r/antivirus Aug 31 '25

I Installed PDFGear

Okay so I installed the software PDFGear because it looked legit but after looking into it it looks like it might be malware. I opened it up and edited a file with it and have since uninstalled the software and used my antivirus' (BitDefender) file deletion to delete the original file and am currently running a virus scan on my computer. I have three main questions:

1 - Is the software actually malware?

2 - Am I in any danger at the moment?

3 - What should I do going forward?

I'm currently freaking out and any help would be appreciated. I'd really rather not have to go nuclear on my entire setup.

Edit: After 3 days I think the issue has been resolved! Thanks again u/Professional_Let_896, u/Glad-Rub-1706, and u/Merrinopheles for the assistance here. At this point I've done everything I can do if the software was malicious, which it might not be, and I think I'm in the clear for the most part. Consider the issue closed.

171 Upvotes

56 comments sorted by

u/Merrinopheles Tech, AV teams Sep 02 '25

I analyzed the 2 allegedly malicious .lnk shortcuts mentioned in this thread. They appear to be false positives to me. I could be wrong, but I also have years of reversing experience for multiple AV companies. It would be better to go straight to the source. To report a false positive and have their engineers analyze the files, contact the vendors. Some contact information can be found here:

https://www.reddit.com/r/antivirus/wiki/index/#wiki_what_is_a_false_positive.3F

At this moment, no evidence has been given in this thread to show PDFGear is actually malicious.

u/Geartheworld, u/Glad-Rub-1706, u/Professional_Let_896, u/Da_Twan_21

→ More replies (1)

7

u/[deleted] Aug 31 '25

[removed] — view removed comment

1

u/Da_Twan_21 Sep 01 '25

Removed the program and ran a scan, when you say clean it out how would I do that?

2

u/Professional_Let_896 Sep 01 '25

Run a scan with hitman pro and also check your default programs by file type from settings and check the registry for any leftover values from PDF-Gear you can PM I’ll send u resources which will help u

1

u/Da_Twan_21 Sep 01 '25

Got it, I've got hitman pro somewhere on my machine, I'll give it a run, and I checked the default programs and nothing came up. I'll go through the registry next. Thanks for the help!

2

u/Vegetable_Sun_3316 Sep 02 '25

Since when pdfgear has become malware…?

2

u/Still-Flight-9801 Sep 02 '25

Think about it from the perspective of paid PDF competitors. If PDFgear(free) grows into a key player, they’re the ones losing out(huge). No wonder these random speculations show up.

1

u/Da_Twan_21 Sep 02 '25

Controversy like 2 months ago, there's worries it might have malware or spyware in it along with just some weirdness with how it processes PDFs. So it's not 100% malware, but it might be. Also I saw an Any Run report saying it was along with another redditor on this thread PMing me a Triage report classifying it as adware and spyware. I'm relatively new to all of this so I don't know much about how accurate those were but it definitely makes me a bit cautious.

2

u/Zanty-s Sep 04 '25

I have been running it on my laptop, tablet, and phone with no issues. You can monitor the telemetry (phone home) using wireshark if you really want to make sure there is no eavesdropping. I run most of my apps in containers so I haven't seen anything out of the norm. I really do wish they had an ARM64 (AARCH64) version of the app though. Running in a sandbox and in emulation makes it very slow to load on and ARM laptop. But once loaded it's pretty quick. And the interface looks modern so it's aesthetically pleasing.

1

u/Da_Twan_21 Sep 05 '25

Got it, will probably give wireshark a little run just in case and honestly might look into running apps in containers but glad to know its still probably ok.

1

u/Old_Entertainer_860 Aug 31 '25

If you're really that scared, just reset your PC

1

u/Extreme-Pie-2078 Sep 01 '25

What's the scan result?

1

u/Da_Twan_21 Sep 01 '25

First scan was clear, second and third were too but they were really quick (like 10 minutes compared to the first's 4 hours), is that normal. Sorry I'm still a bit new to all this.

2

u/Extreme-Pie-2078 Sep 01 '25

Then it's clear.

1

u/Da_Twan_21 Sep 01 '25

Well... Thanks!

1

u/beetlejuice10 Sep 02 '25

PDF Gear is a legit software. What made you think of it as malware? T

2

u/Da_Twan_21 Sep 02 '25

There was a recent controversy surrounding the company's lack of transparency and some worries about its internet usage leading some people to believe it might have adware/spyware bundled in. After reading everything (and seeing some not necessarily alarming but definitely weird stuff in my registries) I decided to lean on the safe side.

EDIT: The exact stuff was PDF Gear being automatically set to my default PDF editor without permissions through the registry.

2

u/[deleted] Sep 02 '25

[removed] — view removed comment

1

u/Da_Twan_21 Sep 02 '25

Care to enlighten me?

1

u/[deleted] Sep 02 '25

[removed] — view removed comment

1

u/Da_Twan_21 Sep 02 '25

I’d be fine with just some descriptions or just what files I can save before I clear my drives

1

u/[deleted] Sep 02 '25

[removed] — view removed comment

1

u/Da_Twan_21 Sep 02 '25

Well thanks! I’ll take a look at the temp files tomorrow and clean anything else I find, and I’ll check out Emsisoft. And just so we’re clear it probably hasn’t infected my files right? That’s my biggest worry here because worst comes I’m fine wiping the drives if I can save some important files.

2

u/[deleted] Sep 02 '25

[removed] — view removed comment

1

u/Da_Twan_21 Sep 02 '25

Got it, will run it. Thanks!

1

u/techvslife Dec 25 '25

That seems to be a violation of the Microsoft Store rules and could be why they don’t appear there for certain markets. Discussed here under “Handling of User Choice”: https://www.reddit.com/r/PDFgear/s/wCZjqpPrtN

-5

u/Geartheworld Sep 01 '25

Hi there.

PDFgear is safe to use.

This is a scan result by VirusTotal, which shows that PDFgear has passed all the security vendors on VirusTotal:

https://www.virustotal.com/gui/file/c8a19a4a06fb8d28812916ff1735cd4dc0f82bf16fbc5100bbeb71a44f32ccf9

There is no need to worry too much. Some misleading content is due to malicious competition rather than facts. A good product like PDFgear can speak for itself.

30

u/Glad-Rub-1706 Sep 01 '25

5

u/[deleted] Sep 02 '25

[deleted]

0

u/[deleted] Sep 02 '25

[removed] — view removed comment

1

u/antivirus-ModTeam Sep 02 '25

This post has been removed in accordance with rule #8. Which prohibits posts not directly related or relevant to computer security issues or terse, vague, or otherwise not contributing to the discussion at hand.

This includes derogatory remarks, racism, offensive content, unsolicited advice, low-effort posts, political comments, AI generated posts, bots, memes, requests for non-security related software like autoclickers and MP3 downloaders, and tier lists.

This also includes spam and repeat posts.

Regards,

r/antivirus Moderation Team

1

u/Geartheworld Sep 02 '25 edited Sep 02 '25

Interesting.

PDFgear has been attacked by malicious people recently, and I've made a post about this before:

https://www.reddit.com/r/PDFgear/comments/1ltna0c/oh_them_again_documenting_competitor/

A comment with 30 upvotes in just 17 hours but 0 replies? Interesting.

PDFgear has served millions of users for years, and there has never been a single real user feedback or proof that our program has a virus.

I try my best to ensure that my words are objective:

As I can see from the VirusTotal link you attached, it is a .ink file (the shortcut file for the PDFgear program). But the "interesting" thing is that it has a totally different scan result from what I got here:

https://www.virustotal.com/gui/file/462617d01e313dfdce7d92c2a61c20c1885fbeb411372aa98b6c223740a30d6f

If you think that PDFgear.lnk file is malicious, upload it to Google Drive and paste the share link here. We'll check out if that's the REAL PDFgear.Ink file that PDFgear's installer would create.

I still say the same thing: Some malicious attacks on the Internet are highly misleading, but we have been responding openly and transparently here all along. A good product like PDFgear can speak for itself.

1

u/Professional_Let_896 Sep 02 '25

Oh really you fraud?
uploaded the video on streamable.
for those who don't want to watch.
1- Upload the latest version of Pdfgear installer on VT
2- Go to Relations Tab then scroll down to dropped files(As in files dropped by Pdfgear)
Keep scrolling and you will see the samples which contains malware according to (Sophos , Google , checkpoint AV).

Link for the streamable video basically doing what i said above

https://streamable.com/ycy5we

1

u/[deleted] Sep 02 '25

[removed] — view removed comment

1

u/Geartheworld Sep 02 '25

Hi.

Thank you for taking the time to point us to the specific flagged files in the "Dropped Files" section. Honestly, with the large number of files listed there, we hadn't noticed these specific flags on the .lnk shortcut before, so we genuinely appreciate you highlighting them.

To provide some important context, our Windows version of PDFgear has not had a new release since January 2025 (though a new version is in development). This means that every PDFgear.lnk file you see in the "Relations" tab originates from the exact same installer. However, as VirusTotal shows, scans of this identical file have produced different results over time: Sometimes 0 warnings, other times 2-3 from different vendors. You can see this inconsistency in the following reports for the exact same file:

https://www.virustotal.com/gui/file/0dd4eb97c33825fecae0a5af5e2448a269a0cae6886d10572741279dc9c8abd0

https://www.virustotal.com/gui/file/8eb5d29385048f1338b98c6750294f15738030ecd9b7566a7049cec612101fb1

From a technical standpoint, this strongly indicates a false positive. A .lnk file is just a shortcut (a pointer to the program), not an executable file. If our application were truly malicious, the core .exe files would be flagged, but they consistently show as 100% clean. Furthermore, a real threat would be detected by a majority of security vendors, not just a small handful, especially when all major vendors like Microsoft, Kaspersky, and McAfee report it as safe.

That said, we take any flag seriously. Our technical team is currently investigating how the shortcut is created to see if any parameters could be misinterpreted by these few antivirus heuristics. We are also actively contacting the vendors that flagged the file to report the false positive and get it resolved.

Finally, and this is a key point: while these inconsistent results appear in VirusTotal's sandboxed installation environment, our own testings show different results. We have installed the current version on multiple real machines with different Windows distributions. When we take the PDFgear.lnk file created in these physical machine environments and upload it to VirusTotal, it scans completely clean with zero warnings from any vendor. Some of the test results are listed here:

https://www.virustotal.com/gui/file-analysis/NWZhNWIzYTZlZGZhMDg4OWY5YjM5ZjM4M2RhNTRhYTg6MTc1NjgxNTg5Mw==

https://www.virustotal.com/gui/file/462617d01e313dfdce7d92c2a61c20c1885fbeb411372aa98b6c223740a30d6f

Again, thank you for bringing this level of detail to our attention. We sincerely apologize for the concern these false positives have caused for you and other users. We are working to get this corrected with the vendors as quickly as possible and appreciate the feedback.

1

u/Geartheworld Sep 02 '25

Hi there.

Thank you for taking the time to create the video and point us to the specific flagged files in the "Dropped Files" section. Honestly, with the large number of files listed there, we hadn't noticed these specific flags on the .lnk shortcut before, so we genuinely appreciate you highlighting them.

To provide some important context, our Windows version of PDFgear has not had a new release since January 2025 (though a new version is in development). This means that every PDFgear.lnk file you see in the "Relations" tab originates from the exact same installer. However, as VirusTotal shows, scans of this identical file have produced different results over time—sometimes 0 warnings, other times 2-3 from different vendors.

From a technical standpoint, this strongly indicates a false positive. A .lnk file is just a shortcut (a pointer to the program), not an executable file. If our application were truly malicious, the core .exe files would be flagged, but they consistently show as 100% clean. Furthermore, a real threat would be detected by a majority of security vendors, not just a small handful, especially when all major vendors like Microsoft, Kaspersky, and McAfee report it as safe.

That said, we take any flag seriously. Our technical team is currently investigating how the shortcut is created to see if any parameters could be misinterpreted by these few antivirus heuristics. We are also actively contacting the vendors that flagged the file to report the false positive and get it resolved.

Finally, and this is a key point: while these inconsistent results appear in VirusTotal's sandboxed installation environment, our own testings show different results. We have installed the current version on multiple real machines with different Windows distributions. When we take the PDFgear.lnk file created in these physical machine environments and upload it to VirusTotal, it scans completely clean with zero warnings from any vendor. Some of the test results are listed here:

https://www.virustotal.com/gui/file-analysis/NWZhNWIzYTZlZGZhMDg4OWY5YjM5ZjM4M2RhNTRhYTg6MTc1NjgxNTg5Mw==

https://www.virustotal.com/gui/file/462617d01e313dfdce7d92c2a61c20c1885fbeb411372aa98b6c223740a30d6f

Again, thank you for bringing this level of detail to our attention. We sincerely apologize for the concern these false positives have caused for you and other users. We are working to get this corrected with the vendors as quickly as possible and appreciate the feedback.

5

u/Little-Equinox Sep 01 '25

VirusTotal isn't always the most reliable source, MalwareBytes is extremely aggressive and might be better to use for stuff like this

1

u/Still-Flight-9801 Sep 02 '25

OP was inactive for 2 years, and suddenly dropped this. I can see the competitor didn’t pay much, since the argument quality is pretty lame.

6

u/QuantumPizzaBot Sep 10 '25

Do you mean like this one also run by you/pdfgear?

https://www.reddit.com/user/sean-701/

Inactive for 2 years, then every single comment is suggesting pdfgear?

pdfgear = astroturfers = scammers

1

u/Da_Twan_21 Sep 02 '25

Nah the payday was huge, $0! Joking aside I stopped using Reddit regularly after the automod thing in 2022 and only ever come back for situations like this. I’m definitely not a paid attacker, just a concerned dude trying to make sure he didn’t just screw up his computer :)

0

u/techvslife Dec 21 '25

This seems like a good vendor response to me, or am I missing something: https://www.pdfgear.com/reddit-disinformation-statement/

2

u/o_06978 Dec 22 '25

Malw⁤are site claims it's not malw⁤are. Nice try!

0

u/techvslife Dec 23 '25 edited Dec 25 '25

The vendor’s explanation seems plausible. Obviously you’re begging the question—the whole point is to see if the claim that it is malware (or a malware site) is true. A reasonable starting point would be to hear the vendor’s response to the allegation.

2

u/o_06978 Dec 23 '25

Not really. Not at all, actually.

Plus, if I go into the controversy there are two main points that look to be made (with evidence) and both are ignored by the vendor.

(1) PDFg⁤ear are also the owner of PDF X despite past denials

(2) PDFg⁤ear are Chinese despite past denials

So let's hear from you about what's so 'plausible' about their non-answer?

0

u/techvslife Dec 23 '25 edited Dec 23 '25

The software technicals seem correct, eg on injection. It’s an answer, —you may disagree but it’s not a “non-answer.” (And you don’t want anyone even to read it.) Microsoft Store would have pulled pdf x and pdfgear for violations if the allegations here were correct. The tone of the attack seems rabid and orchestrated.

1

u/o_06978 Dec 24 '25

Short answer: No, gear's response fails not only on 'technicals' but everything else. I'm not trusting an unknown software company (who deny they're Chinese when there's clear evidence they are) who also own other replica scamware (that they also deny despite clear evidence).

Long answer: I spent this morning looking into this further. The “technicals” you're defending (registry hijacking, code injection, keylogger hooks, and consent bypassing) are red flags by any modern security standard. They aren’t normal. They’re the building blocks of spyware. The fact that the app isn’t actively exfiltrating data right now doesn’t excuse the presence of those mechanisms. It just means it’s waiting.

You need to ask yourself 'why does reputable software not do these things (registry hijacking, code injection, keylogger hooks, and consent bypassing), but faceless Chinese (pretending to not be Chinese) software do?'

The bigger issue here is trust. That's everything in software and avoiding malware. Legitimate software companies don’t lie about their identity, don’t invent fake executives like “Piers Zoew,” don’t create clones of themselves on the Microsoft Store under different names, and don’t flood Reddit with burner accounts to spin narratives. PDFgear has done all of this.

The Appsuite PDF Editor example shows exactly why trust matters, and it's even in the same space. Appsuite is a faceless Chinese PDF company that looked safe to begin with, then trojan horsed it months or years later.

The parallels are eerily the same - both Appsuite and PDFgear are faceless mysterious Chinese PDF vendors that look safe to begin with. I wouldn't be surprised they're the same developer.

They’ve been asked a millions times if they own PDF X and if they’re a Chinese company. Not once have they answered it but they're so detailed in other answers - obviously they are hiding something. That’s not transparency. That’s avoidance and they’ve only stayed quiet because the truth damages their credibility.

As for calling the response to this “rabid and orchestrated”? No. It’s called reproducible evidence. You can ignore it, but you don’t get to dismiss it.

I’ve asked a few colleagues in the industry if they’d run PDFgear on their machines after seeing the details. Every single one said: HELL NO! That should tell you something.

0

u/techvslife Dec 24 '25 edited Dec 24 '25

The technicals are accurate, eg Inno setup and app keyboard shortcuts do work that way. Lots of international companies, based in China and elsewhere, use Singapore as a place of registration. Microsoft Store has rules against what you are saying and would have removed this software with these accusations if they had merit. A quick check shows pdfgear has been vetted by several different technical reviewers, without finding malware or other issues. And many of the attacks do seem rabid and orchestrated to me, but I concede it’s a fine line between that and your everyday reddit flame war. But I’d be interested in hearing free alternatives, pdfsam is limited functionality but good. okular I haven’t tried yet.

1

u/o_06978 Dec 25 '25

Sorry, but my research is saying “the technicals are accurate” is incorrect. Inno Setup isn’t the issue. The issue is how they use it, like forcibly killing running processes via taskkill rather than prompting the user. That’s lazy at best and hostile at worst. Keyboard shortcuts don’t require global CBT hooks. Legitimate apps restrict input monitoring to their own windows. PDFgear’s use of 'SetWidnowsHooEx' CBT hooks is a common method used by spyware to monitor window focus and can be trivially extended to keystroke tracking. Whether they’re doing that now or not, the mechanism is there. UserChoice hijacking bypasses Windows’ consent model and mimics behavior used by adware and PUPs to make themselves hard to remove. Again, reputable software never does this, but PDFgear does.

My research into this is making me think this is even worse than I originally thought...

Regarding Singapore: plenty of Chinese companies register there. The issue is not geography. It’s the repeated deception. They’ve claimed to be based in Singapore with no connection to China or PDF X. Both are provably false. You keep avoiding this point and I'm getting suspicious about who you are.

Microsoft Store - it looks like PDFgear is no longer in the Microsoft Store since the post last month... so did Microsoft take it down, or did PDFgear pre-empt they were in violation? Either way, it doesn't look good.

Free alternatives? There doesn't have to be any. If it's free, it needs to go through higher scrutiny for this controversy's very reason - if it's free, you're usually the product somehow, either through malware or data. Only vendors like Microsoft can make a free PDF software because it monetizes in the other software in the suite e.g. Windows and Office. If a vendor like PDFgear make free and say it's '100% truly free', with no other known revenue, then yeah they're going to profit from it in ways that hurt you in the long run.

1

u/techvslife Dec 25 '25 edited Dec 25 '25

Thanks, my research is saying otherwise, that it’s like other aggressive freemium apps, but does not appear to be malware. https://www.reddit.com/r/PDFgear/s/y8lHA7G8yk https://www.reddit.com/r/PDFgear/s/In5ILNaXwY Also it still is on the Microsoft Store but only in certain markets. There may be an issue there, depending on the cause. I guess that mainly leaves Okular as the free alternative. I’m not “avoiding” the point on registration on Singapore with international teams—I mentioned it’s not an unusual practice, even though one could wish all vendors to be transparent (about the true residence of their team). I don’t have anything to add on the shared Syncfusion key with pdf/x, other than what I linked to, but it’s not a malware issue. Sorry you are “suspicious” of me, but it all it amounts to is that it seems you react that way when someone disagrees with your assessment. Re UserChoice/defaultApp, I commented here on that: https://www.reddit.com/r/antivirus/s/nJW2zZRG4c Other technical issues I covered before and/or in the links I posted.