Oops - HP laptops include keystroke logger that records user names and passwords

Keylogger discovered in HP laptop audio drivers
HP laptops loaded up with keystroke logging software for 18 months, claims security firm
Author

13 May, 2017

The keylogger is used by audio drivers to determine when the up and down volume control buttons on the keyboard have been pressed.

2017-05-05: Sent technical information to HPE security contact. Security researchers believe that the keylogger function was installed into the laptops by developers of the audio driver.

The log file itself is overwritten every time the computer is booted up but with system backups, an ongoing complete history of user keystrokes would be available. This is basically where every typing activity by users is recorded and stored in an unsecured file on the computer.

That seemed innocent enough but, on further examination, Modzero found that the audio driver package -developed and digitally signed by the audio chip manufacturer Conexant - has been poorly implemented, turning the driver "effectively into keylogging spyware". However, a number of debugging features have ended up ensuring that all keystrokes are recorded and written to a log file.

"There is no evidence that this keylogger has been intentionally implemented", the security firm said in its blog post.

'Obviously, it is a negligence of the developers - which makes the software no less harmful'. "We want to make sure this doesn't happen again". However, by doing this, may disable special key function but that's a fair trade-off IMO.

Notably, a security firm known as Modzero has earlier intimated HP and Conexant about the keystroke logging flaw, however, HP's Nash said that the company had already been in a process of working on the fix before Modzero's notification.

The audio driver was created to identify when a special key on the PC was used. This includes paraphrases for online banking and email accounts.

As noted, the Keylogger contained in audiocpu Conexant driver version 1.0.0.46 and older.

It does not appear the keylogger feature was designed with malicious intent, though.

All users of HP computers should check whether the program C:\Windows\System32\MicTray64.exe or C:\Windows\System32\MicTray.exe is installed.

For now, ModZero recommends that users check for and delete or rename the MicTray64 and MicTray applications (located at C:\Windows\System32\). You can also verify the files C:WindowsSystem32MicTray.exe or C:WindowsSystem32MicTray64.exe.


More news


  • 'Guardians' Of The Galaxy Vol. 3': Elizabeth Debicki Will Return As

    Gunn confirmed that he intends on having Debicki reprise her role as Ayesha. "I absolutely plan on bringing Elizabeth Debicki back".
    Theresa May and Jeremy Corbyn get personal over defence on election trail

    Theresa May and Jeremy Corbyn get personal over defence on election trail

    In excerpts of a speech later in London today, he said that his stance on the issue was far from the "almost routine" military interventions of recent times.
    China says it tested new missile in northeastern sea

    China says it tested new missile in northeastern sea

    Meant to shoot down incoming North Korean missiles, Beijing has called the system a threat to its own national security. Officials also did not say what platform the weapon was launched from.
  • Tottenham's Son Heung-min is Premier League player of month

    Tottenham's Son Heung-min is Premier League player of month

    With the London side falling short of the Premier League title for a second year running, there were fears players could move on. It is a game that we want to win and for sure they will want to win.

    Crosby scores twice, Bonino has victor as Pens beat Caps

    Washington made a tremendous push from that point forward, peppering Fleury with shot after shot, but the Pens survived. He's probably right: This is going to be a long, wonderful seesaw series - that is, if the Caps win Game 2.
    Marvell Technology Group Ltd. (NASDAQ:MRVL) Valuation According To Analysts

    Marvell Technology Group Ltd. (NASDAQ:MRVL) Valuation According To Analysts

    The stock of Marvell Technology Group Ltd. (NASDAQ: MRVL ) has "Positive" rating given on Friday, August 7 by Susquehanna. The stock has a market capitalization of $7.90 billion, a price-to-earnings ratio of 383.537 and a beta of 1.11.
  • Master of None season 2

    Master of None season 2

    Dev has fled NY for the more provincial pastures of Italy-a change drastic enough to alter a show's entire alchemy. In one great episode, he comes to terms with his Muslim upbringing, which he's strained against since childhood.
    Bellerin to replace the Ox when Arsenal face Stoke?

    Bellerin to replace the Ox when Arsenal face Stoke?

    All the games the same thing... we saw our games since the beginning of the season, many games where we've had the same feeling. Do you something awesome to share with the world? Hello.
    Speeding Amtrak engineer charged in deadly derailment

    Speeding Amtrak engineer charged in deadly derailment

    On May 12, 2015 Amtrak train 188 travelling from Washington , DC to New York City derailed on the outskirts of Philadelphia . Kline and attorney Robert Mongeluzzi, who helped negotiate the settlement, announced the judge's order late Thursday.
  • Obama starts defining his new role in the age of Trump

    Obama starts defining his new role in the age of Trump

    Michael Flynn's knowing lies about his contacts with Russian Federation left him subject to manipulation by foreign adversaries. Sally Yates tells Congress General Mike Flynn had been compromised subject to blackmail by Russian Federation .
    Mets Matt Harvey breaks silence by apologizing for recent actions

    Mets Matt Harvey breaks silence by apologizing for recent actions

    He was infamously tardy for a workout in advance of the 2015 postseason, which initially was explained as an issue with traffic. Meanwhile, one has to wonder how this latest incident impacts Harvey's long-term future with the Mets organization.
    Judge Orders Prosecutors to Charge Driver in Amtrak Derailment

    Judge Orders Prosecutors to Charge Driver in Amtrak Derailment

    Two other lawyers representing 32 other crash victims in lawsuits against Amtrak joined in the appeal for criminal charges . The city quickly referred the prosecution to the state attorney general Thursday to avoid a potential conflict of interest.