Skip to main content

Application:W32/Keylogger.MicTray

Classification

Type:

Application

Aliases:

  • Application.Keylogger.MicTray.[variant]
  • Application.Keylogger.QNZ

Summary

This detection identifies certain versions of the Conexant HD Audio Driver files, which in May 2017 security researchers reported were unintentionally logging all keystrokes typed on the affected machine. The audio drivers come pre-installed on certain models of laptops from HP.

Removal

Technical Details

In May 2017, security researchers reported the discovery of a keylogger installed on some laptop models from HP. The keylogger was identified as certain versions (1.0.0.46 and higher) of the Conexant HD Audio Driver files, which come pre-installed on certain models of laptops released in 2015 and 2016.

According to the customer advisory released by HP itself, the audio drivers unintentionally included debugging capabilities that were not meant for public release. The debugging feature resulted in the audio driver silently capturing all keystrokes that were typed on the affected machine and saving them to an unencrypted log file at C:\Users\Public\MicTray.log.

HP also confirmed that they do not have access to the data, and that the log file the data is saved in is removed each time the user restarts or logs off the machine.

For more information about the issue, see:

Potential loss of privacy or security

Debugging is legitimately used by developers to troubleshoot problems during development before a program is released to the public. In this context however, the unintentional capturing of users' keystrokes may raise privacy concerns. The data stored in the unencrypted file may also pose a security concern if an unauthorized

As such, we recommend that users any affected machines at their earliest convenience. HP released security updates for the Conexant HD Audio Driver files, which can be found, along with further details and instructions, at:

Protect your devices from malware with F‑Secure Total

Protecting your devices from malicious software is essential for maintaining online security. F‑Secure Total makes this easy, helping you to secure your devices in a brilliantly simple way.

  • Award‑winning antivirus and malware protection

  • Online browsing, banking, and shopping protection

  • 24/7 online identity and data breach monitoring

  • Unlimited VPN service to safe­guard your privacy

  • Password manager with private data protection

Choose how many devices you want to protect to get started.

  • Free customer support

  • Cancel anytime

  • The trial does not obligate you to buy the product

After 30 days your subscription will renew automatically for one year at €69.99.

More Support

Community

Ask questions in our Community.

User guides

Check the user guide for instructions.

Contact Support

Chat with with or call an agent.

Submit a Sample

Submit a file or URL for analysis.