A malware flagged executable was found in Geekom’s official LAN driver archive for six AMD mini PCs on August 15, 2026. The file was named Install PCIE Win11 11.10.0720.2022 11222022.exe; VirusTotal, MetaDefender, FileScan.IO, and YARAify were among the tools used to analyze it, with reported signatures including Ma...
Research answer

Create a landscape editorial hero image for this Studio Global article: What happened when malware was discovered in Geekom’s official driver archive in August 2026—including who first reported it, the exact LAN. Article summary: A Reddit user first flagged the issue, and VideoCardz independently verified it by downloading the archive from Geekom’s site on August 15. The shared AMD mini-PC LAN package contained an executable widely flagged as mal. Topic tags: general, general web. Style: premium digital editorial illustration, source-backed research mood, clean composition, high detail, modern web publication hero. Use reference image context only for broad subject, composition, and topical grounding; do not copy the exact image. Avoid: logos, brand marks, copyrighted characters, real person likenesses, fake screenshots, UI text, readable text, watermarks, charts with fake numbers, click
A Reddit user first raised the alarm about a Geekom driver archive. VideoCardz independently downloaded the package from Geekom’s website on August 15, 2026, and found the same executable inside it. Geekom later acknowledged that the file had been hosted on its support infrastructure, apologized, and removed the affected legacy resources.
The available evidence supports treating the installer as unsafe, but it does not establish that Geekom deliberately distributed malware, how the file reached the company’s servers, how many people ran it, or what it did on victims’ systems.
The executable was named:
Install_PCIE_Win11_11.10.0720.2022_11222022.exe
It was located in the LAN-driver folder of a shared archive intended for six AMD-based Geekom mini PC families:
The archive was not simply flagged by one antivirus product. VideoCardz checked the file with FileScan.IO, MetaDefender, and VirusTotal, while YARAify reported ClamAV detections including Malware.Agentb and two Asruex-related signatures, one labeled Win.Trojan.Asruex. Reports associated with the same file hash dated back to December 2024.
Multiple detections are enough reason not to execute the installer, although scanner results alone do not prove the file’s complete behavior or rule out every possibility of a false positive. The available reporting did not establish a victim count or provide a full technical analysis of what happened after execution.
A driver installer typically needs administrator-level permissions. If the flagged executable were malicious, that level of access could allow code to make privileged system changes and potentially expose data or install additional components. Tom’s Hardware specifically warned that malware embedded in a driver installer could receive administrator-level permissions.
That is a risk assessment, not evidence that this particular file carried out every possible action. Users should therefore avoid testing it themselves, even on a spare system.
Geekom said the installer remained available on an outdated support page after the company replaced its older support system with a newer one. Although the page was no longer part of the site’s normal navigation, the legacy resource remained reachable through links indexed by search engines.
The company said its review found no comparable anomaly on the current driver pages. It also said the issue did not affect Geekom hardware or the Windows operating system pre-installed on its mini PCs. Geekom said it was removing the legacy files and pages and tightening its resource-management and review procedures.
Geekom also asked VideoCardz to consider removing its original report. VideoCardz declined, arguing that its central claim was correct: the file had been downloadable from Geekom’s own infrastructure and the company had confirmed that fact.
One important question remains unanswered: Geekom has not explained how the malware-flagged executable entered the archive or remained available on its servers. The company’s legacy-page explanation describes why the file was still reachable, but not its original provenance.
If you have downloaded the archive or still have the installer, Geekom’s guidance is straightforward:
The safest distinction is between downloading the archive and executing the installer. A downloaded file can be removed without proving that the system was compromised; execution is the event that could have granted the installer elevated access.
The Geekom case concerns a downloadable executable inside a legacy LAN-driver archive. It is not the same as an incident involving malware in a factory-installed Windows image: the available reporting specifically says Geekom’s pre-installed operating system was not affected.
That difference matters for assessing exposure. Geekom users who never downloaded or ran the old driver installer were not shown by the supplied reporting to have received the flagged file through the machine’s pre-installed Windows environment. Users who did execute it should take the stronger scanning and reinstall precautions above.
Studio Global AI
This page includes a source-backed answer you can continue inside Studio Global.
A malware flagged executable was found in Geekom’s official LAN driver archive for six AMD mini PCs on August 15, 2026.
A malware flagged executable was found in Geekom’s official LAN driver archive for six AMD mini PCs on August 15, 2026. The file was named Install PCIE Win11 11.10.0720.2022 11222022.exe; VirusTotal, MetaDefender, FileScan.IO, and YARAify were among the tools used to analyze it, with reported signatures including Malware.Agentb and Win...
Anyone who downloaded or ran the installer should delete it, scan the computer, and obtain the network driver from Windows Update, Realtek, or Geekom’s current support pages.