Post coming in InfoWorld
[See the full post at: Have an HP computer? Check for the Conexant keylogger called MicTray]
![]() |
Patch reliability is unclear. Unless you have an immediate, pressing need to install a specific patch, don't do it. |
SIGN IN | Not a member? | REGISTER | PLUS MEMBERSHIP |
-
Have an HP computer? Check for the Conexant keylogger called MicTray
Home » Forums » Newsletter and Homepage topics » Have an HP computer? Check for the Conexant keylogger called MicTray
- This topic has 19 replies, 10 voices, and was last updated 8 years ago by
anonymous.
AuthorTopicViewing 11 reply threadsAuthorReplies-
MrJimPhelps
AskWoody MVPMay 11, 2017 at 9:01 am #114272Pretty shocking.
It seems that these days everyone feels it is ok to grab your personal information.
You could disable all Conexant devices and install a sound card. Or, don’t buy a computer if it has Conexant audio.
Group "L" (Linux Mint)
with Windows 10 running in a remote session on my file server -
Anonymous
Inactive -
woody
Manager -
John in Mtl
AskWoody LoungerMay 11, 2017 at 9:29 am #114286That’s what I did – searched for “MicTray” and “*Tray”. Nothing found, yay! But I already knew I had no Conexant chips in the box…
Still, I’m sitting here going, “Wow, who would ever suspect that their audio driver is recording all their keystrokes!” Unplug the mic to disable audio spying, yeah makes sense; but how could anyone ever know that the driver records keystrokes? Wicked!!
-
mindwarp
AskWoody PlusMay 11, 2017 at 10:48 pm #114517Actually, it somewhat makes sense why the driver was looking at keystrokes, since it was looking to see if a keyboard button to toggle the microphone was hit. Evidently whoever wrote the driver couldn’t think of a better way to do it than borrowing malware techniques. That said, the next question should be are there any other drivers that are looking for specific keystrokes that were written the same way…
1 user thanked author for this post.
-
anonymous
Guest
-
-
-
EP
AskWoody_MVPMay 11, 2017 at 9:59 am #114304The sp78991 & sp78993 packages from HP (VERSION: 11.30.1680.45 REV: Q PASS: 52 and VERSION: 11.30.1680.45 REV: Q PASS: 5) also have the mictray.exe & mictray64.exe files included . The mictray files seem to be first included in v8.65.114.0 (a Sept. 2015 driver) for HP
Seems like the Conexant audio driver from Dell [aka. Conexant CX20722 Audio Driver v8.65.135.91] (in the Audio_Driver_KY3FK_WN32_8.65.135.91_A04.EXE file) also has the mictray files. Fortunately, the Conexant audio driver I use on my family’s Dell Inspiron 620 computer (v8.50.4.0) did not have the mictray files included.
I’m pretty sure the recent Conexant audio drivers from ASUS & Lenovo (drivers that begin with version 8.66.x) do NOT have the Mictray files.
BobbyB
AskWoody LoungerMay 11, 2017 at 12:22 pm #114368Well many thx for the heads up there @Woody. Certainly an eye opener that one.I am guessing looking at it its an x64(amd64)64 bit so a big “Phew!” here and then probably 32bit isnt affected all my connexant working drivers are circa 2005 backed up and installed for my ole Win7 (Compaq/HP) machine sitting in the corner. The newer (HP)x64 one doesent use Connexant but checked its Drivers in HP Softpaq mercifully clean as was system32 & Public folders.
Got to wonder how did that happen can we trust any proprietry or M$ drivers any more? 🙁anonymous
Guest-
anonymous
Guest
anonymous
GuestMay 12, 2017 at 8:28 am #114554Spyware keylogging in Windows 10 is a feature, now spyware in a driver is bad? Come on… we should embrace our new spyware overlords and accept them. Shower them with many taraquads of our personal information and miscellaneous other data. In the new spyware filled PC landscape there is one scourge that will be eliminated forever … passwords. If your OS, driver, and applications log your keystrokes for use by their respective companies and people within them whats the point of having passwords?
500 million Windows 10 users can’t be wrong. Can they?
Resistance is futile…
anonymous
Guest-
woody
Manager
JohnFDoe
AskWoody LoungerMay 14, 2017 at 9:46 am #115163Having read the detailed writeup, and knowing the system calls involved better than most, I would like to correct a few misunderstandings:
- This was an accidental keylogger, someone at Conexant or HP accidentally shipped multiple builds of the driver with extra code to debug the assignment of the mute/volume per-model hotkeys (e.g. FN+< on one model, FN+F7 on another, etc.).
- That debugging code would write to a log file every time a key was pressed, if that key was recognized as a volume mute/down/up key, and (unfortunately) what the key was. Obviously the idea was to only log this for a few hours on HP’s own test computers while editing the config files, but they slipped up.
- The “LL Keyboard Hook” API is the most reliable of the not-unusual Win32 APIs that can make such hotkeys work, it’s not some special malware-only API. It is not even an API just for hotkeys, there are situations where this can be needed in almost any kind of non-trivial keyboard input code.
- MicTray64.exe is a very appropriate name for a program that shows a Microphone icon in the “tray” next to the system clock, and implements hotkeys for muting etc. the Microphone without using the mouse to click the icon. I would expect the fixed version (without the debug logging, but with the hotkey catching) to still have that name, just a higher version number.
- It appears that HP and or Conexant may have worked the developer hard, as one of the vulnerable files was timestamped around 4 AM EST on Dec 24.
- It also appears that ModZero AG may have jumped the gun by releasing the details just days after being told they had contacted the wrong company (HPE who makes servers instead of HP who makes laptops and Conexant who wrote MicTray64.exe).
- I had nothing to do with the code in question, but I happen to know enough to understand the finer details of the writeup by ModZero AG.
-
woody
Manager
anonymous
GuestMay 14, 2017 at 10:59 am #115185gborn
AskWoody_MVPMay 16, 2017 at 8:23 am #115670@JohnFDoe: Your assumption may be right – but they left a “backdoor” within the system, that may have been used easily to send keystrokes remotely.
Anyway, HP released another conexant audio driver with a ‘deactivated’ keylogger …
… then they released days later just another conexant audio driver, finally with a removed keylogger.
But not to mention any change log (as far as I’ve seen – I’m not a native English language speaker – on their Security Advisory site with driver update links – seems not too smart (even not informing the ‘finder’ of the keylogger, Mr. Schröder, about their plans).
BTW: I’ve documented the latest steps within the blog post The HP Conexant audio driver ‘stop key logger’ placebo update.
Ex Microsoft Windows (Insider) MVP, Microsoft Answers Community Moderator, Blogger, Book author
https://www.borncity.com/win/
1 user thanked author for this post.
EP
AskWoody_MVPMay 16, 2017 at 8:37 pm #115801A plethora of updated Conexant HD Audio drivers have been posted at the Microsoft Update Catalog site recently to deal with the “mictray keylogger” problem.
seems like the 8.65.1xx versions were affected and HP & Microsoft have posted new Conexant audio drivers
anonymous
GuestViewing 11 reply threads - This topic has 19 replies, 10 voices, and was last updated 8 years ago by
-

Plus Membership
Donations from Plus members keep this site going. You can identify the people who support AskWoody by the Plus badge on their avatars.
AskWoody Plus members not only get access to all of the contents of this site -- including Susan Bradley's frequently updated Patch Watch listing -- they also receive weekly AskWoody Plus Newsletters (formerly Windows Secrets Newsletter) and AskWoody Plus Alerts, emails when there are important breaking developments.
Get Plus!
Welcome to our unique respite from the madness.
It's easy to post questions about Windows 11, Windows 10, Win8.1, Win7, Surface, Office, or browse through our Forums. Post anonymously or register for greater privileges. Keep it civil, please: Decorous Lounge rules strictly enforced. Questions? Contact Customer Support.
Search Newsletters
Search Forums
View the Forum
Search for Topics
Recent Topics
-
Microsoft : Edge is better than Chrome
by
Alex5723
6 hours, 51 minutes ago -
The EU launched DNS4EU
by
Alex5723
12 hours, 24 minutes ago -
Cell Phone vs. Traditional Touchtone Phone over POTS
by
280park
2 hours, 45 minutes ago -
Lost access to all my networked drives (shares) listed in My Computer
by
lwerman
17 hours, 51 minutes ago -
Set default size for pasted photo to word
by
Cyn
23 hours, 52 minutes ago -
Dedoimedo tries 24H2…
by
Cybertooth
11 hours, 59 minutes ago -
Windows 11 Insider Preview build 27871 released to Canary
by
joep517
1 day, 22 hours ago -
Windows 11 ad from Campaign Manager in Windows 10
by
Jim McKenna
1 day, 20 hours ago -
Small desktops
by
Susan Bradley
13 hours, 31 minutes ago -
Totally disable Bitlocker
by
CWBillow
16 hours, 24 minutes ago -
Phishers extract Millions from HMRC accounts..
by
Microfix
1 day, 20 hours ago -
Windows 10 22H2 Update today (5 June) says up-to-date but last was 2025-04
by
Alan_uk
3 days, 2 hours ago -
Thoughts on Malwarebytes Scam Guard for Mobile?
by
opti1
21 hours, 33 minutes ago -
Mystical Desktop
by
CWBillow
3 days, 6 hours ago -
Meta and Yandex secretly tracked billions of Android users
by
Alex5723
2 days, 11 hours ago -
MS-DEFCON 2: Do you need that update?
by
Susan Bradley
1 day, 3 hours ago -
CD/DVD drive is no longer recognized
by
WSCape Sand
3 days, 21 hours ago -
Windows 11 24H2 Default Apps stuck on Edge and Adobe Photoshop
by
MikeBravo
4 days ago -
North Face and Cartier customer data stolen in cyber attacks
by
Alex5723
3 days, 22 hours ago -
What is wrong with simple approach?
by
WSSpoke36
1 day, 20 hours ago -
Microsoft-Backed Builder.ai Set for Bankruptcy After Cash Seized
by
Alex5723
4 days, 9 hours ago -
Location, location, location
by
Susan Bradley
3 days ago -
Cannot get a task to run a restore point
by
CWBillow
4 days, 11 hours ago -
Frustrating search behavior with Outlook
by
MrJimPhelps
4 days, 1 hour ago -
June 2025 Office non-Security Updates
by
PKCano
4 days, 21 hours ago -
Secure Boot Update Fails after KB5058405 Installed
by
SteveIT
13 minutes ago -
Firefox Red Panda Fun Stuff
by
Lars220
4 days, 21 hours ago -
How start headers and page numbers on page 3?
by
Davidhs
5 days, 8 hours ago -
Attack on LexisNexis Risk Solutions exposes data on 300k +
by
Nibbled To Death By Ducks
4 days, 10 hours ago -
Windows 11 Insider Preview build 26200.5622 released to DEV
by
joep517
5 days, 16 hours ago
Recent blog posts
Key Links
Want to Advertise in the free newsletter? How about a gift subscription in honor of a birthday? Send an email to sb@askwoody.com to ask how.
Mastodon profile for DefConPatch
Mastodon profile for AskWoody
Home • About • FAQ • Posts & Privacy • Forums • My Account
Register • Free Newsletter • Plus Membership • Gift Certificates • MS-DEFCON Alerts
Copyright ©2004-2025 by AskWoody Tech LLC. All Rights Reserved.