Posted on 2012-08-15
I CANNOT for the life of me remove this infection from the hard drive! The customer brought it in. It runs Windows XP, or it is supposed to anyways. You boot up the computer and when it goes to boot to the hard drive, all you get is a blinking cursor. I've seen this before, so I removed the hard drive and through it into a slave computer. I have ran Avast! on the hard drive and found 2 generic infections. I have externally scanned it with Malwarebytes, which found nothing (kind of surprised about that!). I ran TDSSKiller, and it does find a rootkit. Rootkit.Boot.Pihar.c on the slaved hard drive. I tell it to Cure, it says it has to write a standard boot code, I say Yes, then it reboots the computer.
Problem is, I scan it again after the computer has rebooted, and it is STILL there! I've tried to 'Cure' it 5 times now! Any suggestions?