How to remove Webrebates

6 threats found

Adware Webrebates

6 threats removed

Recommended solution

Download OSHI Defender and scan your PC for free

Download and scan now




Webrebates is a form of malicious software that delivers unwanted advertisements on your computer. Programs like this can also be used to track and report your computing activities without your consent, so this type of application can pose a serious security threat.




How to manually remove Webrebates guide. Only for ADVANCED users.

  • Step 1: Basic check for Webrebates activity

    Check running processes on your system. Usually you can find Webrebates process running. Use the Ctrl+Shift+Esc buttons combination to open system information window and click Processes tab. Scroll down the whole list and try to find the process named like Webrebates. If you find Webrebates process running, right click on it and choose “End Process”. It will disable Webrebates for the current Windows session, but remember that if you do not completely remove Webrebates using next steps, then your PC will stay vulnerable to malware attack. Next steps are much more important in removing Webrebates.

  • Step 2: Disconnect your PC from the Internet

    Prevent the malware from leaking or spreading your personal data. Adware usually uses the Internet to transfer all possible and important information you have. Some Adwares are not so “Active” and they can simply disable some Windows features and options. To disconnect your PC from the Internet you need to plug-off LAN cable (if you use LAN connection) or to turn of the Wi-Fi module (if you use Wi-Fi Internet connection). Most of (not 100%) Adwares can not access Wi-Fi module preferences. Turning off the Internet will disable Webrebates from transferring any data from your PC.

  • Step 3: Enter the safe mode.

    The next step is very important in removing Webrebates. After turning off the Internet and disabling Webrebates process you will need to reboot your PC in so-called Safe Mode. Safe Mode is a Windows mode which allows you to start the System using only important applications and services. Safe Mode does not usually allow Webrebates to load when the system boots (!!!but exceptions can appear!!!). Choose Restart in Windows Start menu and wait until the screen turns off.

    After that you have to follow the next instructions according to the versions of Microsoft Windows you use:

      Windows XP:
    1. Press the F8 key repeatedly when the first screen appears.

    2. Select Safe Mode from Windows Advanced Options Menu and press ENTER.

      Windows Vista, 7:
    1. Press the F8 key repeatedly when the first screen appears.

    2. Use the arrow keys from Windows Advanced Options Menu in order to select Safe Mode and press ENTER.

      Windows 8, 8.1, 10:
    1. Press and hold the Shift button when left-clicking the Restart button on Windows log-on screen.

    2. Select Safe Mode from Windows Troubleshooting boot screen and press ENTER.

  • Step 4: Removing virus files

    Having booted your PC in Safe mode you have to start cleaning your PC manually by deleting every file associated with Webrebates one by one. Here is the list of all files associated with Webrebates. Delete all files listed below using the Shift+Delete buttons combination. Always double check the file name as sometimes Adwares use very similar filenames as very important system files do and you can mistakenly remove important system file what will harm your system and you will not be able to boot your PC at all.

    • [RANDOM LETTER].gif

    • [RANDOM NAME].dat

    • 1150_0.dat

    • 1150_1.dat

    • 1150_2.dat

    • 1150sh.dat

    • 2805e.exe

    • 3_0_1browserhelper3.dll

    • 41a3c264191.dat

    • 41a3c26c4d33.da

    • 42d3837c6f64.dat

    • 42d385b14548.dat

    • 4af289ae2885.dat

    • 4af289b63360.dat

    • Application

    • AutoTrack_README1.txt

    • cmpt70000.dat

    • data_excludes_topr1150.dls

    • data_topr1150.dls

    • disp1150.exe

    • djtopr1150.exe

    • dump.txt

    • f_popo1150[RANDOM LETTER]_rb.htm

    • f_popo1150[RANDOM LETTER]_ub.htm

    • f_popo1150c_rb.htm

    • f_popo1150c_ub.htm

    • f_spec1150[RANDOM LETTER]_rb.htm

    • f_spec1150[RANDOM LETTER]_ub.htm

    • f_spec1150c_rb.htm

    • f_spec1150c_ub.htm

    • foot1150[RANDOM LETTER]_rb.htm

    • foot1150[RANDOM LETTER]_ub.htm

    • foot1150c_rb.htm

    • foot1150c_ub.htm

    • ftoprRPMP0.htm

    • ftoprRPMS0.htm

    • ftoprUPMP0.htm

    • ftoprUPMS0.htm

    • imgconv.dll

    • loader.dls

    • log.txt

    • logfile.txt

    • merc1150.dat

    • merc1158.dat

    • merc1167.dat

    • mercexcl.dat

    • merchants.dls

    • mercj1151.dls

    • p.gif

    • personality.dls

    • popo1150[RANDOM LETTER].htm

    • popo1150a_r.htm

    • popo1150a_rb.htm

    • popo1150a_rbh.htm

    • popo1150a_u.htm

    • popo1150a_ub.htm

    • popo1150a_ubh.htm

    • popo1150c.htm

    • pref1150[RANDOM LETTER].htm

    • pref1150a.htm

    • pref1150c.htm

    • psid1150.dat

    • psid1151.dls

    • psid1158.dat

    • psid1167.dat

    • psid1187.dat

    • readme.txt

    • remv1150c.htm

    • rge5055.dat

    • s435617293f0e.dat

    • scri1150a.htm

    • shopping.dls

    • spec1150a_r.htm

    • spec1150a_rb.htm

    • spec1150a_rbh.htm

    • spec1150a_u.htm

    • spec1150a_ub.htm

    • spec1150a_ubh.htm

    • spec1150c.htm

    • sty5055.dat

    • system.dls

    • systemdata.dls

    • systemdata1.dls

    • Thumbs.db

    • topmoxie_conflicts2.htm

    • topmoxie_proxy.htm

    • topr_blnk.gif

    • topr_c_envelope.gif

    • topr_c_footer.gif

    • topr_c_hdr_autotrack_remove.gif

    • topr_c_hdr_settings_toprebates.gif

    • topr_c_hdr_settings.gif

    • topr_c_pop_circles_bg2.gif

    • topr_c_pop_circles.gif

    • topr_c_warning.gif

    • topr_envelope.gif

    • topr_pop_circles_2.gif

    • topr_pop_circles_3.gif

    • topr_pop_circles.gif

    • topr_pop_settings.gif

    • topr_popup_toprebates_hdr_small.gif

    • topr_popup_toprebates_hdr_small2.gif

    • topr_register_footer.gif

    • topr_register.gif

    • topr11150.dat

    • topr1150_envelope.gif

    • topr1150_pop_circles.gif

    • topr1150_pop_settings.gif

    • topr1150_popup_toprebates_hdr_small.gif

    • topr1150_popup_toprebates_hdr_small2.gif

    • topr1150_popup4.htm

    • topr1150_preferences0_wo.htm

    • topr1150_preferences0.htm

    • topr1150_register_footer.gif

    • topr1150_register.gif

    • topr1150_script0.htm

    • topr1150.dat

    • topr1150.dls

    • toprC0.htm

    • toprex.dat

    • toprex.dls

    • toprP0.htm

    • toprp11150.dat

    • toprR1.htm

    • toprRPMF0.htm

    • toprUPMF0.htm

    • toprXPMP0.htm

    • toprXPMS0.htm

    • trebates.exe

    • unstsa3.exe

    • updates.dls

    • w11150.exe

    • web_rebates.txt

    • webcpr_grab0_wo.htm

    • webcpr_grab0.htm

    • webcpr.dls

    • weblrebates.dat

    • WebRebates_Auto_InstallSilent_Euro.exe

    • webrebates.dll

    • WebRebates.exe

    • WebRebates.inf

    • WebRebates0.exe

    • WebRebates1.exe

    • webrebates2.dll

    • WebRebates2.exe

    • WebRebatesrun.exe

    • websrebates.dat

    • webzrebates.dat

    • x435617195967.dat

    Please, remember that viruses are always progressing and sometimes new files can appear. If you are using our offline PDF guide on How to remove Webrebates, please check if you have it’s latest version.

    We do not guarantee that Webrebates has the same file structure at the moment of deleting.

    After removing all files associated with Webrebates that were listed above, reboot your system in normal mode and check if your PC works fine or you still have any troubles.

    It it is OK – congratulations! You have made a great job!

    If it is still NOT ok – use OSHI Defender to check your PC.

Similar threats

Associated threats

Virus files


The main symptoms of the infection of your computer

Fix all problems

Frequently Asked Questions

We have an answer

  • How does Webrebates infect my computer?

  • I detected Webrebates on my computer. What do I do?

  • What damage can Webrebates do to my computer?

  • What are the main symptoms of Webrebates?

  • Can Webrebates spread to other computers?

  • Countries with the highest Webrebates infection rates.

  • The first recorded appearance of Webrebates

I have a question


You have a question?


How does Webrebates infect my computer?

Webrebates is an Adware-type virus. The most common way a computer becomes infected with Webrebates is when a user downloads free software or browser toolbars.

Was the answer helpful?
Was the answer helpful?

I detected Webrebates on my computer. What do I do?

If you have OSHI Defender installed on your computer, it will detect and remove Webrebates and all related files. First, restart your browser and then check the Home Page to make sure that you’re still using your preferred search engine (Google, Bing, Yahoo, etc.), because Webrebates replaces users’ search engines with ones that display ads.

Was the answer helpful?
Was the answer helpful?

What damage can Webrebates do to my computer?

Developed by large companies, viruses like Webrebates are mostly legal products that hackers use to make money on the ads that Webrebates displays on infected computers.

Was the answer helpful?
Was the answer helpful?

What are the main symptoms of Webrebates?

High network activity
Unusual browser settings
Pop-up windows

Was the answer helpful?
Was the answer helpful?

Can Webrebates spread to other computers?

As a rule, Webrebates requires user interaction and cannot automatically infect other computers on your local network or by using the same USB-disk on additional computers. There may be exceptions, though.

Was the answer helpful?
Was the answer helpful?

Countries with the highest Webrebates infection rates.


Was the answer helpful?
Was the answer helpful?

The first recorded appearance of Webrebates


Was the answer helpful?
Was the answer helpful?


Use the form below to send us your comments and questions

Address: Rm.709, Wellborne Commercial Centre, 8 Java Road, North Point, Hong Kong.

Report a problem

Please provide us with as much information and data as possible (Application name, application version, OSHI Defender version, OS version e.t.c.)

Affiliate program registration

Fill out following form and receive 80% commission per OSHI Defender sale