G
Guest
A customer brought a system into the shop for malware removal. After cleaning
it up, which included removing a rootkit (at least the portions I could
find), it ran pretty well, except for a few problems that would appear to
have a common root cause. The machine is xp home sp2.
1) sometimes, when going into the Printers & Faxes folder, or Control Panel,
the contents of the right-hand pane do not display. There is no flashlight
icon visible in the right-hand pane when this happens, and if you close out
and go back in, then it works.
2) when opening My Computer, nothing displays in the right-hand pane, no
matter how many times you go into My Computer.
3) opening Windows Explorer reveals only a My Computer folder icon in the
left-hand tree pane (no C: or CD drives) and nothing in the right hand pane.
However, you can go to the address bar and see C: and the CD drives in the
pull-down list, and you can then navigate throughout the computer, and the
contents then show in the right-hand pane.
I took a look at http://support.microsoft.com/?kbid=309663 but this doesn't
really fit, as Help and System Restore display normallly. I also tried
XP_CD-DVD-Fix.zip even though none of the drives are visible, and this did
not fix the problem.
It acts as though the drives are hidden through some sort of group policy
setting, even though this is a home machine that has never been on a
domain/server network. I suspect that the root kit based malware might have
been responsible for this, so I suspect that I will have to manually fix it
through the registry. Can anyone point me to the registry hack that affects
this?
it up, which included removing a rootkit (at least the portions I could
find), it ran pretty well, except for a few problems that would appear to
have a common root cause. The machine is xp home sp2.
1) sometimes, when going into the Printers & Faxes folder, or Control Panel,
the contents of the right-hand pane do not display. There is no flashlight
icon visible in the right-hand pane when this happens, and if you close out
and go back in, then it works.
2) when opening My Computer, nothing displays in the right-hand pane, no
matter how many times you go into My Computer.
3) opening Windows Explorer reveals only a My Computer folder icon in the
left-hand tree pane (no C: or CD drives) and nothing in the right hand pane.
However, you can go to the address bar and see C: and the CD drives in the
pull-down list, and you can then navigate throughout the computer, and the
contents then show in the right-hand pane.
I took a look at http://support.microsoft.com/?kbid=309663 but this doesn't
really fit, as Help and System Restore display normallly. I also tried
XP_CD-DVD-Fix.zip even though none of the drives are visible, and this did
not fix the problem.
It acts as though the drives are hidden through some sort of group policy
setting, even though this is a home machine that has never been on a
domain/server network. I suspect that the root kit based malware might have
been responsible for this, so I suspect that I will have to manually fix it
through the registry. Can anyone point me to the registry hack that affects
this?