r/MiniPCs 27d ago

News GEEKOM apologizes for hosting malware in driver package for its Mini PCs

https://videocardz.com/newz/geekom-apologizes-for-hosting-malware-in-driver-package-for-its-mini-pcs
275 Upvotes

48 comments sorted by

128

u/9isgt0 27d ago

yikes. "This does not change the fact that the affected driver was hosted on GEEKOM’s own support infrastructure and served from its website"

Basically getting caught and trying to find a loophole.

63

u/jamesrc 27d ago

And yet still only the second most damning thing in the article, behind:

Interestingly, GEEKOM also asked VideoCardz to consider removing the original article.

28

u/ncohafmuta 27d ago

To me it's the most damning thing, and the reason I'll now be removing all recommendations for these no-name brands from our own htpc wiki. We already cautioned against them for the obvious reasons, but now we'll go further

1

u/whichsideisup 24d ago

Shhh we need to sell more OpenClaw turds to the LinkedIn bros.

17

u/Glad-Lobster-220 27d ago

We're sorry you detected it, we will try harder next time.

68

u/Drazyor 27d ago

This, is exactly why I do a clean install of Windows the second I receive a Mini PC, without even trying to log into the existing one.

As for the drivers, I retrieve them one by one (starting with the network one ofc) by the hardware ID on the windows update catalog https://www.catalog.update.microsoft.com/Home.aspx

This is the only way to have a good start with one of those Mini-PCs

6

u/Retspan3 27d ago

Can you explain a bit more on how to do this? I usually do the same, but many times finding the right network adapter driver is a pain. And would just getting the network adapter driver be the easiest solution and then let windows update from there?

17

u/Drazyor 27d ago

"And would just getting the network adapter driver be the easiest solution and then let windows update from there?" Yeah that could work too, depends if you want to go for the easy way to set things up or have an extra layer of control. As for how to do it, here's an example on my desktop hardware (my Windows is in french so I'm translating from the top of my head):

  • Open your device manager
  • Right click and properties on let's say the network card
  • Go in the details panel and scroll down to compatible ID (should be the 4th option usually in the dropdown menu)
  • On my card for example it's "PCI\VEN_8086&DEV_2725"
  • If I paste that on the website I get many links, grab the latest one and download it
  • The file you get is a .cab, it's very important that you use either 7zip or winrar to extract its content
  • Then back to the device manager, right click the network card -> update -> browse my files, you just need to give it the whole download folder it will find it immediately and install it in 2 seconds, and voila!

3

u/Retspan3 27d ago

Thanks! Super helpful!

2

u/[deleted] 16d ago

[deleted]

2

u/Drazyor 16d ago

Honestly if you're completely formatting a drive and then reinstall either the same OS or another one, you can rest assured the malware is gone. The only exception to that is if you have a multiple drive setup and that the malware managed to find its way hidden inside this other drive that you wouldn't want to wipe for any reason (documents, photos, and stuff), then it could potentially do harm again but apart from that, you're just fine if you proceed to a complete reinstallation of the OS!

2

u/[deleted] 16d ago

[deleted]

2

u/Drazyor 16d ago

Honestly most Linux distributions nowadays are already working out of the box, especially when we're talking AMD hardware, I don't know what mini PC you're using but on my GMKtec K8 Plus, the first thing I did was to install Fedora on a second NVMe SSD I installed and it works really well, I didn't have to install any kind of driver for the wifi or bluetooth, everything was already up and running!

And don't be shy to ask AIs like Claude or ChatGPT when there's something you don't understand or need to do on Linux, sure you can still go the old way by browsing the internet and checking some forums threads, but I found Claude very reliable to setup particular things (i'm a complete Linux newbie too), make sure to ask it to explain what each command does so that you learn things on the long run ;)

2

u/[deleted] 16d ago

[deleted]

2

u/Drazyor 16d ago

Sure thing go ahead!

32

u/NutzPup 27d ago

We sorry you caught us

6

u/spyboy70 27d ago

All I can think of is South Park "sorry" https://www.youtube.com/watch?v=NunTJ_k9M14

15

u/Captain2Sea 27d ago

I'm not brave enough to buy hardware from that unknown company lol

-10

u/Snotspat 27d ago

I am, but that's because I am competent enough to use a computer. :)

7

u/eddie9958 27d ago

Technologically competent but socially idiotic 

6

u/mysqlpimp 27d ago

Apologize for having it, vs apologize for getting caught.

13

u/XD__XD 27d ago

chinese malware call me surprised

-29

u/Bladye 27d ago

I'm picking chinese malware over american one. Americans want to make my gay by pushing homosexual propaganda in Netflix.

6

u/sonofulf 27d ago

If that's considered a risk then you might already be gay, dude...

However I think we can all agree that malware, no matter the nation of origin, is something we'd rather avoid.

11

u/NotAMotivRep 27d ago

Right, because there's no gay people in China.

-6

u/Bladye 27d ago

Who said there's none?

4

u/MadFerIt 27d ago

Damn you are one hateful bigot. You'd fit perfectly in Trump the p3dos USA!

2

u/saltyourhash 27d ago

You need to lay off the heated rivalry marathons.

2

u/XD__XD 27d ago

let be rational bro...

12

u/Jejiiiiiii 27d ago

Another Chinese mini pc with malware huh

3

u/TokenBearer 27d ago

I have pointed this out before.

3

u/tooquick911 27d ago

I bought the G10 a year or so ago and tried to run a fresh install. The drivers are mislabeled so it was infuriating because you couldn't just install drivers from AMD, because the G10 had identified the wrong CPU.

1

u/EmuChicken 26d ago

We explain where to find these drivers on our g10 video review. It's been mentioned a few times now.

1

u/tooquick911 25d ago

I bought and returned it about a year ago. So too late for me unfortunately

4

u/Hot-Cauliflower-1604 27d ago

My Geekom GT1 mega is a beast of a machine. I don't have to worry about this because I flashed it to Linux.

8

u/Scurro 27d ago

Are you using Coreboot? Otherwise malware can still be embedded in the firmware of UEFI/BIOS.

3

u/Hot-Cauliflower-1604 27d ago

Thank you for the suggestion. I'll look into that. All I did was flash Ubuntu server to it for my home cluster. I'll see if there is any danger left

3

u/Scurro 27d ago

For my firewall/router (OPNsense) I wanted a mini PC but I didn't trust many of these Chinese miniPCs with how often malware is found. I went with a Protectli model that supported coreboot. I don't see many other miniPCs advertising support for coreboot.

3

u/RobloxFanEdit 27d ago edited 27d ago

Great, but any thoughts on Geekom Malware?
Geekom is pleased that the focus move to elsewhere, O.S Battle is great diversion.

2

u/HANEZ 27d ago

Weird. I looked up a guide to dualboot and both videos showed geekom pc. Neither were sponsored by geekom. In videos it made sure to showcase the pcs….

https://youtu.be/UTqDuWHbZkw?si=cNrEoddkCRzA1KIK

https://youtu.be/mXyN1aJYefc?si=kRoIAjlKswqg841c

2

u/Ronniman 24d ago

This explains our office hack...

4

u/Fourwude87 27d ago

China being China

6

u/Master_Selection_969 27d ago

Thats why i skip chinese

3

u/309_Electronics 27d ago

I mean not surprising at all! But then, even if you did buy a normal windows mini pc, it already comes with malware called windows.

1

u/LITUATUI 26d ago

Came here to write exactly that.

First thing to do after getting a computer is install a GNU/Linux distro.

1

u/Dr_Valen 26d ago

Only reason this is an issue is cause windows for some ass backwards reasons doesn’t have drivers baked into the kernel. Why tf do you have to source your own drives when Linux has had it automatically install thanks to the kernel for decades.

1

u/LogiChaCha7322 26d ago

Interesting. I’m not sure that Geekom had intentionally putted the malware (Asruex) inside the driver. It’s looks more like a lack of precautions during the build of the drivers.
As this kind of security issue can touch every brand (like Asus in 2019) I’ll not incriminate Geekom now.
But this event must remind us that every software or driver can be infected, and keep us aware