Malware is the scourge of every PC owner. Download the wrong file or click the wrong link and your system is suddenly hijacked. Although common sense practices can prevent most intrusions, antivirus suites like Avira will detect worms and Trojans that slip through. But what happens when malware attacks official drivers?
Recently, owners of Geekom mini PCs (inexpensive portable desktop computers that could become the new standard in computers) discovered that an official driver download contained malware executables. The installation package — designed for the A7, A8, AE7, AE8, AX7 Pro and AX8 Pro — contained the digital signatures of viruses such as Malware.Agentb and Win.Trojan.Asruex.
According to research by VideoCardz.com, this is not the first time that Geekom drivers unintentionally carry a malicious payload. The site claims that reports of these malware-infested drivers date back to December 2024. In fact, according to VideoCardz.com’, the exact same viruses were involved. This really shows you how some viruses persist despite our best efforts to eradicate them. Fortunately, these viruses were only found in downloadable driver packages; malware did not come pre-installed with any of Geekom’s mini PCs.
How this malware infiltrated Geekom driver files
Geekom is not the only example of malware hijacking official software. In 2024, a shipment of AceMagic mini-PCs accidentally contained malware due to an infected system image from the factory, and viruses hitched a ride on official video game files on several occasions. But how were Geekom’s systems infected? Sometimes things slip through the cracks.
When Geekom responded to VideoCardz.com’s story, the company said the affected files came from an “outdated Geekom support page” that had been archived but not deleted. Although users could not access the page through the official Geekom website, it was still visible to – and therefore accessible through – search engines. That’s it. Geekom removed access to the driver package from its own infrastructure, but did not prevent users from trying to find the files outside of its website (which is arguably the most common method of accessing such driver downloads).
Of course, the obvious question most people will ask is why Geekom didn’t clean its library of infected files once the viruses were discovered. Nonetheless, the company is now removing the affected driver packages and promising that it will redouble its efforts to improve its “review and resource management procedures.” Well, better late than never.
What to do if you are infested
A warning that you should not install an official Geekom driver is fine if you don’t already have one installed, but as a general rule, you should always update your computer’s components to the latest drivers. So, if you own a Geekom mini PC, there is a good chance that you have already accidentally infected your computer. But you can mitigate the damage.
If you installed the compromised files, perform a hard reset on your computer. Clear all driver updates (but back up your PC and all your personal files), then reinstall Windows. Instead of downloading drivers directly from Geekom, let each component’s built-in update wizard install the necessary files. The Windows Update app is also a viable alternative, although it should be noted that Geekom claims that there are no problems with the driver package currently available on its website.
After that, verify that you have eliminated the malware and all affected files by running a full antivirus scan. You may want to run the security scan twice: once after reinstalling Windows before updating the drivers, and again after you have completed the updates. If the scans come back without problems, you should be able to safely restore all your personal files.
