My wife's computer has been infected with this virus. Her computer began slowing down dramatically starting a week ago. Looking at Task Manager, we found the culprit was using a lot of her memory. After "Ending Process" the memory use of Windows Explorer as recorded in Task Manager began to increase rapidly. I have done the scan with aswMBR and Farbar as instructed, and attach the logs here:
aswMBR version 1.0.1.2252 Copyright© 2014 AVAST Software
Run date: 2015-08-21 09:17:59
—————————–
09:17:59.949 OS Version: Windows x64 6.1.7601 Service Pack 1
09:17:59.949 Number of processors: 2 586 0x3A09
09:17:59.951 ComputerName: SILJA-PC UserName: Silja
09:22:00.518 Initialize success
09:22:11.406 VM: initialized successfully
09:22:11.406 VM: Intel CPU supported
09:22:28.172 VM: disk I/O iaStorA.sys
09:22:40.833 Disk 0 (boot) \Device\Harddisk0\DR0 -> \Device\000000c4
09:22:40.911 Disk 0 Vendor: ATA_____ 3M__ Size: 476940MB BusType: 11
09:22:42.533 Disk 0 MBR read successfully
09:22:42.533 Disk 0 MBR scan
09:22:42.533 Disk 0 Windows VISTA default MBR code
09:22:42.611 Disk 0 Partition 1 80 (A) 27 Hidden NTFS WinRE NTFS 1500 MB offset 2048
09:22:42.705 Disk 0 default boot code
09:22:42.798 Disk 0 Partition 2 00 07 HPFS/NTFS NTFS 464823 MB offset 3074048
09:22:42.892 Disk 0 Partition 3 00 17 Hidd HPFS/NTFS NTFS 10616 MB offset 955031552
09:22:44.062 Disk 0 scanning C:\windows\system32\drivers
09:23:20.531 Service scanning
09:23:28.830 Service BHDrvx64 C:\ProgramData\Norton\{0C55C096-0F1D-4F28-AAA2-85EF591126E7}\NIS_20.3.0.36\Definitions\BASHDefs\20140110.001\BHDrvx64.sys **LOCKED** 5
09:23:31.155 Service ccSet_NIS C:\windows\system32\drivers\NISx64\1406000.01B\ccSetx64.sys **LOCKED** 5
09:23:39.483 Service eeCtrl C:\Program Files (x86)\Common Files\Symantec Shared\EENGINE\eeCtrl64.sys **LOCKED** 5
09:23:40.200 Service EraserUtilRebootDrv C:\Program Files (x86)\Common Files\Symantec Shared\EENGINE\EraserUtilRebootDrv.sys **LOCKED** 5
09:23:46.235 Service IDSVia64 C:\ProgramData\Norton\{0C55C096-0F1D-4F28-AAA2-85EF591126E7}\NIS_20.3.0.36\Definitions\IPSDefs\20150512.001\IDSvia64.sys **LOCKED** 5
09:24:04.424 Service NAVENG C:\ProgramData\Norton\{0C55C096-0F1D-4F28-AAA2-85EF591126E7}\NIS_20.3.0.36\Definitions\VirusDefs\20140115.032\ENG64.SYS **LOCKED** 5
09:24:05.298 Service NAVEX15 C:\ProgramData\Norton\{0C55C096-0F1D-4F28-AAA2-85EF591126E7}\NIS_20.3.0.36\Definitions\VirusDefs\20140115.032\EX64.SYS **LOCKED** 5
09:24:46.297 Service SRTSPX C:\windows\system32\drivers\NISx64\1406000.01B\SRTSPX64.SYS **LOCKED** 5
09:24:48.652 Service SymDS C:\windows\system32\drivers\NISx64\1406000.01B\SYMDS64.SYS **LOCKED** 5
09:24:49.385 Service SymEvent C:\windows\system32\Drivers\SYMEVENT64x86.SYS **LOCKED** 5
09:24:49.666 Service SymIRON C:\windows\system32\drivers\NISx64\1406000.01B\Ironx64.SYS **LOCKED** 5
09:24:49.822 Service SymNetS C:\windows\System32\Drivers\NISx64\1406000.01B\SYMNETS.SYS **LOCKED** 5
09:25:01.257 Modules scanning
09:25:01.304 Disk 0 trace - called modules:
09:25:01.319 ntoskrnl.exe CLASSPNP.SYS disk.sys iaStorF.sys storport.sys hal.dll iaStorA.sys
09:25:01.335 1 nt!IofCallDriver -> \Device\Harddisk0\DR0[0xfffffa8006557060]
09:25:01.335 3 CLASSPNP.SYS[fffff88001cf243f] -> nt!IofCallDriver -> [0xfffffa8006556aa0]
09:25:01.335 5 iaStorF.sys[fffff880019f0a2c] -> nt!IofCallDriver -> \Device\000000c4[0xfffffa80060189c0]
09:25:01.351 Disk 0 statistics 110202/0/0 @ 1.59 MB/s
09:25:01.351 Scan finished successfully
09:27:04.289 Disk 0 MBR has been saved successfully to "C:\Users\Silja\Desktop\MBR.dat"
09:27:04.289 The log file has been saved successfully to "C:\Users\Silja\Desktop\aswMBR.txt"
FARBAR
Addition.txt available at pastebin.com/EKm4Sg1d
FRST.txt:
Scan result of Farbar Recovery Scan Tool (FRST) (x64) Version:14-08-2015 01
Ran by [removed] (administrator) on SILJA-PC (17-08-2015 05:14:07)
Running from C:\Users\[removed]\Desktop
[removed]