How to Check Your PC for Keyloggers (Windows 11 & 10)

Logeshwaran

The fastest way to check for a keylogger on Windows 11 or 10 is Task Manager's Startup Apps tab plus a Windows Security scan — the Startup check takes under two minutes, the scan does the deep work in the background, and together they catch most software keyloggers. And no, you do not need to buy anything to do it. The keylogger that made thousands of people panic in 2017 — HP's "inbuilt keylogger" — was not planted by a hacker at all. It was a debugging feature Conexant left switched on inside an audio driver, quietly writing every keystroke to a text file so engineers could test the mute button. HP never meant for it to ship. That distinction matters, because it changes what you should actually be hunting for on your own PC today.

⚡ Quick Answer

Open Task ManagerCtrl + Shift + Esc, check Startup apps and Processes for anything unfamiliar tied to your microphone, audio driver, or "monitoring" software.

Run a full scanWin + I → Privacy & security → Windows Security → Virus & threat protection.

If both come back clean but you're still not sure, jump to the full six-method check below — software keyloggers hide in more places than Task Manager alone covers.

The 60-Second Check on Windows 11

Right-click the Start button, or press Ctrl + Shift + Esc, and open Task Manager. On the Processes tab, sort by name and read every entry once, slowly. You're not looking for anything exotic — you're looking for a name you cannot explain. Real keyloggers, whether they arrived as malware or as an over-permissive "employee monitoring" tool someone installed on a shared family PC, almost always run as a background process with an innocuous-sounding name: things like SysHelper, AudioSvc2, or a random string of letters. Right-click anything suspicious and choose Open file location — a process with no visible source folder, or one sitting in a temp directory instead of Program Files, is worth investigating further.

Then switch to the Startup apps tab (renamed from the old "Startup" tab in the Windows 11 22H2 Task Manager redesign, but the function is identical). Anything set to "Enabled" that you did not install yourself is a candidate. Keyloggers that survive a reboot need to restart somehow, and Startup apps is one of the most common places they register themselves.

Here's where Windows 11 trips people up who learned this on Windows 10: the right-click context menu is condensed by default. If you right-click a file expecting to see "Properties" or "Open with" immediately and it's not there, click Show more options first (or press Shift + F10) to get the full classic menu. Nothing is missing — it's just one tap deeper than it used to be.

🙋‍♂️ Jake's Reality Check

"I don't know what half of these process names even are. How am I supposed to know which one is the bad one?"

You're not, and that's fine. Nobody memorizes 80 process names. The trick isn't recognizing every entry — it's noticing the one you can't explain, and then right-clicking to check where it lives on disk. A legitimate driver process lives in C:\Windows\System32 or a named folder under Program Files. A keylogger dropped by a bad download usually doesn't.

The Same Check on Windows 10

Good news if you're still on Windows 10: these steps are the same on both. Ctrl+Shift+Esc opens the identical Task Manager, and Startup apps lives under the Startup tab rather than a renamed one, but the columns and the logic are unchanged. The one thing worth saying plainly, because it changes how urgently you should act on anything you find: Windows 10 reached the end of free security updates on October 14, 2025. That doesn't mean your PC stopped working — it still boots, activates, and runs Defender definitions — but any new vulnerability that a real keylogger could exploit to reinstall itself after removal no longer gets a free patch unless you're enrolled in Extended Security Updates. If you found something today and you're on unpatched Windows 10, that's a reasonable moment to look at ESU enrollment, not just at removing the file.

🕐 What changed since we first wrote this

  • Then: in May 2017 we were writing about one specific bug — HP laptops shipping the Conexant HD Audio Driver Package (version 1.0.0.46 and earlier) with a hidden debug feature that wrote every keystroke to C:\users\public\MicTray.log in plain text. Affected models included the HP EliteBook 800 series, ProBook 400/600 series, and several ZBook and Elite x2 models.
  • Now: HP and Conexant shipped a fixed driver back in 2017, and that specific file no longer appears on current hardware. What hasn't gone away is the underlying category of risk — audio, webcam, and "smart" peripheral drivers still run with high privileges and still occasionally log more than they should, just under different names on different hardware today.
  • What that means for you: don't search for MicTray.log specifically and call it a day. Use the general checks below, because the next one won't have the same file name.

Six Ways to Check for a Keylogger

Task Manager catches the obvious cases. It doesn't catch everything, so here's the full toolkit, from fastest to most thorough.

1. Task Manager — Processes and Startup apps

Covered above. Fastest, catches most consumer-grade keyloggers and monitoring software because they need to run continuously to capture keystrokes in real time.

2. Autoruns — the free Microsoft tool most people never install

Task Manager only shows you the startup locations Microsoft decided to surface. Autoruns, a free Sysinternals tool (now owned and distributed by Microsoft), shows every single autostart location on the PC — scheduled tasks, browser extensions, services, drivers, Winlogon hooks, the works. Ethan makes every serious PC he works on run this once. "Task Manager is the summary," he told Jake. "Autoruns is the full transcript. If something's hiding, it's hiding somewhere Task Manager doesn't check, and that's exactly where Autoruns looks." Download it, run it as administrator, and scan for anything unsigned with a name you can't place — Autoruns highlights unsigned entries so you don't have to hunt for them manually.

3. Windows Security full scan

Windows 11 and 10 both ship Microsoft Defender under Windows Security, and its definitions are kept current even after Windows 10's mainstream end of support — it's part of what keeps running post-EOL. A Quick Scan checks the usual hiding spots in under a minute; a Full Scan checks every file on the drive and can take an hour or more depending on how much is on there. Run the Full Scan if Quick Scan comes back clean but something still feels off — a well-hidden keylogger sometimes sits outside Quick Scan's default paths.

4. Check known log-file locations by hand

This is the least reliable method on its own, but it's the one that gave this post its origin story, so it's worth explaining honestly. In 2017, the tell was a single plain-text file sitting in a folder every user on the PC could read: C:\users\public\MicTray.log. You could literally open File Explorer, paste that path into the address bar, and if a text file opened, your keystrokes were sitting there in plain sight. That kind of sloppy, un-hidden logging is rare today — anything actively malicious now tries to hide its files or encrypt them — but it's still worth a five-second glance at your Public folder, your Temp folder (%temp% in the Run box), and your Documents folder for any .log or .txt file you don't remember creating.

5. Resource Monitor — watch for outbound traffic

A keylogger that only saves to a local file is a privacy problem for whoever else uses your PC. One that phones the data home is a much bigger problem, and it leaves a trail. Open Resource Monitor (type resmon into the Run box — Win+R opens Run, a small box for typing the name of a program or file to open directly rather than digging through Start) and check the Network tab while you're not actively browsing. A process you don't recognize sending data out steadily, even when you're not touching the keyboard, is worth investigating with the same "where does this live on disk" question from step one.

6. Check for a hardware keylogger, physically

⚠️ What this actually breaks

No amount of software scanning catches a hardware keylogger, because it's a physical device sitting between your keyboard and your PC and it never touches the operating system at all. If you use a shared or public computer — a library, an internet café, a shop's demo PC — and you're going to type a password on it, look at the cable behind the keyboard before you trust it. A small inline adapter that shouldn't be there is the giveaway.

Method Works on Home? Use it when
Task Manager Yes First check, always
Autoruns Yes Task Manager looked clean but you're still uneasy
Windows Security scan Yes Always, alongside Task Manager
Manual log-file check Yes Quick sanity check, not a substitute for the above
Resource Monitor Yes You suspect the data is leaving the PC
Physical cable check Yes Shared or public keyboards only

✅ Why this is the one to use

If you only do two things, do Task Manager plus a Windows Security Full Scan. Between the two, one catches what's currently running and the other catches what's currently sitting dormant on disk waiting to run — together they cover the vast majority of real-world cases without installing anything new.

If the Checks Come Back Clean but Something Still Feels Off

This happens more than you'd think, and it's worth naming honestly rather than pretending every case wraps up neatly. A few real explanations, in order of how often they turn out to be true:

It's your browser, not Windows. A malicious browser extension can log everything you type into a web page without ever touching Task Manager as a separate process — it runs inside Chrome or Edge itself. Check your browser's extensions list, not just your PC's process list, for anything you don't remember installing.

It's legitimate monitoring software someone else installed. Parental control tools and workplace-issued laptops sometimes include keystroke logging as a documented feature, not malware. If this is a work PC, check with IT before assuming the worst — it may be disclosed in a policy you were given and never read.

It already left. Some keyloggers grab a batch of saved passwords once, send them, and remove themselves to avoid detection. A clean scan today doesn't undo something that already happened. If you have any reason to think this occurred, the next move isn't more scanning — it's changing your passwords, starting with email and banking, from a device you're confident is clean.

🙋‍♂️ Jake's Reality Check

"So there's no tool that just tells me 100% for sure, one way or the other?"

No, and I won't pretend there is. Ethan's answer to this one was blunt: "If you want certainty, not confidence, you wipe the drive and reinstall Windows clean. Everything short of that is a strong indication, not a guarantee." That's not a cop-out — it's the honest limit of what a scan run from inside a potentially compromised operating system can tell you.

Removing a Keylogger You've Found

For most cases, letting Windows Security or a reputable antivirus quarantine and remove the flagged item is the right move — it's built to clean up safely, including any registry entries it created. If you've identified a specific process by hand and want to stop it from starting again while you investigate further, end it in Task Manager first (select it on the Processes tab and choose End task), then disable its entry on the Startup apps tab so it doesn't relaunch on the next reboot.

For a stubborn process that keeps restarting itself even after you've disabled its startup entry, advanced users can block a specific executable by name using the Image File Execution Options key in the registry — this tells Windows to hand the named program off to a debugger instead of running it normally, which stops it cold. This is a real Windows mechanism, not a workaround or a hack, but it edits the registry directly and it will block any program with that exact file name, so only use it on a name you've confirmed is the unwanted process, not a guess.

⚠️ What this actually breaks

Registry edits under Image File Execution Options are unforgiving — get the key name wrong and you can end up blocking a legitimate system process instead of the one you meant to stop, which can affect other software or Windows features that share the same file name. Back up the registry key before you touch it, and if you're not confident reading a registry path, stick to Task Manager and Windows Security instead.

To undo it if you got the wrong name, delete the debugger string value you created, or delete the whole named key under Image File Execution Options — the program returns to running normally the moment that entry is gone.

Windows 11 vs. Windows 10: Traps for Upgraders

Beyond the condensed right-click menu already covered, a few other Windows 11 changes trip people up mid-investigation:

Group Policy Editor (gpedit.msc) is Pro/Enterprise/Education only. If you're on Windows 11 Home and a guide tells you to check a Group Policy setting related to logging or auditing, it won't be there — Home edition uses registry edits for anything Group Policy would normally handle. Ethan's take: "Half the 'advanced' guides online assume Pro. If gpedit won't open and just flashes an error, you're on Home, and the answer is almost always a registry key doing the same job."

Control Panel is shrinking, but it's not gone. Most of what you'd want to check — installed programs, network settings, sound devices — has moved into Settings on Windows 11, with Control Panel still there as a fallback for a handful of legacy tools. If a step below says "Settings" and you're more comfortable in Control Panel, it's usually still reachable; just search for it directly rather than hunting through categories.

Edge Cases: Laptops, Shared PCs, and Remote Desktop

Shared family or shop PCs are the highest-risk case in practice, because they're the ones with the most different people installing things over time. Jake runs into this constantly at his phone shop — a customer's laptop comes in "running slow," and the startup list has software from three different people who've used it. Check Startup apps and Autoruns per user account, not just the one you're logged into, since a keylogger installed under one account may not show under another.

Remote Desktop and VM sessions add a wrinkle: a keylogger running on the host machine can capture keystrokes typed inside a remote session, even though the remote session itself looks clean. If you're troubleshooting a remote desktop connection and something feels off, the check needs to happen on the physical device you're typing on, not just the remote one you're connected to.

Tablets and no-keyboard devices aren't immune — a compromised on-screen keyboard or a malicious app with accessibility permissions can log taps the same way a physical keylogger logs keystrokes. The Task Manager and Windows Security checks above apply the same way; just remember to also review app permissions under Settings > Privacy & security > App permissions.

New PC, out of the box. A brand-new machine can still carry pre-installed vendor software with more access than it needs — this is exactly the category the 2017 HP driver fell into. Running the checks in this guide once, right after first setup and before you sign into anything sensitive, costs five minutes and rules out the one scenario you can't blame on your own browsing habits.

Third-Party Anti-Keylogger Tools: Worth It?

Dedicated "anti-keylogger" software falls into two categories, and they solve different problems. The first detects and removes, the same job Windows Security already does. The second encrypts keystrokes at the driver level before a keylogger can read them at all, which is prevention rather than cleanup, and it's the category that actually adds something Windows doesn't do natively.

Approach What it actually does Skip it if
Detection/removal suites Signature and behavior scanning, same job as Windows Security You already run Defender + Autoruns — this is duplicate coverage
Keystroke encryption tools Scrambles input at the driver level so a logger captures noise, not keys You're not regularly typing credentials on a machine you don't control
Browser-isolated password managers Autofills credentials without you typing them, so a logger has nothing to catch Never — this one's worth using regardless

That third row is the one Ethan actually pushes on people, and it's the cheapest fix in this whole post: if a password manager types your password for you, a keylogger records nothing useful even if it's running. "You don't need to outsmart the keylogger," he told Jake. "You just need to stop typing the thing it wants."

Before You Install Anything New: The Privacy Check

The single best prevention isn't a tool — it's a habit. Before installing anything, especially free software from outside the Microsoft Store, check what permissions it asks for during setup and whether it wants to run at startup. A driver update tool that asks for accessibility or input-monitoring permissions it has no obvious reason to need is exactly the pattern that caused the 2017 incident in the first place: legitimate-looking software with more access than its stated job requires.

For Power Users: A Repeatable Check

If you manage more than one PC — a small shop's back office, or a household with a few kids' laptops — running the same checks by hand every time gets old. PowerShell can list every currently running process along with its file path in one command, which gives you the same "where does this live on disk" answer Task Manager gives you, just in a format you can save and compare month to month:

Get-Process | Select-Object Name, Path | Sort-Object Name

Save that output once as a baseline when you know the PC is clean, then run it again whenever something feels off and compare the two. A new, unexplained entry jumps out immediately without you having to remember every process name from scratch.

Frequently Asked Questions

Is the HP MicTray.log keylogger from 2017 still a risk today?

No. HP and Conexant shipped a fixed audio driver in 2017, and that specific file doesn't appear on current hardware or current driver releases. It's documented here as history, not as an active threat.

Can Windows Defender catch every keylogger?

It catches most software keyloggers with known signatures, but nothing catches a brand-new, custom-built one with certainty, and nothing software-based catches a hardware keylogger. Treat a clean scan as a strong signal, not a guarantee.

Why does my antivirus flag a legitimate program as a keylogger?

Some legitimate remote-support and accessibility tools use the same low-level input-monitoring techniques a keylogger uses, so antivirus software sometimes flags them by behavior rather than by knowing they're malicious. If you installed the software yourself and recognize it, this is usually a false positive — but confirm the publisher before allowing it.

Can a keylogger run without showing up in Task Manager?

Rarely, but it happens — some hide by injecting into a legitimate process instead of running as their own visible entry. This is exactly why Autoruns and a full Windows Security scan matter as a second layer beyond Task Manager alone.

Do I need Group Policy Editor to check for a keylogger?

No. Everything in this guide works on Windows 11 and 10 Home, which doesn't include Group Policy Editor. Task Manager, Windows Security, Autoruns, and Resource Monitor are all available on Home edition.

Is a hardware keylogger visible in Device Manager?

No, and that's what makes them dangerous. A hardware keylogger sits physically between the keyboard cable and the PC's USB port and typically does not register as a driver or device, so it's invisible to any software check. Only a visual inspection of the cable catches it.

Should I change my passwords after finding and removing a keylogger?

Yes, from a device you're confident is clean, starting with email and banking. A keylogger can capture a password long before you find it, so removal alone doesn't undo anything it already collected.

Does a factory reset remove a keylogger?

A standard reset that keeps some files can leave certain persistence mechanisms behind. A full reset that removes everything, or a clean reinstall of Windows, is the closest thing to a guarantee available.

Can a browser extension really log everything I type?

Yes, if it has broad page-access permissions. It doesn't need to touch Windows at all — it operates entirely inside the browser, which is why checking your extensions list matters as much as checking Task Manager.

Is it legal for an employer to log my keystrokes on a work laptop?

This varies by employer policy and jurisdiction, and it's genuinely disclosed in some workplace agreements. If you suspect this on a work-issued device, the right move is asking IT or HR directly rather than trying to disable it yourself.

What's the difference between a keylogger and general spyware?

A keylogger specifically records what you type. Spyware is a broader term that can also include screen capture, webcam access, browsing history collection, and file exfiltration. The checks in this guide catch typical keylogger behavior; broader spyware may leave different signs, like unexpected webcam or microphone activity indicators.

Why would a legitimate driver ever log keystrokes at all?

In the 2017 case, the logging was a leftover debugging feature meant to test hardware keys like the mute button, never intended to ship in a consumer release. It's a reminder that not every case is malicious intent — some are sloppy quality control — but the risk to you is the same either way, since the data sat in plain text regardless of why it was collected.

Revision note. Originally published May 12, 2017, about one specific bug: HP's Conexant audio driver quietly logging keystrokes to a plain-text file. HP fixed that driver years ago, so we've rewritten this for the question it's actually still useful for — how to check any Windows 11 or 10 PC for a keylogger today, HP or otherwise. If you found this because something on your PC genuinely worried you, take a breath: the checks above catch almost everything, and most of the time the answer turns out to be nothing at all.

Related