\temp\djtopr1150.exe
programfilesdir+\web_rebates\disp1150.exe
programfilesdir+\web_rebates\webrebates0.exe
programfilesdir+\web_rebates\webrebates1.exe
programfilesdir+\webrebates\webrebates1.exe
systemroot+\2805e.exe
unregister.exe
unstsa3.exe
- Go to the key HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Run.
If you find the value HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\run\webrebates,
delete it and reboot the machine immediately.
If you find the value HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\run\webrebates0,
delete it and reboot the machine
immediately.
- Unregister these DLLs with Regsvr32, then reboot:
systemroot+\3_0_1browserhelper3.dll
systemroot+\neti.dll
systemroot+\system32\imgconv.dll
systemroot+\system32\vic32.dll
- Remove these registry items (if present)
with RegEdit:
HKEY_LOCAL_MACHINE\software\classes\appid\hungryhands.dll\appid
HKEY_LOCAL_MACHINE\software\classes\clsid\{0a8ce102-fa03-4612-9bee-7fe5452f4cb1}
HKEY_LOCAL_MACHINE\software\classes\clsid\{bcf96fb4-5f1b-497b-aecc-910304a55011}\appid
HKEY_LOCAL_MACHINE\software\classes\interface\{f8fb4ea2-6c05-4de5-8cd0-625b03f48e22}
HKEY_LOCAL_MACHINE\software\classes\typelib\{03f8822f-8877-4002-8bcd-b532d53d8471}
HKEY_LOCAL_MACHINE\software\microsoft\internet explorer\toolbar\{26398112-f068-4273-964b-a1d8bcf3e576}
HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\explorer\browser helper objects\{c5941ee5-6dfa-11d8-86b0-0002441a9695}\bho_path
HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\explorer\browser helper objects\{c5941ee5-6dfa-11d8-86b0-0002441a9695}\bhonew
HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\explorer\browser helper objects\{c5941ee5-6dfa-11d8-86b0-0002441a9695}\bhonew_url
HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\explorer\browser helper objects\{c5941ee5-6dfa-11d8-86b0-0002441a9695}\bhonew_version
HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\explorer\browser helper objects\{c5941ee5-6dfa-11d8-86b0-0002441a9695}\bhoversion
HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\explorer\browser helper objects\{c5941ee5-6dfa-11d8-86b0-0002441a9695}\keynew
HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\explorer\browser helper objects\{c5941ee5-6dfa-11d8-86b0-0002441a9695}\keynew_url
HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\explorer\browser helper objects\{c5941ee5-6dfa-11d8-86b0-0002441a9695}\keynew_version
HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\explorer\browser helper objects\{c5941ee5-6dfa-11d8-86b0-0002441a9695}\keyversion
HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\explorer\dcr2
HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\moduleusage
\c:/winnt/downloaded program files/conflict.1/installer.dll\.owner
HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\moduleusage
\c:/winnt/downloaded program files/conflict.1/installer.dll\{7eb15626-cb8e-4174-8a72-c055b12b4310}
HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\moduleusage
\c:/winnt/downloaded program files/wuinst.dll\.owner
HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\moduleusage
\c:/winnt/downloaded program files/wuinst.dll\{e2f2b9d0-96b9-4b25-b90c-636ecb207d18}
HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\run\webrebates
HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\run\webrebates0
HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\shell extensions\approved\{26398112-f068-4273-964b-a1d8bcf3e576}
HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\uninstall\untopr1150
\displayname
HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\uninstall\untopr1150
\uninstallstring
HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\uninstall\windows sr 3.0\-\-
HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\uninstall\windows sr 3.0\displayname
HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\uninstall\windows sr 3.0\uninstallstring
- Remove these files (if present) with Windows
Explorer:
10689.gbd2
1150_0.dat
1150_1.dat
1150_2.dat
1150sh.dat
40d3649e11d4.dat
40d364a11d51.dat
40d364a94b0d.dat
40d364aa1c1d.dat
arupdate.exe
b3_t_%22web+rebates%22763.xml
belt.ini
c:\temp\webrebates_cdt_installsilent.exe
cashback.exe
cb.exe
flash.exe
fwntoolbar.dll.manifest
install.log
jau5055.dat
jsy5055.dat
key3.txt
log.txt
merc1158.dat
nls.exe
profilepath+\local settings\temp\djtopr1150.exe
psid1158.dat
readme.txt
rge5055.dat
sty5055.dat
systemroot+\2805e.exe
systemroot+\3_0_1browserhelper3.dll
systemroot+\artmmp.ini
systemroot+\cache371\b_371_0_1_501300.htm
systemroot+\cache371\b_371_0_1_569200.htm
systemroot+\cache371\b_371_0_1_582200.htm
systemroot+\neti.dll
systemroot+\system32\adcache\b_371_0_1_501300.htm
systemroot+\system32\adcache\b_371_0_1_569200.htm
systemroot+\system32\adcache\b_371_0_1_582200.htm
systemroot+\system32\imgconv.dll
systemroot+\system32\vic32.dll
topr1150.dat
toprebates.txt
unregister.exe
unstsa3.exe
web_rebates.txt
- Remove these directories (if present) with
Windows Explorer:
programfilesdir+\web_rebates
programfilesdir+\web_rebates\da1150\david
programfilesdir+\web_rebates\sy1150\html
programfilesdir+\web_rebates\sy1150\images
programfilesdir+\web_rebates\sy1150\sy1150
programfilesdir+\web_rebates\sy1150\tp1150
systemroot+\winskw
Using Spyware Doctor
to
remove WebRebates AUTOMATICALLY.

More
Removal Instructions for Emerging Adware Spyware
|