PDA

View Full Version : Adware


Shackled Phoenix
Dec 25, 2004, @ 05:49 PM
Alright, i've got 3 things of adware on my PC i can't seem to get rid of. No adware remover i've found has been able to get it off, including adaware and hijack this (hijack this usually kills anything and everything).

The files i'm unable to delete are

winctlad.exe
Webrebates0.exe
bargains.exe

anyone got any ideas? i'm gonna reboot and try killing em in command prompt but since XP isn't DoS based, it doesn't seem to work as well anymore (i've tried and failed this method with other programs before)

edit:
alright, thanks to ultrawinclean i'm down to just webrebates0.exe

Karmashock
Dec 25, 2004, @ 11:42 PM
I can't believe the ad removing software isn't taking care of this... however, you can remove this manually like so:
Destroy Autorun:
Delete the following keys
HKEY_LOCAL_MACHINE\software\microsoft\windows\curr entversion\run\webrebates,
and/OR
HKEY_LOCAL_MACHINE\software\microsoft\windows\curr entversion\run\webrebates0,

Reboot your system then:

Make sure you click start --> Run and type in msconfig. Then select the startup tab. Any references to the processes below.

End Processes (may or may not exist):
2805e.exe
arupdate.exe
cashback.exe
cb.exe
djtopr1150.exe
flash.exe
nls.exe
disp1150.exe
webrebates0.exe
webrebates1.exe
webrebates_cdt_installsilent.exe
unstsa3.exe

Unregister DLLs:
C:\windows\3_0_1browserhelper3.dll
C:\windows\neti.dll
C:\windows\system32\imgconv.dll
C:\windows\system32\vic32.dll

Remove Directories:
C:\Program Files\web_rebates
C:\Windows\winskw

And next time wear protection... you dirty dirty girl. :D

Shackled Phoenix
Dec 26, 2004, @ 12:58 AM
this didn't help. the following keys did not exist. Weird thing is, with winctlad gone winpatrol managed to finally kill the webrebate startup which enabled me to delete webrebates.

I've got an unidentified process though that i can't freaking kill. the process is Tsa2.exe, i've done a system search can't find it, winpatrol can't stop it and i've no idea what it does, only that it's not something that's supposed to be there.

Edit: new virus scanner found and visciously stabbed Tsa2.exe. problem solved, PC actually clean.

Karmashock
Dec 26, 2004, @ 07:48 AM
c:\Program Files\Common Files\tsa\tsm2.exe

That's the 'file' name for that process. At least according to google... I don't get adware, spyware, or viruses... Easily accomplished by staying away from porn sites... the only two ways I've ever seen people get them is from those places or basically intentionally infecting yourself at download.com. If it says "shareware" read that as "spyware"...

L&P, KS.

Fragman
Dec 26, 2004, @ 07:22 PM
Run system in safe mode only necessary files will be loaded then you can delete it all

JADezimar
Dec 26, 2004, @ 07:51 PM
You have to end the process before you can delete it. If the process is still running thats why you get the read and write or program is in use message and cannot delete. Im assuming you identified the adware through the process tree.