# Adware won't go away

**URL:** <https://forum.kirupa.com/t/adware-wont-go-away/63555>\
**Category:** random\
**Created:** [September 7, 2004, 11:13pm UTC](https://forum.kirupa.com/t/adware-wont-go-away/63555 "2004-09-07T23:13:17Z")\
**Posts on this page:** 15\
**Page:** 1

<div class="post-metadata">

**Author:** ![NeoDreamer](https://avatars.discourse-cdn.com/v4/letter/n/ccd318/32.png) [@NeoDreamer](https://forum.kirupa.com/u/NeoDreamer)\
**Post date:** [September 7, 2004, 11:13pm UTC](https://forum.kirupa.com/t/adware-wont-go-away/63555/1 "2004-09-07T23:13:17Z")

</div>

When I go to Start \> Settings \> Control Panel \> Add/Remove Programs, I see this program called “WebRebates (by [TopRebates.com](http://TopRebates.com))”. There is also an annoying program of the same name in my task manager which takes up quite a lot of CPU and RAM. I’ve run Ad-aware and Norton Internet Security and uninstalled it numerous times, but it just won’t go away.

This adware was stupid enough to include its website in the program name. So how I can shut their website down and get rid of my virus? I need revenge!!!

---

<div class="post-metadata">

**Author:** ![system](https://canada1.discourse-cdn.com/flex011/uploads/kirupa/original/3X/6/2/621e5c11736f46532526e61be85940af4230f3e5.png) [@system](https://forum.kirupa.com/u/system)\
**Post date:** [September 7, 2004, 11:46pm UTC](https://forum.kirupa.com/t/adware-wont-go-away/63555/2 "2004-09-07T23:46:09Z")

</div>

I made a draft of an angry letter. Any suggestions?

> 

To:  
Ed Yeh  
4546 B-10 El Camino Real, Suite 327  
Los Altos, CA 94022

It seems that your company, [www.toprebates.com](http://www.toprebates.com), has installed adware on my computer. I’ll remind you that this is illegal under US law. Please tell me how to remove this adware from my computer. I’ve already tried many anti-virus programs, and they’ve all failed. If I do not receive a response within 48 hours, I will be forced to take legal action.

Katsuhiro Nakagawa  
Toyota Motor Corp  
Vice Chairman

---

<div class="post-metadata">

**Author:** ![system](https://canada1.discourse-cdn.com/flex011/uploads/kirupa/original/3X/6/2/621e5c11736f46532526e61be85940af4230f3e5.png) [@system](https://forum.kirupa.com/u/system)\
**Post date:** [September 7, 2004, 11:49pm UTC](https://forum.kirupa.com/t/adware-wont-go-away/63555/3 "2004-09-07T23:49:00Z")

</div>

Yea, I just formatted, and my little brother was visiting my house, and he somehow installed around 40 adware programs. One of them is that [toprebates.com](http://toprebates.com) thing too. Screw them man.

---

<div class="post-metadata">

**Author:** ![system](https://canada1.discourse-cdn.com/flex011/uploads/kirupa/original/3X/6/2/621e5c11736f46532526e61be85940af4230f3e5.png) [@system](https://forum.kirupa.com/u/system)\
**Post date:** [September 7, 2004, 11:54pm UTC](https://forum.kirupa.com/t/adware-wont-go-away/63555/4 "2004-09-07T23:54:54Z")

</div>

don’t have much time - but a program called “Pest Patrol” should remove it without a hitch for you.

---

<div class="post-metadata">

**Author:** ![system](https://canada1.discourse-cdn.com/flex011/uploads/kirupa/original/3X/6/2/621e5c11736f46532526e61be85940af4230f3e5.png) [@system](https://forum.kirupa.com/u/system)\
**Post date:** [September 8, 2004, 1:26am UTC](https://forum.kirupa.com/t/adware-wont-go-away/63555/5 "2004-09-08T01:26:00Z")

</div>

Reboot in **safe mode** (by tapping F8 at startup and select safe mode from the menu).  
Be sure you’re able to [view hidden files](http://www.xtra.co.nz/help/0,,4155-1916458,00.html), and remove the following files in bold (if found):

C:\Program Files\*_Web\_rebates_\*\<-----folder

more information hit up [geekstogo](http://www.geekstogo.com/forum)

---

<div class="post-metadata">

**Author:** ![system](https://canada1.discourse-cdn.com/flex011/uploads/kirupa/original/3X/6/2/621e5c11736f46532526e61be85940af4230f3e5.png) [@system](https://forum.kirupa.com/u/system)\
**Post date:** [September 8, 2004, 1:47am UTC](https://forum.kirupa.com/t/adware-wont-go-away/63555/6 "2004-09-08T01:47:12Z")

</div>

> [@prstudio](#):
>
> don’t have much time - but a program called “Pest Patrol” should remove it without a hitch for you.

Not Free = Not for me. :trout:

> [@crewman747](#):
>
> Reboot in **safe mode** (by tapping F8 at startup and select safe mode from the menu).  
> Be sure you’re able to [view hidden files](http://www.xtra.co.nz/help/0,,4155-1916458,00.html), and remove the following files in bold (if found):  
> C:\Program Files\*_Web\_rebates_\*\<-----folder  
> more information hit up [geekstogo](http://www.geekstogo.com/forum)

Been there, done that. Failed 😉

---

<div class="post-metadata">

**Author:** ![system](https://canada1.discourse-cdn.com/flex011/uploads/kirupa/original/3X/6/2/621e5c11736f46532526e61be85940af4230f3e5.png) [@system](https://forum.kirupa.com/u/system)\
**Post date:** [September 8, 2004, 1:50am UTC](https://forum.kirupa.com/t/adware-wont-go-away/63555/7 "2004-09-08T01:50:20Z")

</div>

[ot]Are you really the vice chairman of toyota?[/ot]

---

<div class="post-metadata">

**Author:** ![system](https://canada1.discourse-cdn.com/flex011/uploads/kirupa/original/3X/6/2/621e5c11736f46532526e61be85940af4230f3e5.png) [@system](https://forum.kirupa.com/u/system)\
**Post date:** [September 8, 2004, 3:37am UTC](https://forum.kirupa.com/t/adware-wont-go-away/63555/8 "2004-09-08T03:37:56Z")

</div>

ok well here we go…[Download HiJack This](http://www.tomcoyote.org/hjt/)

open it, hit scan, then save log, then copy and paste the log here.

---

<div class="post-metadata">

**Author:** ![system](https://canada1.discourse-cdn.com/flex011/uploads/kirupa/original/3X/6/2/621e5c11736f46532526e61be85940af4230f3e5.png) [@system](https://forum.kirupa.com/u/system)\
**Post date:** [September 8, 2004, 4:36am UTC](https://forum.kirupa.com/t/adware-wont-go-away/63555/9 "2004-09-08T04:36:06Z")

</div>

theres a freeware program called “Adaware” made by a swedish company “lavasoft”. just install it and update the file defenitions…that should do it, very nice program for spam and stuff like that

---

<div class="post-metadata">

**Author:** ![system](https://canada1.discourse-cdn.com/flex011/uploads/kirupa/original/3X/6/2/621e5c11736f46532526e61be85940af4230f3e5.png) [@system](https://forum.kirupa.com/u/system)\
**Post date:** [September 8, 2004, 4:51am UTC](https://forum.kirupa.com/t/adware-wont-go-away/63555/10 "2004-09-08T04:51:23Z")

</div>

Adaware + Spybot + 2 restarts = no more spy/adware

---

<div class="post-metadata">

**Author:** ![system](https://canada1.discourse-cdn.com/flex011/uploads/kirupa/original/3X/6/2/621e5c11736f46532526e61be85940af4230f3e5.png) [@system](https://forum.kirupa.com/u/system)\
**Post date:** [September 8, 2004, 4:56am UTC](https://forum.kirupa.com/t/adware-wont-go-away/63555/11 "2004-09-08T04:56:12Z")

</div>

![](http://home.deds.nl/~t_one/images/updates/results.gif)

Go check out spysweeper

---

<div class="post-metadata">

**Author:** ![system](https://canada1.discourse-cdn.com/flex011/uploads/kirupa/original/3X/6/2/621e5c11736f46532526e61be85940af4230f3e5.png) [@system](https://forum.kirupa.com/u/system)\
**Post date:** [September 8, 2004, 5:39am UTC](https://forum.kirupa.com/t/adware-wont-go-away/63555/12 "2004-09-08T05:39:44Z")

</div>

TopRebates Manual Removal:  
Follow these steps to remove TopRebates from your machine. Begin by backing up your registry and your system, and/or setting a Restore Point, to prevent trouble if you make a mistake.

Kill these running processes with Task Manager:  
arupdate.exe  
programfilesdir+\web\_rebates\disp1150.exe  
programfilesdir+\webrebates\webrebates.exe  
programfilesdir+\webrebates\webrebates1.exe  
systemroot+\2805e.exe  
unregister.exe  
unstsa3.exe  
webrebates0.exe

go to start - run - type regedit -

Go to the key HKEY\_LOCAL\_MACHINE\Software\Microsoft\Windows\CurrentVersion\Run.  
If you find the value HKEY\_LOCAL\_MACHINE\software\microsoft\windows\currentversion\run\webrebates, delete it and reboot the machine immediately.  
If you find the value HKEY\_LOCAL\_MACHINE\software\microsoft\windows\currentversion\run\webrebates0, delete it and reboot the machine immediately.

Unregister these DLLs with Regsvr32, then reboot:  
start - run then type as an example the following format:  
"regsvr32 /u filefromlistbelow.dll"  
continue through the list - typing the command each time and pressing ok

adroar.dll  
systemroot+\3\_0\_1browserhelper3.dll  
systemroot+  
eti.dll  
systemroot+\system32\imgconv.dll  
systemroot+\system32\vic32.dll

Remove these registry items (if present) with RegEdit:  
HKEY\_LOCAL\_MACHINE\software\classes\appid\hungryhands.dll\appid  
HKEY\_LOCAL\_MACHINE\software\classes\clsid{0a8ce102-fa03-4612-9bee-7fe5452f4cb1}  
HKEY\_LOCAL\_MACHINE\software\classes\clsid{bcf96fb4-5f1b-497b-aecc-910304a55011}\appid  
HKEY\_LOCAL\_MACHINE\software\classes\interface{f8fb4ea2-6c05-4de5-8cd0-625b03f48e22}  
HKEY\_LOCAL\_MACHINE\software\classes ypelib{03f8822f-8877-4002-8bcd-b532d53d8471}  
HKEY\_LOCAL\_MACHINE\software\microsoft\internet explorer oolbar{26398112-f068-4273-964b-a1d8bcf3e576}  
HKEY\_LOCAL\_MACHINE\software\microsoft\windows\currentversion\explorer\browser helper objects{c5941ee5-6dfa-11d8-86b0-0002441a9695}\bho\_path  
HKEY\_LOCAL\_MACHINE\software\microsoft\windows\currentversion\explorer\browser helper objects{c5941ee5-6dfa-11d8-86b0-0002441a9695}\bhonew  
HKEY\_LOCAL\_MACHINE\software\microsoft\windows\currentversion\explorer\browser helper objects{c5941ee5-6dfa-11d8-86b0-0002441a9695}\bhonew\_url  
HKEY\_LOCAL\_MACHINE\software\microsoft\windows\currentversion\explorer\browser helper objects{c5941ee5-6dfa-11d8-86b0-0002441a9695}\bhonew\_version  
HKEY\_LOCAL\_MACHINE\software\microsoft\windows\currentversion\explorer\browser helper objects{c5941ee5-6dfa-11d8-86b0-0002441a9695}\bhoversion  
HKEY\_LOCAL\_MACHINE\software\microsoft\windows\currentversion\explorer\browser helper objects{c5941ee5-6dfa-11d8-86b0-0002441a9695}\keynew  
HKEY\_LOCAL\_MACHINE\software\microsoft\windows\currentversion\explorer\browser helper objects{c5941ee5-6dfa-11d8-86b0-0002441a9695}\keynew\_url  
HKEY\_LOCAL\_MACHINE\software\microsoft\windows\currentversion\explorer\browser helper objects{c5941ee5-6dfa-11d8-86b0-0002441a9695}\keynew\_version  
HKEY\_LOCAL\_MACHINE\software\microsoft\windows\currentversion\explorer\browser helper objects{c5941ee5-6dfa-11d8-86b0-0002441a9695}\keyversion  
HKEY\_LOCAL\_MACHINE\software\microsoft\windows\currentversion\explorer\dcr2  
HKEY\_LOCAL\_MACHINE\software\microsoft\windows\currentversion\moduleusage  
\c:/winnt/downloaded program files/conflict.1/installer.dll.owner  
HKEY\_LOCAL\_MACHINE\software\microsoft\windows\currentversion\moduleusage  
\c:/winnt/downloaded program files/conflict.1/installer.dll{7eb15626-cb8e-4174-8a72-c055b12b4310}  
HKEY\_LOCAL\_MACHINE\software\microsoft\windows\currentversion\moduleusage  
\c:/winnt/downloaded program files/wuinst.dll.owner  
HKEY\_LOCAL\_MACHINE\software\microsoft\windows\currentversion\moduleusage  
\c:/winnt/downloaded program files/wuinst.dll{e2f2b9d0-96b9-4b25-b90c-636ecb207d18}  
HKEY\_LOCAL\_MACHINE\software\microsoft\windows\currentversion\run\webrebates  
HKEY\_LOCAL\_MACHINE\software\microsoft\windows\currentversion\run\webrebates0  
HKEY\_LOCAL\_MACHINE\software\microsoft\windows\currentversion\shell extensions\approved{26398112-f068-4273-964b-a1d8bcf3e576}  
HKEY\_LOCAL\_MACHINE\software\microsoft\windows\currentversion\uninstall\untopr1150  
\displayname  
HKEY\_LOCAL\_MACHINE\software\microsoft\windows\currentversion\uninstall\untopr1150  
\uninstallstring  
HKEY\_LOCAL\_MACHINE\software\microsoft\windows\currentversion\uninstall\windows sr 3.0--  
HKEY\_LOCAL\_MACHINE\software\microsoft\windows\currentversion\uninstall\windows sr 3.0\displayname  
HKEY\_LOCAL\_MACHINE\software\microsoft\windows\currentversion\uninstall\windows sr 3.0\uninstallstring

Remove these files (if present) with Windows Explorer:  
1150\_0.dat  
1150\_1.dat  
1150\_2.dat  
1150sh.dat  
40d3649e11d4.dat  
40d364a11d51.dat  
40d364a94b0d.dat  
40d364aa1c1d.dat  
adroar.dll  
arupdate.exe  
autotrack\_readme1.txt  
b3\_t\_%22web+rebates%22763.xml  
belt.ini  
fwntoolbar.dll.manifest  
install.log  
jau5055.dat  
jsy5055.dat  
key3.txt  
log.txt  
merc1158.dat  
popo1150a\_r.htm  
popo1150a\_rb.htm  
popo1150a\_rbh.htm  
popo1150a\_u.htm  
popo1150a\_ub.htm  
popo1150a\_ubh.htm  
pref1150a.htm  
programfilesdir+\web\_rebates\disp1150.exe  
programfilesdir+\webrebates\webrebates.exe  
programfilesdir+\webrebates\webrebates1.exe  
psid1158.dat  
rge5055.dat  
scri1150a.htm  
spec1150a\_r.htm  
spec1150a\_rb.htm  
spec1150a\_rbh.htm  
spec1150a\_u.htm  
spec1150a\_ub.htm  
spec1150a\_ubh.htm  
sty5055.dat  
systemroot+\2805e.exe  
systemroot+\3\_0\_1browserhelper3.dll  
systemroot+\artmmp.ini  
systemroot+\cache371\b\_371\_0\_1\_501300.htm  
systemroot+\cache371\b\_371\_0\_1\_569200.htm  
systemroot+\cache371\b\_371\_0\_1\_582200.htm  
systemroot+  
eti.dll  
systemroot+\system32\adcache\b\_371\_0\_1\_501300.htm  
systemroot+\system32\adcache\b\_371\_0\_1\_569200.htm  
systemroot+\system32\adcache\b\_371\_0\_1\_582200.htm  
systemroot+\system32\imgconv.dll  
systemroot+\system32\vic32.dll  
topr1150.dat  
toprebates.txt  
unregister.exe  
unstsa3.exe  
web\_rebates.txt  
webrebates0.exe

Remove these directories (if present) with Windows Explorer:  
programfilesdir+\web\_rebates  
programfilesdir+\web\_rebates\da1150\david  
programfilesdir+\web\_rebates\sy1150\html  
programfilesdir+\web\_rebates\sy1150\images  
programfilesdir+\web\_rebates\sy1150\sy1150  
programfilesdir+\web\_rebates\sy1150 p1150  
systemroot+\winskw

make sure that the first processes are stopped - if they aren’t you will run into problems - you could also reboot into safe mode to do this procedure.

if you have trouble let me know.

---

<div class="post-metadata">

**Author:** ![system](https://canada1.discourse-cdn.com/flex011/uploads/kirupa/original/3X/6/2/621e5c11736f46532526e61be85940af4230f3e5.png) [@system](https://forum.kirupa.com/u/system)\
**Post date:** [September 8, 2004, 5:48am UTC](https://forum.kirupa.com/t/adware-wont-go-away/63555/13 "2004-09-08T05:48:25Z")

</div>

hijack this is the easiest way to get rid of it but be careful when deleting stuff be very careful

---

<div class="post-metadata">

**Author:** ![system](https://canada1.discourse-cdn.com/flex011/uploads/kirupa/original/3X/6/2/621e5c11736f46532526e61be85940af4230f3e5.png) [@system](https://forum.kirupa.com/u/system)\
**Post date:** [September 8, 2004, 7:20am UTC](https://forum.kirupa.com/t/adware-wont-go-away/63555/14 "2004-09-08T07:20:03Z")

</div>

hijack this doesn’t remove but like half of the program unfortunately.

---

<div class="post-metadata">

**Author:** ![system](https://canada1.discourse-cdn.com/flex011/uploads/kirupa/original/3X/6/2/621e5c11736f46532526e61be85940af4230f3e5.png) [@system](https://forum.kirupa.com/u/system)\
**Post date:** [September 8, 2004, 7:58pm UTC](https://forum.kirupa.com/t/adware-wont-go-away/63555/15 "2004-09-08T19:58:07Z")

</div>

> [@Yeldarb](#):
>
> [ot]Are you really the vice chairman of toyota?[/ot]

No, it’s just to intimidate the hoe.
