Give me a bit and I will get you a list.
First of all though you still have some nasty things showing in your HJT log.
Two KEY items showing are;
O4 - HKLM\..\Run: [DDCActiveMenu] "C:\Program Files\WildTangent\DDC\ActiveMenu\DDCActiveMenu.exe " -boot
1) Click on Start, Settings, Control Panel
2) Double-click on Add/Remove Programs
3) Click on the WildTangent selection and Change/Remove, Uninstall, or Add/Remove depending on the operating system. Then follow the onscreen prompts to remove the WT Driver.
If it DOES NOT appear in Add/Remove then try the following;
Delete the WildTangent folder in Program Files and WindowsLet me know if you are NOT able to do this.
- Open My Computer
- Double-click on Drive C
- Double-click on Program Files
- Right-click on WildTangent and choose Delete (if the folder exists)
- Go back to Drive C and double-click on Windows
- Right-click on the WT folder and choose Delete (if the folder exists)
The other baddie appearing in the HJT log is this one;
O4 - HKLM\..\Run: [explorer] C:\WINDOWS\system32\explorer.exe
This is RapidBlaster.
RapidBlaster is a task run on Windows startup. When an internet connection is present it periodically connects to its servers to retrieve advertising.
To remove RapidBlaster please do the following;
Update your Nortons.
Totally disconnect your internet connection, in other words, UNPLUG from the internet completely.
Uninstall RapidBlaster
- Press Ctrl+Alt+Delete once.
- Click Task Manager.
- Click the Processes tab.
- Double-click the Image Name column header to alphabetically sort the processes.
- Scroll through the list and look for Rb32.exe.
- If you find the file, click it, and then click End Process.
- Exit the Task Manager.
Next open your Norton Program.
- Click Start > Control Panel.
- In the Control Panel window, double-click Add or Remove Programs.
Click "RapidBlaster" or "rb32 lptt01."- Remove
Next, still disconnected from the internet I want you to run HiJackThis again and place checkmarks next to the following entries if still present;
- Start Norton AntiVirus and make sure that it is configured to scan all the files.
- Run a full system scan.
- If any files are detected as infected with Dialer.Rapidblaster, click Delete.
O2 - BHO: SWEETIE Class - {1A0AADCD-3A72-4b5f-900F-E3BB5A838E2A} - C:\PROGRA~1\MACROG~1\SWEETI~1\toolbar.dll (file missing)
O2 - BHO: (no name) - {4B18DD50-C996-44fc-AC52-0FECFF82ED58} - (no file)
O3 - Toolbar: SweetIM For Internet Explorer - {BC4FFE41-DE9F-46fa-B455-AAD49B9F9938} - C:\Program Files\Macrogaming\SweetIMBarForIE\toolbar.dll (file missing)
O4 - HKLM\..\Run: [DDCActiveMenu] "C:\Program Files\WildTangent\DDC\ActiveMenu\DDCActiveMenu.exe " -boot
O4 - HKLM\..\Run: [explorer] C:\WINDOWS\system32\explorer.exe
O9 - Extra button: (no name) - {e2e2dd38-d088-4134-82b7-f2ba38496583} - %windir%\Network Diagnostic\xpnetdiag.exe (file missing)
O9 - Extra 'Tools' menuitem: @xpsp3res.dll,-20001 - {e2e2dd38-d088-4134-82b7-f2ba38496583} - %windir%\Network Diagnostic\xpnetdiag.exe (file missing)
O14 - IERESET.INF: START_PAGE_URL=http://www.savewealth.com
Once you have placed the checkmarks then click the FIX button.
Exit HJT.
Shut down the computer. Reconnect the internet. Reboot the computer and run a NEW HJT scan, save the log and post back here.


Reply With Quote