HP Laptops Found with Keylogger Built Into Audio Driver
-
Reports are coming in that dozens of models of HP laptops have been discovered to have a Conextant audio driver included and enabled by default that log all user keystrokes and write them to a local log file making them a potential risk to malware, hackers or other users of the system. The keylogger also includes an API which may enable malware to watch real time keystrokes without being detected by antivirus tools.
-
Here is the current known list of machines that are affected. As with most risks of this nature, only Windows machines are at risk.
HP EliteBook 820 G3 Notebook PC HP EliteBook 828 G3 Notebook PC HP EliteBook 840 G3 Notebook PC HP EliteBook 848 G3 Notebook PC HP EliteBook 850 G3 Notebook PC HP ProBook 640 G2 Notebook PC HP ProBook 650 G2 Notebook PC HP ProBook 645 G2 Notebook PC HP ProBook 655 G2 Notebook PC HP ProBook 450 G3 Notebook PC HP ProBook 430 G3 Notebook PC HP ProBook 440 G3 Notebook PC HP ProBook 446 G3 Notebook PC HP ProBook 470 G3 Notebook PC HP ProBook 455 G3 Notebook PC HP EliteBook 725 G3 Notebook PC HP EliteBook 745 G3 Notebook PC HP EliteBook 755 G3 Notebook PC HP EliteBook 1030 G1 Notebook PC HP ZBook 15u G3 Mobile Workstation HP Elite x2 1012 G1 Tablet HP Elite x2 1012 G1 with Travel Keyboard HP Elite x2 1012 G1 Advanced Keyboard HP EliteBook Folio 1040 G3 Notebook PC HP ZBook 17 G3 Mobile Workstation HP ZBook 15 G3 Mobile Workstation HP ZBook Studio G3 Mobile Workstation HP EliteBook Folio G1 Notebook PC
-
Ive got one hp laptop here, but is the Spectre line, and does not use this driver and has no mictray.exe
Checking all my other hp desktops just in case. There are some using the Conexant audio driver, but none have mictray.exe so far. -
@momurda said in HP Laptops Found with Keylogger Built Into Audio Driver:
Ive got one hp laptop here, but is the Spectre line, and does not use this driver and has no mictray.exe
Checking all my other hp desktops just in case. There are some using the Conexant audio driver, but none have mictray.exe so far.Look for the log file as well, just in case it is being created via some other process.
-
C:\Users\Public\MicTray.log
-
Glad that I just returned the demo we received, although I don't recall what model it was.
-
@DustinB3403 said in HP Laptops Found with Keylogger Built Into Audio Driver:
Glad that I just returned the demo we received, although I don't recall what model it was.
But it can recall an awful lot
-
So very important to know... if you have one of these HPs and you take it to Geek Squad or return it to HP or send it out for recycling: it is easily full of your very, very private data, stuff that you never yourself recorded on the machine!
-
@scottalanmiller said in HP Laptops Found with Keylogger Built Into Audio Driver:
So very important to know... if you have one of these HPs and you take it to Geek Squad or return it to HP or send it out for recycling: it is easily full of your very, very private data, stuff that you never yourself recorded on the machine!
I generally never let MY computer go without first DoD'ing the drive.... And if the system died (my ACER) I keep the HDD... nothing was wrong with it any way.
No logger found in my old system -
-
Good lord, someone's getting fired + put on trial for that one
-
@MattSpeller said in HP Laptops Found with Keylogger Built Into Audio Driver:
Good lord, someone's getting fired + put on trial for that one
One can only hope.
-
-
@MattSpeller said in HP Laptops Found with Keylogger Built Into Audio Driver:
Good lord, someone's getting fired + put on trial for that one
Haha, oh man that's funny.
-
@scottalanmiller said in HP Laptops Found with Keylogger Built Into Audio Driver:
@MattSpeller said in HP Laptops Found with Keylogger Built Into Audio Driver:
Good lord, someone's getting fired + put on trial for that one
One can only hope.
Stop reading my mind before I scroll down far enough to see your reply
-
-
@scottalanmiller said in HP Laptops Found with Keylogger Built Into Audio Driver:
https://cdn.arstechnica.net/wp-content/uploads/2017/05/keylogger.jpg
That password though. . . I mean come on "football23" no capitals, or special characters. . . Would you even need a keylogger for that?
-
I have one here.
I made the log file read only.
Let's have a little fun. -
@DustinB3403 said in HP Laptops Found with Keylogger Built Into Audio Driver:
@scottalanmiller said in HP Laptops Found with Keylogger Built Into Audio Driver:
https://cdn.arstechnica.net/wp-content/uploads/2017/05/keylogger.jpg
That password though. . . I mean come on "football23" no capitals, or special characters. . . Would you even need a keylogger for that?
My guess for a single cracking machine (8 video cards for massively parallel compute), about 2 minutes.
-
Yeah I actually just shipped one of these laptops back yesterday!
Good thing it was only a trial device and we did nothing with it.
-
@scotth Is the log file showing all keystrokes before you made it readoly?