02-26-2013 09:23 PM
I have been seeing this message "Winrscmde- High CPU Usage Performance Alert" from Norton Internet Security 2012 for months now. And my PC doesn't return to regular Windows after putting it to sleep (not sure if it is related or some hard drive problem). First, I asked my husband for help but he insisted there was nothing wrong, so I had to take the matter on my own. After I did some research online, I am suspecting that my PC is infected. I saw there are some similar postings here, so I am hoping someone can really help me. I have a Dell Inspiron 560 that was purchased 2 years ago and it is 64 bit. I thank you in advance for help as my life really depends on using a safe computer.
I downloaded the frst64.exe file as it was recommended on other posting, and I am attaching FRST.txt.
02-26-2013 09:54 PM
And use someone like myself who knows what is going on and trained in tools to deal with this, If done wrong Windows may not startup.
02-26-2013 10:18 PM
Can you at least tell me what virus/malware on my PC? I am short on time as well. Someone suggested that I clean all the hard drives and re-install everything, please tell me if that will work in getting rid of the virus.
02-26-2013 10:20 PM
As Quads said, go to the site he suggested. Malware removal advice is not being given here, at the moment.
02-26-2013 10:29 PM
People like myself on the exact board I posted above can remove it for you just follow the instructions exactly, do what is asked, do not do what is NOT asked.
It is looks like the x64 variant of Pihar so involves the BCD and its own file system etc.
02-26-2013 11:58 PM
You can tell them this needs to be fixed
ATTENTION: ========> Check for possible partition/boot infection:
TDL4: custom:26000022 <===== ATTENTION!
9 Drive k: (RECOVERY) (Fixed) (Total:12.03 GB) (Free:5.38 GB) NTFS ==>[System with boot components (obtained from reading drive)]
ATTENTION: Malware custom entry on BCD on drive k: detected. Check for MBR/Partition infection.
From Norton Forums FRST log, malware not being removed here