I have marked this as I don't need a solution... At least I don't think I need a solution.
I am hopeful I have fixed this, but I found no assistance on Norton forums, so wanted to at least document this. One of my customers had a virus on her computer even though we have Norton 360 operating and up to date. It was starting a process lvfvcwdzbrbc.exe and she says playing music of some kind... I did not hear it as I was running remote... After trying several Norton scans and Power Eraser (which fails with error code 0x80004005) I finally removed what I could find by hand and we are crossing our fingers that I got it all.
I found a start-up process marked as a Microsoft Operating System... forgot to write down the name, but it was just a jumble of letters. I found that process in the registry and removed it. I then deleted the user wangjihua and under users/<user name>/AppData/LocalLow/Microsoft/Nulsswdprg.
could only delete those files after disabling the start-up and restarting and actually, Users/<user name> was hidden... I had to use the attrib command -h -s to make that visible again. It also has disabled system restore. I still have to figure out how to repair that, but customer is back operating.
Found some help on bleepingcomputer identifying this as wangzhisong virus in December of 2013. Maybe someone from Norton could look into this?
AR