Want to protect your cyber security and still get fast solutions? Ask a secure question today.Go Premium

x
  • Status: Solved
  • Priority: Medium
  • Security: Public
  • Views: 2765
  • Last Modified:

pwdmon.dll

I found this dll in the system32 folder: pwdmon.dll.  It also has an entry in the Notification Packages key of  HKLM\SYSTEM\CurrentControlSet\Control\Lsa .  I can't find any information on this dll.  Can anyone shed some light on its purpose and where it comes from?
0
dhenderson12
Asked:
dhenderson12
1 Solution
 
LanBuddhaCommented:
That is a registry key for windows security.

I am not sure what the file does but if you right click on the file and look at the properties you should be able to find out the manufacturer if it is legit. Some information about it should be found in the properties.
0
 
dhenderson12Author Commented:
Thanks for the reply.  There are NO values listed in the properties of this file ... none.
0
 
LanBuddhaCommented:
Look at the creation date. Did you install anything on that date? I would be very suspicious of the file. Maybe save your registry and then remove the key and see what happens. What other processes are running? Or just try renaming the file and see if a program complains. Do you have anything like a finger print reader on your computer?

Search Google for Rootkit analyzer and see if that DLL is hooking your keyboard or something..
0
Managing Security Policy in a Changing Environment

The enterprise network environment is evolving rapidly as companies extend their physical data centers to embrace cloud computing and software-defined networking. This new reality means that the challenge of managing the security policy is much more dynamic and complex.

 
score_underCommented:
You could assume that it is spyware or adware, or possibly a component for some obscure program, because I have a virus-free laptop and the file does not exist on it. I am running xp(pro)sp2.
0
 
kneHCommented:
What I usually do with files like these is the following:
- Create a backupcopy of the file and place it somewhere easy to acces from the command line (eg the c:\ root)
- Then rename the file in the system32 dir. Will it allow it? If not it is in use.
- if you cannot rename the file.. boot into safemode and try then
- if you can rename it that's cool. Now delete it. Does windows put it back?
- if so it might be a system file.
- after you've renamed it test your system for a while. Does it give any errors anywhere?

hope that'll help somewhat.


0
 
TolomirAdministratorCommented:
I've found this: http://www.brightstrand.com/simple.html

It uses a pwdmon program.

Tolomir
0
 
Computer101Commented:
PAQed with no points refunded (of 125)

Computer101
EE Admin
0

Featured Post

The Firewall Audit Checklist

Preparing for a firewall audit today is almost impossible.
AlgoSec, together with some of the largest global organizations and auditors, has created a checklist to follow when preparing for your firewall audit. Simplify risk mitigation while staying compliant all of the time!

Tackle projects and never again get stuck behind a technical roadblock.
Join Now