HP delivers some of its laptops with a pre-installed keylogger with its audio drivers. Here’s what you need to do to remove it.
What does this keylogger do?
Researchers have discovered a keylogger that comes packaged with the Conexant HD Audio Driver Package in version 220.127.116.11 and earlier. Along with this audio driver, there is a file named MicTray64.exe that features a scheduled task to run each time the users longs on to their system. From this, all keystrokes are then stored in a plaintext file (at C:\users\public\MicTray.log), something most users won’t be too excited about.
Other users of that specific machine will be able to access the file and it may even possible that any program installed on the computer could access it. In the case there is malware involved, the results can be quite devastating.
How to block HP’s key logger
On Reddit, a user named “_My_Angry_Account_” presented a successful solution that will prevent the built-in keylogger from running. Here are the necessary steps you need to take:
- Start the Registry Editor.
- Go to HKEY_LOCAL_MACHINE\Software\Microsoft\Windows NT\currentversion\image file execution options.
- Right click on the image file execution options > New > Key
- Name the new key MicTray.exe
- Right click new MicTray.exe key > New > String Value
- Assign a name to the new value debugger
- Set the new debugger string value to: devenv / debugexe
Further on, the user explains what all this will result in:
It forces any .exe file named MicTray or MicTray64 to go through a debugger and this causes it to fail. This is also how I nerfed the GWX.exe that would auto upgrade computers to Windows X.
*edit to add – If you are running Windows 64-bit then steps 4 and 5 should be:
- Name the new key MicTray64.exe
- Right click new MicTray64.exe key > New > String value
To check your version of Windows the shortcut is to hold down your Windows Key and press Pause (Break) or in Windows 8.1 and 10 you can right click on the start button and click on System. In previous versions you can right click on Computer or My Computer and click on Properties to find out what version of Windows you are running.
28 models of machines released by HP seem to be affected by this keylogger for now.
RELATED STORIES TO CHECK OUT: