Registry | Load Hive Disabled in REGEDT32

  • Thread starter Thread starter Will
  • Start date Start date
W

Will

Can someone explain to me how is it possible that in HKLM on a Windows 2000
computer the "Load Hive" menu option is disabled? I'm logged in as local
administrator. The box in question has been hacked, so it would not
surprise me if the virus had reset a registry entry. Is there something I
can do to force the Load Hive to become available?
 
This article may help.

How to Restore the Default NTFS Permissions for Windows 2000
http://support.microsoft.com/?id=266118


Failing that these might help.

How to Perform an In-Place Upgrade of Windows 2000
http://support.microsoft.com/default.aspx?scid=kb;[LN];292175

What an In-Place Windows 2000 Upgrade Changes and What It Does Not Change
http://support.microsoft.com/default.aspx?scid=kb;[LN];306952

Be sure to apply SP4 and these two below to your repair install before
connecting to any network. Internet included. (sasser, msblast)
http://download.microsoft.com/download/E/6/A/E6A04295-D2A8-40D0-A0C5-241BFECD095E/W2KSP4_EN.EXE
http://www.microsoft.com/technet/security/bulletin/MS03-043.mspx
http://www.microsoft.com/technet/security/bulletin/MS03-049.mspx

Then

Rollup 1 for Microsoft Windows 2000 Service Pack 4
http://www.microsoft.com/downloads/...CF-8850-4531-B52B-BF28B324C662&displaylang=en

--

Regards,

Dave Patrick ....Please no email replies - reply in newsgroup.
Microsoft Certified Professional
Microsoft MVP [Windows]
http://www.microsoft.com/protect

:
| Can someone explain to me how is it possible that in HKLM on a Windows
2000
| computer the "Load Hive" menu option is disabled? I'm logged in as local
| administrator. The box in question has been hacked, so it would not
| surprise me if the virus had reset a registry entry. Is there something
I
| can do to force the Load Hive to become available?
|
| --
| Will
|
|
 
What would default NTFS permissions have to do with the default behavior of
a menu item on REGEDT32?
 
Dunno but given the unknown damage this is where I'd start and work your way
down.

--

Regards,

Dave Patrick ....Please no email replies - reply in newsgroup.
Microsoft Certified Professional
Microsoft MVP [Windows]
http://www.microsoft.com/protect

:
| What would default NTFS permissions have to do with the default behavior
of
| a menu item on REGEDT32?
|
| --
| Will
 
Dave Patrick said:
Dunno but given the unknown damage this is where I'd start and work your way
down.

Well, I appreciate the advice on file system permissions in any case. I
don't think that addresses the question on what causes Load Hive to not
show. As a pure guess, I would imagine Load Hive is looking at some
registry entry or looking for write access to some registry in order to
enable Load Hive.
 
Will said:
Well, I appreciate the advice on file system permissions in any case. I
don't think that addresses the question on what causes Load Hive to not
show. As a pure guess, I would imagine Load Hive is looking at some
registry entry or looking for write access to some registry in order to
enable Load Hive.

It's a permissions issue.

John
 
Read the summary again. This isn't just file system perms.

--

Regards,

Dave Patrick ....Please no email replies - reply in newsgroup.
Microsoft Certified Professional
Microsoft MVP [Windows]
http://www.microsoft.com/protect

:
| Well, I appreciate the advice on file system permissions in any case. I
| don't think that addresses the question on what causes Load Hive to not
| show. As a pure guess, I would imagine Load Hive is looking at some
| registry entry or looking for write access to some registry in order to
| enable Load Hive.
|
| --
| Will
|
|
 
In said:
Can someone explain to me how is it possible that in HKLM on a
Windows 2000 computer the "Load Hive" menu option is disabled?

Just to eliminate the possibily have you placed the focus on the
"root" of HKLM at the time?
 
Mark V said:
Just to eliminate the possibily have you placed the focus on the
"root" of HKLM at the time?

It's always good to confirm assumptions. Yes, I had two Windows 2000
machines side by side, and when selecting the root of HKLM on the machine
that was hacked Load Hive doesn't enable. When selection the root of HKLM
on the machine that was not hacked Load Hive does enable (as it should).
 
Back
Top