Home Malware Programs Spyware NT Logon Capture

NT Logon Capture

Posted: March 28, 2006

NT Logon Capture is a specific malware threat that automatically runs on every Windows startup and records computer logon user names and passwords. Gathered information is logged to a file. NT Logon Capture must be manually installed.

File System Modifications

  • The following files were created in the system:
    # File Name
    1 ntlc.exe
    2 ssntlc.dll

Registry Modifications

  • The following newly produced Registry Values are:
    HKEY..\..\..\..{RegistryKeys}tlc.exe
Loading...