Threat Database Potentially Unwanted Programs PUP.LightLogger Keylogger for Parents

PUP.LightLogger Keylogger for Parents

Threat Scorecard

Popularity Rank: 4,399
Threat Level: 10 % (Normal)
Infected Computers: 1,549
First Seen: August 22, 2020
Last Seen: February 6, 2026
OS(es) Affected: Windows

SpyHunter Detects & Remove PUP.LightLogger Keylogger for Parents

File System Details

PUP.LightLogger Keylogger for Parents may create the following file(s):
# File Name MD5 Detections
1. lmonitor.exe 32afc09e040ebe58bf3591aefeaee98d 733
2. lightlog.exe 8c595675a085d143207b92daacf4e226 317
3. f_00018d c705383852dc4da7f4e4175ecc87789a 12
4. 2334445ee2b6b53b1be2908b97d8a9a9555302661ffefd26cbefbe759fdea87b.exe f28f3f995dc8b31fb7ccb67d10c26623 6
5. ladmin.exe 0f3462f2e1670366a29f4c8e4b19d430 6
More files

Analysis Report

General information

Family Name: PUP.LightLogger Keylogger for Parents
Signature status: No Signature

Known Samples

MD5: 07c909ba64c3cc8655c20b602fb08063
SHA1: 44850bd5b6ff299e91d88837e0399cdec525345d
SHA256: A8A753E172120DD02F9B6EF08189053046C52F264F4C94A99110377D7EC4DE77
File Size: 2.12 MB, 2117632 bytes

Windows Portable Executable Attributes

  • File doesn't have "Rich" header
  • File doesn't have exports table
  • File doesn't have relocations information
  • File doesn't have security information
  • File is 64-bit executable
  • File is either console or GUI application
  • File is GUI application (IMAGE_SUBSYSTEM_WINDOWS_GUI)
  • File is Native application (NOT .NET application)
  • File is not packed
  • IMAGE_FILE_DLL is not set inside PE header (Executable)
Show More
  • IMAGE_FILE_EXECUTABLE_IMAGE is set inside PE header (Executable Image)

Windows PE Version Information

Name Value
Company Name HeavenWard
File Description LightLogger Monitor
File Version 6,20,5,1
Internal Name lmonitor
Legal Copyright (C) 2020, HeavenWard
Original Filename lmonitor.exe
Product Name LightLogger
Product Version 6,20,5,1

File Traits

  • x64

Block Information

Total Blocks: 10,222
Potentially Malicious Blocks: 13
Whitelisted Blocks: 8,769
Unknown Blocks: 1,440

Visual Map

0 ? 0 0 0 0 0 0 0 0 ? 0 ? ? 0 ? 0 0 ? 0 ? ? ? 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 ? 0 0 0 0 0 0 0 0 0 0 ? 0 ? 0 0 0 0 0 0 0 0 0 ? 0 0 0 0 0 0 0 ? 0 0 0 0 0 0 0 0 0 0 ? 0 ? 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 ? ? 0 0 0 ? 0 0 ? ? 0 0 ? 0 0 ? ? 0 ? 0 ? 0 ? 0 ? 0 0 ? 0 0 ? 0 0 ? 0 0 ? 0 0 0 ? 0 0 0 0 0 ? 0 0 0 0 ? ? 0 0 ? 0 0 0 0 ? ? 0 0 0 ? ? 0 0 ? 0 0 0 0 0 0 0 0 0 0 0 0 0 ? 0 0 0 0 0 ? 0 0 ? ? 0 0 0 0 0 0 0 ? 0 0 0 0 ? 0 0 0 ? ? 0 ? 0 0 0 0 0 0 0 0 0 0 ? 0 0 0 ? 0 0 0 ? 0 0 0 ? 0 0 0 ? 0 0 0 ? 0 0 0 ? 0 0 0 ? 0 0 0 ? 0 0 0 ? 0 0 0 0 0 0 0 ? 0 0 0 0 0 0 0 0 ? 0 0 0 0 0 ? ? 0 ? 0 ? ? 0 0 0 ? 0 0 0 0 0 0 0 ? 0 0 0 0 ? 0 0 0 0 0 ? 0 0 0 0 0 ? 0 0 0 0 0 ? 0 0 0 0 0 ? 0 0 0 0 0 0 0 0 0 ? 0 0 0 0 0 0 0 0 0 0 0 ? ? 0 ? 0 0 0 0 0 0 0 0 0 0 0 0 ? 0 0 0 0 0 ? 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 ? 0 0 0 0 0 0 0 0 ? 0 0 0 0 0 0 0 0 0 ? ? ? 0 0 0 ? 0 0 0 ? 0 0 0 0 0 0 0 0 0 0 ? 0 ? 0 ? 0 0 ? 0 0 0 0 ? 0 ? 0 0 ? 0 0 0 0 0 0 0 0 ? 0 ? 0 0 0 0 0 0 0 0 0 0 0 0 0 ? 0 0 ? 0 ? x ? 0 0 ? 0 0 0 0 0 ? ? 0 0 x 0 0 ? 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 ? ? 0 0 0 0 0 0 0 0 0 ? 0 0 ? 0 0 0 0 0 0 0 0 0 0 0 0 x ? 0 0 0 ? ? 0 0 0 0 0 0 0 0 0 ? 0 ? 0 0 0 0 0 ? 0 0 0 0 0 0 0 0 0 ? ? 0 0 0 0 0 0 0 0 0 0 ? 0 0 0 0 0 0 ? 0 0 0 0 0 ? 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 ? 0 ? 0 0 0 0 ? 0 ? 0 0 0 0 0 0 0 0 0 ? ? 0 0 0 0 x 0 0 0 0 0 0 0 0 0 ? 0 0 ? 0 0 0 ? 0 0 0 ? 0 0 ? 0 ? 0 0 0 0 0 ? 0 0 0 0 0 ? 0 0 0 0 0 ? 0 0 0 0 ? 0 0 0 ? ? 0 0 0 0 0 0 0 0 0 0 0 0 0 0 ? 0 0 0 0 0 0 0 0 0 ? 0 0 0 0 0 x ? 0 0 0 0 0 0 ? 0 0 0 0 0 ? ? ? 0 0 0 0 x 0 0 0 0 0 0 0 0 0 x 0 ? 0 0 ? ? 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 x 0 ? ? 0 ? 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 ? 0 0 0 0 0 0 0 0 0 0 ? 0 0 0 0 0 0 0 0 0 0 0 0 0 ? 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 ? 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 ? 0 0 0 0 0 0 ? 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 ? 0 0 0 ? 0 0 0 0 0 0 ? 0 0 ? 0 0 ? 0 0 0 0 ? ? 0 0 0 0 0 0 0 ? 0 ? 0 0 0 0 0 0 0 0 0 0 ? 0 0 0 0 ? 0 0 0 0 0 0 ? 0 0 0 0 0 0 ? 0 0 0 0 0 0 0 0 0 0 0 0 ? 0 0 0 ? ? ? ? 0 ? 0 0 ? 0 ? ? ? ? 0 0 ? 0 0 ? 0 0 ? 0 ? ? 0 0 0 0 0 0 0 0 0 ? 0 0 0 0 0 0 ? 0 0 0 0 0 0 0 ? 0 0 0 0 0 ? ? ? ? 0 ? 0 0 0 0 0 ? 0 0 0 0 0 0 0 0 ? 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 ? ? 0 0 0 0 0 ? 0 ? 0 ? 0 0 ? ? 0 ? 0 ? ? ? 0 0 ? ? ? 0 0 ? ? 0 0 ? 0 ? 0 0 ? 0 0 0 0 0 0 0 0 0 ? 0 ? 0 0 0 0 ? 0 0 0 ? 0 ? 0 0 0 ? ? 0 0 0 0 0 0 0 0 ? ? 0 0 ? ? ? 0 0 ? 0 0 0 0 0 ? 0 0 ? 0 0 ? 0 0 0 0 0 0 0 0 ? 0 0 0 ? 0 ? 0 0 x ? ? ? 0 ? 0 0 0 ? 0 ? 0 x 0 0 ? ? 0 0 0 ? 0 0 ? ? ? ? 0 ? ? 0 ? ? 0 0 0 0 x 1 0 0 ? ? 0 0 ? 0 0 ? ? ? 0 ? ? ? ? ? 0 0 0 ? 0 0 0 ? 0 ? ? 0 1 ? 0 0 ? 0 0 0 0 0 ? 0 0 ? 0 0 0 0 0 0 0 0 0 0 0 0 0 0 ? 0 0 ? 0 0 ? 0 0 ? 0 ? ? 0 ? 0 0 0 0 0 0 ? 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 ? 0 ? 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 ? 0 ? 0 0 0 0 0 0 0 0 0 0 0 ? 0 0 ? 0 0 0 0 0 0 0 0 ? 0 ? 0 0 ? 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 ? 0 ? 0 ? 0 0 ? 0 0 ? 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 ? 0 0 0 0 0 ? 0 0 ? 0 0 0 ? 0 ? 0 ? 0 ? 0 0 ? 0 ? 0 ? 0 ? 0 ? 0 0 ? ? 0 0 ? 0 0 0 ? 0 0 0 0 0 0 ? 0 ? 0 0 ? 0 0 ? 0 0 0 0 0 0 ? 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 ? 0 0 0 0 0 ? ? 0 0 0 0 0 0 0 0 ? 0 0 0 0 0 ? 0 ? 0 ? 0 0 0 0 ? 0 ? 0 ? 0 0 0 0 ? ? ? 0 0 0 0 0 0 ? 0 ? ? 0 0 ? 0 0 0 ? 0 0 ? 0 0 0 0 0 ? 0 0 0 ? 0 0 0 ? 0 0 0 ? 0 0 0 0 0 0 0 0 0 1 0 0 ? 0 0 0 0 0 0 ? 0 0 0 0 0 ? 0 0 0 0 ? 0 0 0 1 ? ? 0 0 0 ? 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 ? ? 0 0 ? ? ? 0 ? ? 0 1 0 0 0 0 0 0 0 0 0 0 0 0 0 ? ? 0 0 0 0 0 0 0 0 0 0 1 0 0 0 0 ? 0 ? ? ? 0 ? 0 ? 0 ? 0 0 0 ? 0 ? 0 0 ? 0 0 0 0 0 0 ? 0 0 0 0 ? 0 0 0 ? 0 0 0 0 ? 0 0 ? ? 0 0 0 ? 0 0 0 0 ? 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 ? 0 ? 0 0 0 ? 0 0 0 0 0 0 0 0 0 0 0 ? 0 0 0 0 0 0 0 0 0 0 0 0 0 ? 0 ? 0 ? 0 ? 0 0 0 0 0 0 0 0 0 0 ? 0 0 0 ? ? 0 0 0 0 0 ? 0 0 0 0 0 0 0 0 0 ? 0 0 0 0 0 0 ? 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 ? 0 0 0 0 0 0 0 0 0 0 ? ? ? ? ? ? 0 ? 0 ? 0 0 ? 0 0 0 0 0 0 0 0 0 0 ? 0 ? 0 ? 0 0 0 0 0 0 0 0 0 0 0 ? 0 0 0 0 0 0 0 0 0 0 ? 0 0 0 0 0 ? 0 0 0 0 ? 0 0 0 0 0 ? 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 ? 0 0 0 0 0 ? 0 0 0 0 ? 0 0 0 0 ? ? 0 0 0 0 0 0 0 0 0 0 ? ? 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 ? 0 0 0 0 0 0 0 0 0 0 0 0 0 0 ? 0 0 ? 0 ? 0 0 ? 0 ? 0 0
... Data truncated
0 - Probable Safe Block
? - Unknown Block
x - Potentially Malicious Block

Files Modified

File Attributes
c:\programdata\heavenward\lightlogger\logs\44850bd5b6ff299e91d88837e0399cdec525345d_0002117632.log Generic Write,Read Attributes

Windows API Usage

Category API
Syscall Use
  • ntdll.dll!NtAlpcConnectPortEx
  • ntdll.dll!NtAlpcQueryInformation
  • ntdll.dll!NtAlpcSendWaitReceivePort
  • ntdll.dll!NtApphelpCacheControl
  • ntdll.dll!NtAssociateWaitCompletionPacket
  • ntdll.dll!NtClose
  • ntdll.dll!NtCreateEvent
  • ntdll.dll!NtCreateFile
  • ntdll.dll!NtCreateIoCompletion
  • ntdll.dll!NtCreateSection
Show More
  • ntdll.dll!NtCreateSemaphore
  • ntdll.dll!NtCreateTimer2
  • ntdll.dll!NtCreateWaitCompletionPacket
  • ntdll.dll!NtCreateWorkerFactory
  • ntdll.dll!NtDuplicateObject
  • ntdll.dll!NtFreeVirtualMemory
  • ntdll.dll!NtMapViewOfSection
  • ntdll.dll!NtOpenDirectoryObject
  • ntdll.dll!NtOpenFile
  • ntdll.dll!NtOpenKey
  • ntdll.dll!NtOpenKeyEx
  • ntdll.dll!NtOpenProcessToken
  • ntdll.dll!NtOpenSection
  • ntdll.dll!NtOpenThreadToken
  • ntdll.dll!NtProtectVirtualMemory
  • ntdll.dll!NtQueryAttributesFile
  • ntdll.dll!NtQueryInformationFile
  • ntdll.dll!NtQueryInformationProcess
  • ntdll.dll!NtQueryInformationThread
  • ntdll.dll!NtQueryInformationToken
  • ntdll.dll!NtQueryKey
  • ntdll.dll!NtQueryPerformanceCounter
  • ntdll.dll!NtQuerySecurityAttributesToken
  • ntdll.dll!NtQuerySecurityObject
  • ntdll.dll!NtQuerySystemInformation
  • ntdll.dll!NtQuerySystemInformationEx
  • ntdll.dll!NtQueryValueKey
  • ntdll.dll!NtQueryVirtualMemory
  • ntdll.dll!NtQueryWnfStateData
  • ntdll.dll!NtReadFile
  • ntdll.dll!NtReleaseWorkerFactoryWorker
  • ntdll.dll!NtSetEvent
  • ntdll.dll!NtSetInformationFile
  • ntdll.dll!NtSetInformationProcess
  • ntdll.dll!NtSetInformationThread
  • ntdll.dll!NtSetInformationVirtualMemory
  • ntdll.dll!NtSetInformationWorkerFactory
  • ntdll.dll!NtSetTimer2
  • ntdll.dll!NtTerminateProcess
  • ntdll.dll!NtTestAlert
  • ntdll.dll!NtTraceControl
  • ntdll.dll!NtUnmapViewOfSectionEx
  • ntdll.dll!NtWaitForSingleObject
  • ntdll.dll!NtWaitForWorkViaWorkerFactory
  • ntdll.dll!NtWriteFile
  • ntdll.dll!NtWriteVirtualMemory
  • win32u.dll!NtUserGetClassInfoEx
  • win32u.dll!NtUserGetKeyboardLayout
  • win32u.dll!NtUserGetThreadState
  • win32u.dll!NtUserKillTimer
  • win32u.dll!NtUserPostMessage
  • win32u.dll!NtUserSetTimer
  • win32u.dll!NtUserUnregisterClass
User Data Access
  • GetComputerNameEx
  • GetUserName

Trending

Most Viewed

Loading...