winrscmde Trojan and cimiu.exe?

Yesterday, as my husband was using the computer, it shut off and he said he encountered some message saying "Illegal shutdown" right before it turned off. He couldnt boot back on to the computer. After some fighting, I got on to the computer but nothing was functioning. None of the software I had on the computer would work and i eventually ran a computer restore on it.

 

I got the computer to a decent place to where it was fairly usable but starting this morning I started getting a blue screen with an error message and something about it "collecting data for crash dump", with a number of other sentences on it, but the screen moved too quickly for me to see. Right after the blue screen appeared, the computer would reboot, and start up again. Then a few minutes after I signed on to Windows 7, it would blue screen and reboot. This cycled for a while until I used the time in-between each blue screen/reboot to download xfinity's Constant Guard software and then got Norton Security.

 

Norton then found cimiu.exe as a high risk and asked me to restart the computer in order to remove it, just as i clicked the restart button, the computer crashed with a blue screen. I assumed that Norton removed it since I havent seen the message appear once again, but I'm not completely sure because I am unable to run a scan with Norton since I am not able to actually get the software to start. Whenever I click on the icon for Norton, nothing happens.

 

Ever since the last reboot, I havent got a blue screen or another reboot, I'm hoping this is a good thing. Recently though, (about 20-30 minutes ago), Norton displayed a small box with a message about "winrscmde creating high performance" (or something to that affect). After some research, I learned that this is a trojan and I want this thing off immediately.

 

The only problem I'm having now is how to remove it, I dont even know where I could access this file and I would appreciate if I could get some instructions on how to get this removed.