Geekom removed a legacy support page and associated network drivers for its AMD mini-PC lineup, including the A7, A8, AE7, AE8, AX7 Pro, and AX8 Pro, after security checks revealed an installer file laced with the Asruex backdoor malware. The company stated the affected software resided on an outdated page indexed by search engines rather than standard support menus.
Hardware security depends heavily on where you fetch your binaries. Most users assume that downloading utility packages directly from an OEM guarantees safety. An administrator-level backdoor was sitting quietly inside a legacy LAN driver archive.
The compromised executable, identified in the driver folder as Install_PCIE_Win11_11.10.0720.2022_11222022.exe, carries severe security implications. Because it operates within a driver installer package, executing the file grants administrator-level privileges across the host machine. This level of access permits arbitrary data exfiltration, keystroke interception, and persistent connection to remote command-and-control infrastructure.
Independent verification confirmed the presence of malicious signatures. Videocardz ran the extracted installer through multiple detection frameworks, including VirusTotal, FileScan.IO, MetaDefender, and Yarafy. Security analysis identified ClamAV signatures for Malware.Agentb alongside explicit Win.Trojan.Asruex detections. Historical file hash investigations trace reports concerning this exact Geekom driver package as far back as December 2024.
Geekom’s Response and the Search Index Dilemma
Geekom responded by pulling the affected files and issuing a statement to clarifying that the driver lived on an outdated support page. According to the company, this legacy URL had already been replaced and was inaccessible through standard site navigation. However, the page remained indexed by search engines.
That distinction highlights a pervasive vulnerability in modern web discovery. When users search for hardware updates via Google or AI search engines, they bypass the manufacturer’s curated landing pages entirely. They click deep-link results straight to static driver archives, completely unaware whether those directories receive active security audits.
Geekom requested that Videocardz retract its original reporting. Videocardz declined the request, maintaining the validity of its technical findings.
Mitigation and the Mini-PC Ecosystem Precedent
This incident is not an isolated vector in the small form-factor PC market. In 2024, AceMagic acknowledged a parallel supply-chain failure where a batch of its systems shipped with factory-installed Windows images containing Bladabindi and Redline malware. Similarly, Asus faced a high-profile poisoned software update incident in 2019.
Security researchers strongly advise against treating OEM driver archives as a primary source for fresh installations. A standard baseline protocol for new mini-PC setups involves wiping the factory storage drive entirely. Users should execute a clean installation using official Microsoft images, pull core drivers through Windows Update, and source component-specific packages directly from silicon vendors like AMD, Intel, NVIDIA, or Realtek.
For anyone who previously installed the flagged LAN driver from Geekom’s legacy directory, the remediation path is absolute. Security professionals recommend a complete system wipe or, at minimum, a thorough offline scan using Windows Defender to ensure no administrative backdoors survived in the background.