Unknown password filter installed

Risk Level: High risk vulnerability  High

Check or Attack Name: Unknown Pwd Filter

Platforms: Windows NT
Description:

An unknown password filter was found registered in the HKEY_LOCAL_MACHINE\System\CurrentControlSet\Control\Lsa registry key. If this password filter is not part of your normal security policy, it may represent evidence that the host (and possibly other machines that it trusts) has been compromised.

Remedy:

Verify that the password filter detected is part of your site security, and was not installed by an attacker.

—OR—

If the password filter is unauthorized, consider your system as compromised:

  1. Immediately remove the computer from the network.
  2. Create a backup of the contents of the hard drive, or isolate the data on a non-networked storage device.
  3. Perform a low-level format of all hard drives on the computer.
  4. Reinstall the operating system.
  5. Configure the computer with the original user names, groups, and applications.
  6. Run Internet Scanner to determine vulnerabilities, and resolve detected vulnerabilities.
  7. Before using the files on the backup, scan all files using an up-to-date antivirus program, and copy only the files you know to be authorized on that computer.
  8. Reconnect the computer to the network.
References:

X-Force Logo
Know Your Risks