Well, your log is not correct, because the tool is launched under terminal session .
Repeat log under local user with administrator rights and attach it to your next post.
Some files looks suspicious to me. Do you know what is this:
C:\WINDOWS\system32\ALSNDMGR.CPL
C:\1c889\1Click.exe
We would like to see a copy of them.
you can use this script for copying them:
Код:
begin
QuarantineFile('C:\WINDOWS\system32\ALSNDMGR.CPL','');
QuarantineFile('C:\1c889\1Click.exe','');
end.
make shure that quarantine is a zip file the with password virus and upload it by
http://virusinfo.info/upload_virus_eng.php?tid=37555