Zoek.exe v5.0.0.1 Updated 31-December-2015 Tool run by Van Alphen on do 05-05-2016 at 11:34:21,53. Microsoft Windows 7 Home Premium 6.1.7601 Service Pack 1 x64 Running in: Normal Mode Internet Access Detected Launched: C:\Users\Van Alphen\Downloads\zoek.exe [Scan all users] [Script inserted] ==== Older Logs ====================== C:\zoek-results2016-05-04-114206.log 60132 bytes ==== Deleting CLSID Registry Keys ====================== HKEY_USERS\S-1-5-21-3618103154-1282251522-2710838709-1000\Software\Microsoft\Windows\CurrentVersion\Ext\Stats\{BD6ECB00-7C4A-4F97-B425-44117F2A7AAE} deleted successfully HKEY_USERS\S-1-5-21-3618103154-1282251522-2710838709-1000\Software\Microsoft\Windows\CurrentVersion\Ext\Settings\{BD6ECB00-7C4A-4F97-B425-44117F2A7AAE} deleted successfully HKEY_LOCAL_MACHINE\SOFTWARE\Classes\AppID\{7F46C358-270D-4791-A579-AD1DDA1A3F7B} deleted successfully HKEY_CLASSES_ROOT\CLSID\{BAC72C85-CEC6-4B86-AF06-FA20C259FAB8} deleted successfully HKEY_CLASSES_ROOT\Wow6432Node\CLSID\{BAC72C85-CEC6-4B86-AF06-FA20C259FAB8} deleted successfully HKEY_LOCAL_MACHINE\SOFTWARE\Classes\AppID\{ABD8D96F-8F32-4167-B31F-FED987846B81} deleted successfully HKEY_LOCAL_MACHINE\SOFTWARE\Classes\AppID\{D2E5FFD9-E488-4844-8C6D-051AA67C99F2} deleted successfully HKEY_CLASSES_ROOT\Wow6432Node\CLSID\{6557DB6C-EFE1-45AC-92A6-FBB1554B7502} deleted successfully HKEY_CLASSES_ROOT\CLSID\{BD6ECB00-7C4A-4F97-B425-44117F2A7AAE} deleted successfully HKEY_CLASSES_ROOT\Wow6432Node\CLSID\{BD6ECB00-7C4A-4F97-B425-44117F2A7AAE} deleted successfully HKEY_CLASSES_ROOT\CLSID\{E4ADC61E-D06A-4E0E-8582-78C809CC8450} deleted successfully HKEY_CLASSES_ROOT\Wow6432Node\CLSID\{E4ADC61E-D06A-4E0E-8582-78C809CC8450} deleted successfully HKEY_CLASSES_ROOT\Interface\{FD1B7376-A344-48BD-857D-C87B4D8502EF} deleted successfully HKEY_CLASSES_ROOT\Wow6432Node\Interface\{FD1B7376-A344-48BD-857D-C87B4D8502EF} deleted successfully HKEY_LOCAL_MACHINE\SOFTWARE\Classes\TypeLib\{48DDEC26-CEC3-478E-9566-0842DAF10CEA} deleted successfully HKEY_LOCAL_MACHINE\SOFTWARE\Classes\TypeLib\{921462B2-5269-45A2-AA8D-F8F7A3690255} deleted successfully HKEY_LOCAL_MACHINE\SOFTWARE\Classes\TypeLib\{EB2BEAEF-150C-4DE4-9D09-F16403C22769} deleted successfully HKEY_LOCAL_MACHINE\SOFTWARE\Classes\AppID\{87BDDAA1-CB99-4B47-89F6-7651D7731BC6} deleted successfully ==== Deleting CLSID Registry Values ====================== ==== Registry Fix Code ====================== Windows Registry Editor Version 5.00 [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Internet Explorer\MAIN\FeatureControl\FEATURE_BROWSER_EMULATION] "Amazon1ButtonTaskbarApp.exe"=- [-HKEY_LOCAL_MACHINE\SOFTWARE\AppDataLow\Software\Amazon\Amazon1ButtonApp] [-HKEY_LOCAL_MACHINE\SOFTWARE\AppDataLow\Software\Amazon] [-HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Active Setup\Installed Components\{981b174d-7733-4e7f-b89d-6545a7c21838}] [-HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\{B6DCCCD3-520D-4485-B642-FCC136CE12C3}] [-HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Amazon1ButtonBrowserHelper.Amazon1ButtonBHO\CLSID] [-HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Amazon1ButtonBrowserHelper.Amazon1ButtonBHO] [-HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Amazon1ButtonRuntime.Amazon1ButtonRuntime\CLSID] [-HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Amazon1ButtonRuntime.Amazon1ButtonRuntime] [-HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Amazon1ButtonRuntime.AmazonRuntimeServer\CLSID] [-HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Amazon1ButtonRuntime.AmazonRuntimeServer] [-HKEY_LOCAL_MACHINE\SOFTWARE\Classes\AmazonAppIE.AppGateway\CLSID] [-HKEY_LOCAL_MACHINE\SOFTWARE\Classes\AmazonAppIE.AppGateway] [-HKEY_LOCAL_MACHINE\SOFTWARE\Classes\AmazonAppIE.GadgetGateway\CLSID] [-HKEY_LOCAL_MACHINE\SOFTWARE\Classes\AmazonAppIE.GadgetGateway] [-HKEY_LOCAL_MACHINE\SOFTWARE\Classes\AppID\Amazon1ButtonBrowserHelper.dll] [-HKEY_LOCAL_MACHINE\SOFTWARE\Classes\AppID\Amazon1ButtonRuntime.dll] [-HKEY_LOCAL_MACHINE\SOFTWARE\Classes\AppID\AmazonAppIE.dll] [-HKEY_LOCAL_MACHINE\SOFTWARE\Classes\AppID\{7F46C358-270D-4791-A579-AD1DDA1A3F7B}] [-HKEY_LOCAL_MACHINE\SOFTWARE\Classes\AppID\{87BDDAA1-CB99-4B47-89F6-7651D7731BC6}] [-HKEY_LOCAL_MACHINE\SOFTWARE\Classes\AppID\{ABD8D96F-8F32-4167-B31F-FED987846B81}] [-HKEY_LOCAL_MACHINE\SOFTWARE\Classes\AppID\{D2E5FFD9-E488-4844-8C6D-051AA67C99F2}] [-HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{6557DB6C-EFE1-45AC-92A6-FBB1554B7502}\InprocServer32] [-HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{6557DB6C-EFE1-45AC-92A6-FBB1554B7502}\ProgID] [-HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{6557DB6C-EFE1-45AC-92A6-FBB1554B7502}\VersionIndependentProgID] [-HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{6557DB6C-EFE1-45AC-92A6-FBB1554B7502}] [-HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{BAC72C85-CEC6-4B86-AF06-FA20C259FAB8}\InprocServer32] [-HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{BAC72C85-CEC6-4B86-AF06-FA20C259FAB8}\ProgID] [-HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{BAC72C85-CEC6-4B86-AF06-FA20C259FAB8}\VersionIndependentProgID] [-HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{BAC72C85-CEC6-4B86-AF06-FA20C259FAB8}] [-HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{BD6ECB00-7C4A-4F97-B425-44117F2A7AAE}\InprocServer32] [-HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{BD6ECB00-7C4A-4F97-B425-44117F2A7AAE}\ProgID] [-HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{BD6ECB00-7C4A-4F97-B425-44117F2A7AAE}] [-HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{E4ADC61E-D06A-4E0E-8582-78C809CC8450}\InprocServer32] [-HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{E4ADC61E-D06A-4E0E-8582-78C809CC8450}\ProgID] [-HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{E4ADC61E-D06A-4E0E-8582-78C809CC8450}\VersionIndependentProgID] [-HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Installer\Products\3DCCCD6BD02558446B24CF1C63EC213C\SourceList] [-HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Installer\Products\3DCCCD6BD02558446B24CF1C63EC213C] [-HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Interface\{FD1B7376-A344-48BD-857D-C87B4D8502EF}] [-HKEY_LOCAL_MACHINE\SOFTWARE\Classes\TypeLib\{48DDEC26-CEC3-478E-9566-0842DAF10CEA}\1.0\0\win32] [-HKEY_LOCAL_MACHINE\SOFTWARE\Classes\TypeLib\{48DDEC26-CEC3-478E-9566-0842DAF10CEA}\1.0\HELPDIR] [-HKEY_LOCAL_MACHINE\SOFTWARE\Classes\TypeLib\{48DDEC26-CEC3-478E-9566-0842DAF10CEA}\1.0] [-HKEY_LOCAL_MACHINE\SOFTWARE\Classes\TypeLib\{921462B2-5269-45A2-AA8D-F8F7A3690255}\1.0\0\win32] [-HKEY_LOCAL_MACHINE\SOFTWARE\Classes\TypeLib\{921462B2-5269-45A2-AA8D-F8F7A3690255}\1.0\0\win64] [-HKEY_LOCAL_MACHINE\SOFTWARE\Classes\TypeLib\{921462B2-5269-45A2-AA8D-F8F7A3690255}\1.0\HELPDIR] [-HKEY_LOCAL_MACHINE\SOFTWARE\Classes\TypeLib\{921462B2-5269-45A2-AA8D-F8F7A3690255}\1.0] [-HKEY_LOCAL_MACHINE\SOFTWARE\Classes\TypeLib\{EB2BEAEF-150C-4DE4-9D09-F16403C22769}\1.0\0\win32] [-HKEY_LOCAL_MACHINE\SOFTWARE\Classes\TypeLib\{EB2BEAEF-150C-4DE4-9D09-F16403C22769}\1.0\0\win64] [-HKEY_LOCAL_MACHINE\SOFTWARE\Classes\TypeLib\{EB2BEAEF-150C-4DE4-9D09-F16403C22769}\1.0\HELPDIR] [-HKEY_LOCAL_MACHINE\SOFTWARE\Classes\TypeLib\{EB2BEAEF-150C-4DE4-9D09-F16403C22769}\1.0] [-HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\Amazon 1Button App Service] [-HKEY_LOCAL_MACHINE\SYSTEM\ControlSet002\services\Amazon 1Button App Service] [-HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\services\Amazon 1Button App Service] [-HKEY_USERS\S-1-5-21-3618103154-1282251522-2710838709-1000\Software\AppDataLow\Software\Amazon\Amazon1ButtonApp\Storage] [-HKEY_USERS\S-1-5-21-3618103154-1282251522-2710838709-1000\Software\AppDataLow\Software\Amazon\Amazon1ButtonApp\StorageIE] [-HKEY_USERS\S-1-5-21-3618103154-1282251522-2710838709-1000\Software\AppDataLow\Software\Amazon\Amazon1ButtonApp] [-HKEY_USERS\S-1-5-21-3618103154-1282251522-2710838709-1000\Software\AppDataLow\Software\Amazon] [-HKEY_USERS\S-1-5-21-3618103154-1282251522-2710838709-1000\Software\Microsoft\Amazon1ButtonApp] [-HKEY_USERS\S-1-5-21-3618103154-1282251522-2710838709-1000\Software\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap\Domains\amazon.com] ==== Registry Fix Code x64 ====================== Windows Registry Editor Version 5.00 [-HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{6557DB6C-EFE1-45AC-92A6-FBB1554B7502}\InprocServer32] [-HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{6557DB6C-EFE1-45AC-92A6-FBB1554B7502}\ProgID] [-HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{6557DB6C-EFE1-45AC-92A6-FBB1554B7502}\VersionIndependentProgID] [-HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{6557DB6C-EFE1-45AC-92A6-FBB1554B7502}] [-HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{BAC72C85-CEC6-4B86-AF06-FA20C259FAB8}\InprocServer32] [-HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{BAC72C85-CEC6-4B86-AF06-FA20C259FAB8}\ProgID] [-HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{BAC72C85-CEC6-4B86-AF06-FA20C259FAB8}\VersionIndependentProgID] [-HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{BAC72C85-CEC6-4B86-AF06-FA20C259FAB8}] [-HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{BD6ECB00-7C4A-4F97-B425-44117F2A7AAE}\InprocServer32] [-HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{BD6ECB00-7C4A-4F97-B425-44117F2A7AAE}\ProgID] [-HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{E4ADC61E-D06A-4E0E-8582-78C809CC8450}\InprocServer32] [-HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{BD6ECB00-7C4A-4F97-B425-44117F2A7AAE}] [-HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{E4ADC61E-D06A-4E0E-8582-78C809CC8450}\VersionIndependentProgID] [-HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{E4ADC61E-D06A-4E0E-8582-78C809CC8450}\ProgID] [-HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\Interface\{FD1B7376-A344-48BD-857D-C87B4D8502EF}] [-HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\AppID\Amazon1ButtonBrowserHelper.dll] [-HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\AppID\Amazon1ButtonRuntime.dll] [-HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\AppID\AmazonAppIE.dll] [-HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\AppID\{7F46C358-270D-4791-A579-AD1DDA1A3F7B}] [-HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\AppID\{87BDDAA1-CB99-4B47-89F6-7651D7731BC6}] [-HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\AppID\{ABD8D96F-8F32-4167-B31F-FED987846B81}] [-HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\AppID\{D2E5FFD9-E488-4844-8C6D-051AA67C99F2}] [-HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\TypeLib\{48DDEC26-CEC3-478E-9566-0842DAF10CEA}\1.0\0\win32] [-HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\TypeLib\{48DDEC26-CEC3-478E-9566-0842DAF10CEA}\1.0\HELPDIR] [-HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\TypeLib\{48DDEC26-CEC3-478E-9566-0842DAF10CEA}\1.0] [-HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\TypeLib\{921462B2-5269-45A2-AA8D-F8F7A3690255}\1.0\0\win32] [-HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\TypeLib\{921462B2-5269-45A2-AA8D-F8F7A3690255}\1.0\0\win64] [-HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\TypeLib\{921462B2-5269-45A2-AA8D-F8F7A3690255}\1.0\HELPDIR] [-HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\TypeLib\{921462B2-5269-45A2-AA8D-F8F7A3690255}\1.0] [-HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\TypeLib\{EB2BEAEF-150C-4DE4-9D09-F16403C22769}\1.0\0\win32] [-HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\TypeLib\{EB2BEAEF-150C-4DE4-9D09-F16403C22769}\1.0\0\win64] [-HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\TypeLib\{EB2BEAEF-150C-4DE4-9D09-F16403C22769}\1.0\HELPDIR] [-HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\TypeLib\{EB2BEAEF-150C-4DE4-9D09-F16403C22769}\1.0] ==== Deleting Files \ Folders ====================== "C:\Windows\Installer\{B6DCCCD3-520D-4485-B642-FCC136CE12C3}\amazonIcon.exe" deleted "C:\Program Files (x86)\Amazon\Amazon1ButtonApp\Amazon1ButtonService64.Exe" deleted "C:\Program Files (x86)\Amazon" not deleted "C:\Program Files (x86)\Amazon\Amazon1ButtonApp" not deleted ==== C:\zoek_backup content ====================== C:\zoek_backup (files=2119 folders=224 402407569 bytes) ==== After Reboot ====================== ==== Deleting Files / Folders ====================== "C:\Program Files (x86)\Amazon" not found ==== EOF on do 05-05-2016 at 12:38:24,15 ======================