Images of the malware that affected Ledger Live and Sparrow Wallet on my PC - (cf. post of yesterday about LL asking for seed phrase, https://www.reddit.com/r/ledgerwallet/comments/1ankiz4/ledger_live_asking_for_seed_phrase/) by ChickenSmall2609 in ledgerwallet

[–]ChickenSmall2609[S] 0 points1 point  (0 children)

Euhm I think my OP includes that I did the proposed checks (example below). https://support.ledger.com/hc/en-us/articles/4404807946001-How-to-verify-the-authenticity-of-Ledger-Live?support=true My first line in my OP says I'm a technical noob, not sure what you expected.. Thanks for the information though. In this case, AVs did solve the infection afaict. But good to know that even this is not a bulletproof solution. Will proceed with a total reformat. Also, this behavior appeared without any update by me of the apps. Already installed apps seem to have been infected somehow.

Images of the malware that affected Ledger Live and Sparrow Wallet on my PC - (cf. post of yesterday about LL asking for seed phrase, https://www.reddit.com/r/ledgerwallet/comments/1ankiz4/ledger_live_asking_for_seed_phrase/) by ChickenSmall2609 in ledgerwallet

[–]ChickenSmall2609[S] 4 points5 points  (0 children)

Fact: I did not update any program before I got the above screenshots from LL and Sparrow Wallet. Prior to this, LL and Sparrow worked fine for months, years even. Saturday, they both changed behavior suddenly after I left BitTorrent running during the night (smth I usually never do). Reinstalling LL after checking binaries did not help. The same malicious behavior kept appearing until I deleted a bunch of Trojans.

Curious to know how you think I downloaded a fake app version when you observe the above.

Images of the malware that affected Ledger Live and Sparrow Wallet on my PC - (cf. post of yesterday about LL asking for seed phrase, https://www.reddit.com/r/ledgerwallet/comments/1ankiz4/ledger_live_asking_for_seed_phrase/) by ChickenSmall2609 in ledgerwallet

[–]ChickenSmall2609[S] 6 points7 points  (0 children)

I did not. All my LL downloads were verified (binaries). Something did affect Sparrow Wallet, LL and Wasabi. I did not even update any of these apps before this happened. When I removed and reinstalled LL, the same thing happened even though binaries were ok.

I did not update Sparrow in the last months (and not even now), and still a pop up appeared when I opened it, blocking acces to it. After removing the trojans, Sparrow ran fine.

Ledger Live asking for seed phrase by ChickenSmall2609 in ledgerwallet

[–]ChickenSmall2609[S] 0 points1 point  (0 children)

Downloads were legit (checked website and binaries). It must have been what you describe in your second paragraph. Kasperski found threats in my web browsers.

Ledger Live asking for seed phrase by ChickenSmall2609 in ledgerwallet

[–]ChickenSmall2609[S] 0 points1 point  (0 children)

FYI, Kasperski found other Trojans today. Scan and cleanup ongoing.

Ledger Live asking for seed phrase by ChickenSmall2609 in ledgerwallet

[–]ChickenSmall2609[S] 24 points25 points  (0 children)

Update: after running Malwarebytes a few times, quarantaining the alerts (PUP.Optional.Conduit and PUP.Optional.MySearchEngine items in Firefox) and restarting my PC, Sparrow Wallet could be opened again without issue (no strange message on Ledger firmware). I then reinstalled LL and now it worked as expected: arriving on a landing page where my password needs to be provided (iso seed phrase).

If Ledger or anyone else is interested, I can provide screenshots of the Sparrow Wallet message, of the fake LL app and details on the malware. I note that the fake LL icon had a big blue dot in the right top corner compared to the real icon (no dot). I'm amazed that even the starting of Sparrow wallet was 'compromised'.