That showed only one key, in search assistant, which shouldn’t be a problem.

Let’s treat this as if you where still infected and start at the beginning. I found what may be a sample of the test.reg so it will give us a starting point.

Open task manager and check to see if this is running, if it is use end task to stop it.

WScript.exe

Open windows explorer

At the top of windows explorer, click tools, folder options, click the
view tab

check Show hidden files and folders
uncheck “Hide extensions for known file types” box
uncheck “Hide protecting operating system files” box

Click apply.

Close the box, wait about a half a minute and reopen it to make sure the settings remained as you set them.

Plug in your flash drive

Please download
OTMoveIt2 by OldTimer.

Save it to your desktop.

Please double-click OTMoveIt2.exe to run it.

Copy the file paths below to the clipboard by highlighting ALL of them and pressing CTRL + C (or, after highlighting, right-click and choose Copy):


c:\autorun.*
D:\autorun.*
F:\autorun.*
c:\windows\test.* /s
c:\windows\autorun.* /s
D:\test.*
F:\test.*
D:\autorun.* /s

Return to OTMoveIt2, right click in the “Paste List Of Files/Patterns To Search For and Move” window (under the yellow bar) and choose Paste.

Click the red Moveit! button.

Copy everything in the Results window (under the green bar) to the clipboard by highlighting ALL of them and pressing CTRL + C (or, after highlighting, right-click and choose copy), and paste it in your next reply.

Close OTMoveIt2

If a file or folder cannot be moved immediately you may be asked to reboot the machine to finish the move process. If you are asked to reboot the machine choose Yes.

NOTE: If OTMOVEITE reboots, before you can get the ruslts they can be found here
C:_OTMoveIt\MovedFiles**_.log
(where “**_” is the “date_time”)