Go to this post here first, and follow the instructions EXACTLY.
How to remove Begin2Search / Coolwebsearch
Boot into Safe Mode.
Uninstall DAP, it is riddled with ads.
Unless you know what these are good for, uninstall them as well:
C:\Program Files\
Rational\ClearCase\bin\albd_server.exe
C:\Program Files\
Kana WallChanger\KanaWall.exe
While still in Safe Mode, run HJT standalone and let it 'fix' (if still there):
C:\Program Files\Rational\ClearCase\bin\albd_server.exe
C:\Program Files\Rational\ClearCase\bin\lockmgr.exe
C:\Program Files\Rational\ClearCase\bin\cccredmgr.exe
C:\PROGRA~1\
DAP\DAP.EXE
C:\Program Files\Kana WallChanger\KanaWall.exe
C:\WINNT\system32\
w?aclt.exe
R1 - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings,ProxyOverride = helpnow.cendant.com;
R0 - HKCU\Software\Microsoft\Internet Explorer\Toolbar,LinksFolderName =
O2 - BHO: (no name) - {98274D33-A6F0-8700-D348-8D4DF6D12FB7} - C:\WINNT\system32\
ottus.dll
O3 - Toolbar: (no name) - {62999427-33FC-4baf-9C9C-BCE6BD127F08} - (no file)
O4 - HKLM\..\Run: [CCDoctorLogonTesting] "C:\Program Files\Rational\ClearCase\bin\ccdoctor.exe" /LogonStartup
O4 - HKLM\..\Run: [DownloadAccelerator] C:\PROGRA~1\DAP\DAP.EXE /STARTUP
O4 - HKCU\..\Run: [Kana WallChanger] "C:\Program Files\Kana WallChanger\KanaWall.exe"
O4 - HKCU\..\Run: [Hck] C:\WINNT\system32\w?aclt.exe
O8 - Extra context menu item: &Download with &DAP - C:\PROGRA~1\DAP\dapextie.htm
O8 - Extra context menu item: Download &all with DAP - C:\PROGRA~1\DAP\dapextie2.htm
O16 - DPF: {00B71CFB-6864-4346-A978-C0A14556272C} (Checkers Class) -
http://messenger.zone.msn.com/binary/msgrchkr.cab31267.cab
O16 - DPF: {14B87622-7E19-4EA8-93B3-97215F77A6BC} (MessengerStatsClient Class) -
http://messenger.zone.msn.com/binary/MessengerStatsPAClient.cab31267.cab
O16 - DPF: {332bd5a0-8000-11d7-b657-00c04faedb18} (Oracle JInitiator 1.1.8.22) -
O16 - DPF: {8E0D4DE5-3180-4024-A327-4DFAD1796A8D} (MessengerStatsClient Class) -
http://messenger.zone.msn.com/binary/MessengerStatsClient.cab31267.cab
O16 - DPF: {B8BE5E93-A60C-4D26-A2DC-220313175592} (ZoneIntro Class) -
http://messenger.zone.msn.com/binary/ZIntro.cab32846.cab
O16 - DPF: {E06E2E99-0AA1-11D4-ABA6-0060082AA75C} (GpcContainer Class) -
https://us6.webex.com/client/v_mywebex/webex/ieatgpc.cab
O16 - DPF: {E87F6C8E-16C0-11D3-BEF7-009027438003} (Persits Software XUpload) -
http://www.streamload.com/Upload/XUpload.ocx
O23 - Service: Atria Location Broker - Unknown - C:\Program Files\Rational\ClearCase\bin\albd_server.exe
O23 - Service: Atria Cred Manager - Unknown - C:\Program Files\Rational\ClearCase\bin\cccredmgr.exe
O23 - Service: Atria Lock Manager - Unknown - C:\Program Files\Rational\ClearCase\bin\lockmgr.exe
When done, delete the
bold files. When a
directory is also
bold, delete everything in it, including that directory itself.