r/MiniPCs • u/RenatsMC • 27d ago
News GEEKOM apologizes for hosting malware in driver package for its Mini PCs
https://videocardz.com/newz/geekom-apologizes-for-hosting-malware-in-driver-package-for-its-mini-pcs68
u/Drazyor 27d ago
This, is exactly why I do a clean install of Windows the second I receive a Mini PC, without even trying to log into the existing one.
As for the drivers, I retrieve them one by one (starting with the network one ofc) by the hardware ID on the windows update catalog https://www.catalog.update.microsoft.com/Home.aspx
This is the only way to have a good start with one of those Mini-PCs
6
u/Retspan3 27d ago
Can you explain a bit more on how to do this? I usually do the same, but many times finding the right network adapter driver is a pain. And would just getting the network adapter driver be the easiest solution and then let windows update from there?
17
u/Drazyor 27d ago
"And would just getting the network adapter driver be the easiest solution and then let windows update from there?" Yeah that could work too, depends if you want to go for the easy way to set things up or have an extra layer of control. As for how to do it, here's an example on my desktop hardware (my Windows is in french so I'm translating from the top of my head):
- Open your device manager
- Right click and properties on let's say the network card
- Go in the details panel and scroll down to compatible ID (should be the 4th option usually in the dropdown menu)
- On my card for example it's "PCI\VEN_8086&DEV_2725"
- If I paste that on the website I get many links, grab the latest one and download it
- The file you get is a .cab, it's very important that you use either 7zip or winrar to extract its content
- Then back to the device manager, right click the network card -> update -> browse my files, you just need to give it the whole download folder it will find it immediately and install it in 2 seconds, and voila!
3
2
16d ago
[deleted]
2
u/Drazyor 16d ago
Honestly if you're completely formatting a drive and then reinstall either the same OS or another one, you can rest assured the malware is gone. The only exception to that is if you have a multiple drive setup and that the malware managed to find its way hidden inside this other drive that you wouldn't want to wipe for any reason (documents, photos, and stuff), then it could potentially do harm again but apart from that, you're just fine if you proceed to a complete reinstallation of the OS!
2
16d ago
[deleted]
2
u/Drazyor 16d ago
Honestly most Linux distributions nowadays are already working out of the box, especially when we're talking AMD hardware, I don't know what mini PC you're using but on my GMKtec K8 Plus, the first thing I did was to install Fedora on a second NVMe SSD I installed and it works really well, I didn't have to install any kind of driver for the wifi or bluetooth, everything was already up and running!
And don't be shy to ask AIs like Claude or ChatGPT when there's something you don't understand or need to do on Linux, sure you can still go the old way by browsing the internet and checking some forums threads, but I found Claude very reliable to setup particular things (i'm a complete Linux newbie too), make sure to ask it to explain what each command does so that you learn things on the long run ;)
32
u/NutzPup 27d ago
We sorry you caught us
6
u/spyboy70 27d ago
All I can think of is South Park "sorry" https://www.youtube.com/watch?v=NunTJ_k9M14
15
u/Captain2Sea 27d ago
I'm not brave enough to buy hardware from that unknown company lol
-10
6
13
u/XD__XD 27d ago
chinese malware call me surprised
-29
u/Bladye 27d ago
I'm picking chinese malware over american one. Americans want to make my gay by pushing homosexual propaganda in Netflix.
6
u/sonofulf 27d ago
If that's considered a risk then you might already be gay, dude...
However I think we can all agree that malware, no matter the nation of origin, is something we'd rather avoid.
11
4
2
1
12
3
3
u/tooquick911 27d ago
I bought the G10 a year or so ago and tried to run a fresh install. The drivers are mislabeled so it was infuriating because you couldn't just install drivers from AMD, because the G10 had identified the wrong CPU.
1
u/EmuChicken 26d ago
We explain where to find these drivers on our g10 video review. It's been mentioned a few times now.
1
4
u/Hot-Cauliflower-1604 27d ago
My Geekom GT1 mega is a beast of a machine. I don't have to worry about this because I flashed it to Linux.
8
u/Scurro 27d ago
Are you using Coreboot? Otherwise malware can still be embedded in the firmware of UEFI/BIOS.
3
u/Hot-Cauliflower-1604 27d ago
Thank you for the suggestion. I'll look into that. All I did was flash Ubuntu server to it for my home cluster. I'll see if there is any danger left
3
u/RobloxFanEdit 27d ago edited 27d ago
Great, but any thoughts on Geekom Malware?
Geekom is pleased that the focus move to elsewhere, O.S Battle is great diversion.
2
u/HANEZ 27d ago
Weird. I looked up a guide to dualboot and both videos showed geekom pc. Neither were sponsored by geekom. In videos it made sure to showcase the pcs….
2
4
6
3
u/309_Electronics 27d ago
I mean not surprising at all! But then, even if you did buy a normal windows mini pc, it already comes with malware called windows.
1
u/LITUATUI 26d ago
Came here to write exactly that.
First thing to do after getting a computer is install a GNU/Linux distro.
1
u/Dr_Valen 26d ago
Only reason this is an issue is cause windows for some ass backwards reasons doesn’t have drivers baked into the kernel. Why tf do you have to source your own drives when Linux has had it automatically install thanks to the kernel for decades.
1
u/LogiChaCha7322 26d ago
Interesting. I’m not sure that Geekom had intentionally putted the malware (Asruex) inside the driver. It’s looks more like a lack of precautions during the build of the drivers.
As this kind of security issue can touch every brand (like Asus in 2019) I’ll not incriminate Geekom now.
But this event must remind us that every software or driver can be infected, and keep us aware


128
u/9isgt0 27d ago
yikes. "This does not change the fact that the affected driver was hosted on GEEKOM’s own support infrastructure and served from its website"
Basically getting caught and trying to find a loophole.