Post coming in InfoWorld
[See the full post at: Have an HP computer? Check for the Conexant keylogger called MicTray]
![]() |
Patch reliability is unclear. Unless you have an immediate, pressing need to install a specific patch, don't do it. |
SIGN IN | Not a member? | REGISTER | PLUS MEMBERSHIP |
-
Have an HP computer? Check for the Conexant keylogger called MicTray
Home » Forums » Newsletter and Homepage topics » Have an HP computer? Check for the Conexant keylogger called MicTray
- This topic has 19 replies, 10 voices, and was last updated 8 years ago by
anonymous.
AuthorTopicViewing 11 reply threadsAuthorReplies-
MrJimPhelps
AskWoody MVPMay 11, 2017 at 9:01 am #114272Pretty shocking.
It seems that these days everyone feels it is ok to grab your personal information.
You could disable all Conexant devices and install a sound card. Or, don’t buy a computer if it has Conexant audio.
Group "L" (Linux Mint)
with Windows 10 running in a remote session on my file server -
Anonymous
Inactive -
woody
Manager -
John in Mtl
AskWoody LoungerMay 11, 2017 at 9:29 am #114286That’s what I did – searched for “MicTray” and “*Tray”. Nothing found, yay! But I already knew I had no Conexant chips in the box…
Still, I’m sitting here going, “Wow, who would ever suspect that their audio driver is recording all their keystrokes!” Unplug the mic to disable audio spying, yeah makes sense; but how could anyone ever know that the driver records keystrokes? Wicked!!
-
mindwarp
AskWoody PlusMay 11, 2017 at 10:48 pm #114517Actually, it somewhat makes sense why the driver was looking at keystrokes, since it was looking to see if a keyboard button to toggle the microphone was hit. Evidently whoever wrote the driver couldn’t think of a better way to do it than borrowing malware techniques. That said, the next question should be are there any other drivers that are looking for specific keystrokes that were written the same way…
1 user thanked author for this post.
-
anonymous
Guest
-
-
-
-
EP
AskWoody_MVPMay 11, 2017 at 9:59 am #114304The sp78991 & sp78993 packages from HP (VERSION: 11.30.1680.45 REV: Q PASS: 52 and VERSION: 11.30.1680.45 REV: Q PASS: 5) also have the mictray.exe & mictray64.exe files included . The mictray files seem to be first included in v8.65.114.0 (a Sept. 2015 driver) for HP
Seems like the Conexant audio driver from Dell [aka. Conexant CX20722 Audio Driver v8.65.135.91] (in the Audio_Driver_KY3FK_WN32_8.65.135.91_A04.EXE file) also has the mictray files. Fortunately, the Conexant audio driver I use on my family’s Dell Inspiron 620 computer (v8.50.4.0) did not have the mictray files included.
I’m pretty sure the recent Conexant audio drivers from ASUS & Lenovo (drivers that begin with version 8.66.x) do NOT have the Mictray files.
-
BobbyB
AskWoody LoungerMay 11, 2017 at 12:22 pm #114368Well many thx for the heads up there @Woody. Certainly an eye opener that one.I am guessing looking at it its an x64(amd64)64 bit so a big “Phew!” here and then probably 32bit isnt affected all my connexant working drivers are circa 2005 backed up and installed for my ole Win7 (Compaq/HP) machine sitting in the corner. The newer (HP)x64 one doesent use Connexant but checked its Drivers in HP Softpaq mercifully clean as was system32 & Public folders.
Got to wonder how did that happen can we trust any proprietry or M$ drivers any more? -
anonymous
Guest -
anonymous
Guest
-
-
anonymous
GuestMay 12, 2017 at 8:28 am #114554Spyware keylogging in Windows 10 is a feature, now spyware in a driver is bad? Come on… we should embrace our new spyware overlords and accept them. Shower them with many taraquads of our personal information and miscellaneous other data. In the new spyware filled PC landscape there is one scourge that will be eliminated forever … passwords. If your OS, driver, and applications log your keystrokes for use by their respective companies and people within them whats the point of having passwords?
500 million Windows 10 users can’t be wrong. Can they?
Resistance is futile…
-
anonymous
Guest -
woody
Manager
-
-
JohnFDoe
AskWoody LoungerMay 14, 2017 at 9:46 am #115163Having read the detailed writeup, and knowing the system calls involved better than most, I would like to correct a few misunderstandings:
- This was an accidental keylogger, someone at Conexant or HP accidentally shipped multiple builds of the driver with extra code to debug the assignment of the mute/volume per-model hotkeys (e.g. FN+< on one model, FN+F7 on another, etc.).
- That debugging code would write to a log file every time a key was pressed, if that key was recognized as a volume mute/down/up key, and (unfortunately) what the key was. Obviously the idea was to only log this for a few hours on HP’s own test computers while editing the config files, but they slipped up.
- The “LL Keyboard Hook” API is the most reliable of the not-unusual Win32 APIs that can make such hotkeys work, it’s not some special malware-only API. It is not even an API just for hotkeys, there are situations where this can be needed in almost any kind of non-trivial keyboard input code.
- MicTray64.exe is a very appropriate name for a program that shows a Microphone icon in the “tray” next to the system clock, and implements hotkeys for muting etc. the Microphone without using the mouse to click the icon. I would expect the fixed version (without the debug logging, but with the hotkey catching) to still have that name, just a higher version number.
- It appears that HP and or Conexant may have worked the developer hard, as one of the vulnerable files was timestamped around 4 AM EST on Dec 24.
- It also appears that ModZero AG may have jumped the gun by releasing the details just days after being told they had contacted the wrong company (HPE who makes servers instead of HP who makes laptops and Conexant who wrote MicTray64.exe).
- I had nothing to do with the code in question, but I happen to know enough to understand the finer details of the writeup by ModZero AG.
-
woody
Manager
-
-
anonymous
GuestMay 14, 2017 at 10:59 am #115185 -
gborn
AskWoody_MVPMay 16, 2017 at 8:23 am #115670@JohnFDoe: Your assumption may be right – but they left a “backdoor” within the system, that may have been used easily to send keystrokes remotely.
Anyway, HP released another conexant audio driver with a ‘deactivated’ keylogger …
… then they released days later just another conexant audio driver, finally with a removed keylogger.
But not to mention any change log (as far as I’ve seen – I’m not a native English language speaker – on their Security Advisory site with driver update links – seems not too smart (even not informing the ‘finder’ of the keylogger, Mr. Schröder, about their plans).
BTW: I’ve documented the latest steps within the blog post The HP Conexant audio driver ‘stop key logger’ placebo update.
Ex Microsoft Windows (Insider) MVP, Microsoft Answers Community Moderator, Blogger, Book author
https://www.borncity.com/win/
1 user thanked author for this post.
-
EP
AskWoody_MVPMay 16, 2017 at 8:37 pm #115801A plethora of updated Conexant HD Audio drivers have been posted at the Microsoft Update Catalog site recently to deal with the “mictray keylogger” problem.
seems like the 8.65.1xx versions were affected and HP & Microsoft have posted new Conexant audio drivers
-
anonymous
Guest
Viewing 11 reply threads - This topic has 19 replies, 10 voices, and was last updated 8 years ago by
-

Plus Membership
Donations from Plus members keep this site going. You can identify the people who support AskWoody by the Plus badge on their avatars.
AskWoody Plus members not only get access to all of the contents of this site -- including Susan Bradley's frequently updated Patch Watch listing -- they also receive weekly AskWoody Plus Newsletters (formerly Windows Secrets Newsletter) and AskWoody Plus Alerts, emails when there are important breaking developments.
Get Plus!
Welcome to our unique respite from the madness.
It's easy to post questions about Windows 11, Windows 10, Win8.1, Win7, Surface, Office, or browse through our Forums. Post anonymously or register for greater privileges. Keep it civil, please: Decorous Lounge rules strictly enforced. Questions? Contact Customer Support.
Search Newsletters
Search Forums
View the Forum
Search for Topics
Recent Topics
-
Windows 11 Insider Preview build 27863 released to Canary
by
joep517
4 hours, 18 minutes ago -
Windows 11 Insider Preview build 26120.4161 (24H2) released to BETA
by
joep517
4 hours, 19 minutes ago -
AI model turns to blackmail when engineers try to take it offline
by
Cybertooth
4 hours, 25 minutes ago -
Migrate off MS365 to Apple Products
by
dmt_3904
29 minutes ago -
Login screen icon
by
CWBillow
12 hours, 31 minutes ago -
AI coming to everything
by
Susan Bradley
4 hours, 29 minutes ago -
Mozilla : Pocket shuts down July 8, 2025, Fakespot shuts down on July 1, 2025
by
Alex5723
19 hours, 58 minutes ago -
No Screen TurnOff???
by
CWBillow
20 hours, 20 minutes ago -
Identify a dynamic range to then be used in another formula
by
BigDaddy07
20 hours, 53 minutes ago -
InfoStealer Malware Data Breach Exposed 184 Million Logins and Passwords
by
Alex5723
1 day, 8 hours ago -
How well does your browser block trackers?
by
n0ads
18 hours, 47 minutes ago -
You can’t handle me
by
Susan Bradley
6 hours, 20 minutes ago -
Chrome Can Now Change Your Weak Passwords for You
by
Alex5723
11 hours, 24 minutes ago -
Microsoft: Over 394,000 Windows PCs infected by Lumma malware, affects Chrome..
by
Alex5723
1 day, 19 hours ago -
Signal vs Microsoft’s Recall ; By Default, Signal Doesn’t Recall
by
Alex5723
23 hours, 22 minutes ago -
Internet Archive : This is where all of The Internet is stored
by
Alex5723
1 day, 20 hours ago -
iPhone 7 Plus and the iPhone 8 on Vantage list
by
Alex5723
1 day, 20 hours ago -
Lumma malware takedown
by
EyesOnWindows
1 day, 8 hours ago -
“kill switches” found in Chinese made power inverters
by
Alex5723
2 days, 5 hours ago -
Windows 11 – InControl vs pausing Windows updates
by
Kathy Stevens
2 days, 5 hours ago -
Meet Gemini in Chrome
by
Alex5723
2 days, 9 hours ago -
DuckDuckGo’s Duck.ai added GPT-4o mini
by
Alex5723
2 days, 9 hours ago -
Trump signs Take It Down Act
by
Alex5723
2 days, 17 hours ago -
Do you have a maintenance window?
by
Susan Bradley
21 hours, 56 minutes ago -
Freshly discovered bug in OpenPGP.js undermines whole point of encrypted comms
by
Nibbled To Death By Ducks
1 day, 19 hours ago -
Cox Communications and Charter Communications to merge
by
not so anon
2 days, 20 hours ago -
Help with WD usb driver on Windows 11
by
Tex265
7 hours, 45 minutes ago -
hibernate activation
by
e_belmont
3 days, 5 hours ago -
Red Hat Enterprise Linux 10 with AI assistant
by
Alex5723
3 days, 9 hours ago -
Windows 11 Insider Preview build 26200.5603 released to DEV
by
joep517
3 days, 12 hours ago
Recent blog posts
Key Links
Want to Advertise in the free newsletter? How about a gift subscription in honor of a birthday? Send an email to sb@askwoody.com to ask how.
Mastodon profile for DefConPatch
Mastodon profile for AskWoody
Home • About • FAQ • Posts & Privacy • Forums • My Account
Register • Free Newsletter • Plus Membership • Gift Certificates • MS-DEFCON Alerts
Copyright ©2004-2025 by AskWoody Tech LLC. All Rights Reserved.