Velocity Reviews - Computer Hardware Reviews

Velocity Reviews > Newsgroups > Computing > Computer Security > "keyhook.exe" process installed by SIS 315 video card driver

Reply
Thread Tools

"keyhook.exe" process installed by SIS 315 video card driver

 
 
Eddie Crismond
Guest
Posts: n/a
 
      08-11-2004
Hello

Windows task manager showed KEYHOOK.EXE running as process on a PC I was
working with today. More than one result from Google indicated that this
was associated with an SIS keyboard driver, designed to do some kind of
filtering. But some indicated that this was full blown malware designed
to log keystrokes.

One description of keyhook.exe, and removal instructions can be found
here...
http://www.pestpatrol.com/pestinfo/b...in_keyhook.asp

I didn't find any DLLs, but I did find the .exe, removed it, its
associated registry entry, and then rebooted.

Reading the setup.ini file in a zipped driver package that I downloaded
for an SIS 315 based video card in this system, showed that keyhook.exe
was apparently installed with this video cards driver.

Here is a snippet from the setup.ini...
[Utility.KeyHook]
ID=Khooker
Name=Khooker
Display=0
Select=5
WriteReg="[RegWrite.KeyHook.Win9X]", "%OS_9X%"
WriteReg="[RegWrite.KeyHook.WinNT]", "%OS_NT%"

There are several other entries in the setup.ini related to keyhook.

Here is the page where the driver was found...
http://www.softwarepatch.com/utilities/sis315.html
Which eventually takes you too...
http://driver.sis.com/graphic/gpu/315/

Does keyhook.exe have anything to do with keylogging, and if so, why
would keyhook.exe be installed with a video card driver?

Thank in advance
Edward Crismond

 
Reply With Quote
 
 
 
 
kony
Guest
Posts: n/a
 
      08-12-2004
On Wed, 11 Aug 2004 18:11:11 -0400, Eddie Crismond
<> wrote:


>Does keyhook.exe have anything to do with keylogging, and if so, why
>would keyhook.exe be installed with a video card driver?


keyhook could do whatever it's written to, with the keyboard
input. In this particular case it appears to be used for video
driver "hotkey" features. If user never knowns of (let alone
uses) the features, there is no reason to leave it running.
 
Reply With Quote
 
 
 
 
Ralph Wade Phillips
Guest
Posts: n/a
 
      08-12-2004
Howdy!

"Eddie Crismond" <> wrote in message
news:...
> Hello
>
> Windows task manager showed KEYHOOK.EXE running as process on a PC I was
> working with today. More than one result from Google indicated that this
> was associated with an SIS keyboard driver, designed to do some kind of
> filtering. But some indicated that this was full blown malware designed
> to log keystrokes.


Err - "John Smith was hired by the school as a teacher. But Google
shows John Smith is a sex offender."

There actually happens to be at least TWO programs named
"keyhook.exe" out there ... and since you have the SiS video, it's a safe
bet that you've got the SiS variant there.

> Does keyhook.exe have anything to do with keylogging, and if so, why
> would keyhook.exe be installed with a video card driver?


Not THIS keyhook - it hooks into the keyboard processing chain to do
hotkey settings.

RwP


 
Reply With Quote
 
Eddie Crismond
Guest
Posts: n/a
 
      08-12-2004
kony wrote:
> On Wed, 11 Aug 2004 18:11:11 -0400, Eddie Crismond
> <> wrote:
>
>
>
>>Does keyhook.exe have anything to do with keylogging, and if so, why
>>would keyhook.exe be installed with a video card driver?

>
>
> keyhook could do whatever it's written to, with the keyboard
> input. In this particular case it appears to be used for video
> driver "hotkey" features. If user never knowns of (let alone
> uses) the features, there is no reason to leave it running.


Good, thanks Kony. As I mentioned in the OP, its off now.
 
Reply With Quote
 
Eddie Crismond
Guest
Posts: n/a
 
      08-12-2004
Ralph Wade Phillips wrote:

> Howdy!
>
> "Eddie Crismond" <> wrote in message
> news:...
>
>>Hello
>>
>>Windows task manager showed KEYHOOK.EXE running as process on a PC I was
>>working with today. More than one result from Google indicated that this
>>was associated with an SIS keyboard driver, designed to do some kind of
>>filtering. But some indicated that this was full blown malware designed
>>to log keystrokes.

>
>
> Err - "John Smith was hired by the school as a teacher. But Google
> shows John Smith is a sex offender."
>
> There actually happens to be at least TWO programs named
> "keyhook.exe" out there ... and since you have the SiS video, it's a safe
> bet that you've got the SiS variant there.
>
>


Great, thats what I was hoping, that it was benign.

>>Does keyhook.exe have anything to do with keylogging, and if so, why
>>would keyhook.exe be installed with a video card driver?

>
>
> Not THIS keyhook - it hooks into the keyboard processing chain to do
> hotkey settings.
>



Thanks

 
Reply With Quote
 
 
 
Reply

Thread Tools

Posting Rules
You may not post new threads
You may not post replies
You may not post attachments
You may not edit your posts

BB code is On
Smilies are On
[IMG] code is On
HTML code is Off
Trackbacks are On
Pingbacks are On
Refbacks are Off


Similar Threads
Thread Thread Starter Forum Replies Last Post
ERROR [HY000] [Microsoft][ODBC Microsoft Access Driver]General error Unable to open registry key 'Temporary (volatile) Jet DSN for process 0xffc Thread 0x228 DBC 0x437b94 Jet'. ERROR [IM006] [Microsoft][ODBC Driver Manager] Driver's SQLSetConnectAttr bazzer ASP .Net 0 03-30-2006 03:16 PM
ERROR [HY000] [Microsoft][ODBC Microsoft Access Driver]General error Unable to open registry key 'Temporary (volatile) Jet DSN for process 0x8fc Thread 0x934 DBC 0x437b94 Jet'. ERROR [IM006] [Microsoft][ODBC Driver Manager] Driver's SQLSetConnectAttr bazzer ASP .Net 1 03-24-2006 04:20 PM
ERROR [HY000] [Microsoft][ODBC Microsoft Access Driver]General error Unable to open registry key 'Temporary (volatile) Jet DSN for process 0x8fc Thread 0x934 DBC 0x437b94 Jet'. ERROR [IM006] [Microsoft][ODBC Driver Manager] Driver's SQLSetConnectAttr bazzer ASP .Net 0 03-24-2006 02:22 PM
SIS PORT Driver problem after Windows Update Mike Computer Support 3 04-29-2005 08:37 PM
Pine SIS 315E - 32MB PCI Video Card Daniel NZ Computing 6 09-18-2004 04:59 AM



Advertisments
 



1 2 3 4 5 6 7 8 9 10 11 12 13 14 15 16 17 18 19 20 21 22 23 24 25 26 27 28 29 30 31 32 33 34 35 36 37 38 39 40 41 42 43 44 45 46 47 48 49 50 51 52 53 54 55 56 57