GEEKOM mini PC owners warned over malware detections in official driver package

A Reddit user has warned that a GEEKOM driver package contains an executable detected as malware. The file comes from the company’s driver archive for several AMD mini PCs, including the A7, A8, AE7, AE8, AX7 Pro and AX8 Pro. The executable is located inside the LAN driver folder and is named Install_PCIE_Win11_11.10.0720.2022_11222022.exe .
We confirmed the report ourselves. We downloaded the archive directly from GEEKOM, extracted the same file and uploaded it to FileScan.IO, MetaDefender and VirusTotal.

The detections are not limited to one antivirus engine. YARAify identifies the same file and reports ClamAV signatures for Malware.Agentb and two Asruex detections, including Win.Trojan.Asruex. Reports concerning this exact GEEKOM driver package can be traced back to December 2024, when the same hash was already being investigated.





This is also not the first malware-related incident involving mini PCs. In 2024, ACEMAGIC acknowledged that a batch of its systems shipped with a compromised Windows installation containing Bladabindi and Redline malware. The ACEMAGIC case concerned the factory-installed system image, while the GEEKOM case involves a downloadable driver package.
Fresh Mini-PC? Clean Windows install recommended
Our recommendation for mini PCs remains the same. Wipe the included installation and perform a clean Windows installation using Microsoft’s official image. Let Windows Update install drivers where possible, then use drivers directly from AMD, Intel, NVIDIA, Realtek or other component manufacturers when needed rather than relying on bundled OEM driver archives.
Source: VirusTotal , FileScan , MetaDefender