I mean, if its fixed its fixed but I don't see wareout in your log.

It’s quite possible that Wareout wasn’t present. CastleCops only lists the hijacked protocol as ‘As yet unidentified. Probably WareOut malware’, for which reason I recommended the FixWareout scan, but I also recommended editing the registry to set the key to the legitimate CLSID:

O18 - Protocol hijack: tv - {9E754710-6158-11D5-B6CE-0050DAAEA668}

This entry should be {CBD30858-AF45-11D2-B6D6-00C04FBBDE6E}

http://www.castlecops.com/o18list-65.html

The entry you have could be Wareout malware:

http://www.castlecops.com/o18list-99.html

It’s not clear from hamzahhaz’ post if FixWareout corrected the hijacked entry of if he edited it himself:

The tv value is changed to the one at castlecops O18-99.

hamzahhaz, can you tell us if you edited the above entry yourself? This will clear up the mystery for mauserme. :wink: