I'm worried I've fallen for a phishing malware, I was in a rush to download irfanview and downloaded a setup from the site below 'Irfanview_Setup.exe'.
When I installed it it just had a blank dialog box with a Next button, I clicked it and loaded something and then nothing else happened...and nothing appeared to have been installed...
I've scanned it with a virus scanner and now my computer but it hasn't found anything. I'm now worried I have something nasty lurking in the background! If anyone can put my mind at rest about this file I'd really appreciate it.
I don't think so, probably a broken downloader. Although the site is labelled bad by WoT (Web of Trust) Irfanview has been around for a long time and I haven't seen warnings about it.
You could run Stinger and Malwarebytes Free perhaps. Both are linked in the last link in my signature below.
Regarding blank interfaces, this can happen if there is jscript corruption.
Try at least step 1 in this FAQ: http://service.mcafee.com/FAQDocument.aspx?lc=1033&id=TS101233
There's an alternate download link here for Irfanview: http://download.cnet.com/IrfanView/ but before trying again run the above and uninstall it if it's showing in your program list.
Message was edited by: Ex_Brit on 24/02/13 4:15:38 EST PM
Thanks for the reply Ex_Brit.
Yes Irfanview is a legit program for sure, I have used it for years. But the website I linked to is not the official website and so my concern is that the file is masquerading as the Irfanview installer but is actually malware.
I'll have a look at your link and see if that helps.
Well I saved it to my desktop despite several warnings from both SiteAdvisor and WoT and although I never installed anything I did scan it with McAfee and Malwarebytes and both came up clean.
The url given is a suspect domain. The whois ownership information is hidden, which is always suspicious.
SiteAdvisor has no information for the site. WOT condemns it, giving plenty of reasons. URLVoid shows it as blacklisted by WOT, hphosts and TrendMicro.
If a download comes from that site you have to watch for whatever comes with it, unbidden.
From WOT :
downloadsumatrapdf.com currently resides on IP: 18.104.22.168 along with:
(a long list of domains, including)
Thank you so much for your help with this, wow, looks like I paid the price for letting my guard down this time! Nightmare.
What worries me is that after "installing" using the setup file, my machine is showing no symptoms, and my up-to-date viirus scanners aren't showing anything in the file or in a full deep scan of the machine... actually worries me more than if it found something that I could then take action against!
What do you think the odds are that this thing is smart enough to remain completely undetected at this point? I'm not sure what to do next!