Skip to content
This repository has been archived by the owner on Jun 16, 2022. It is now read-only.

Ledger Live 2.1.0, 2.2.0, 2.2.3 Installers and Uninstallers for Windows are triggering Windows Defender with Trojan:Win32/Bulta!rfn detection #2822

Closed
d-rez opened this issue Apr 8, 2020 · 16 comments
Labels
important label used to flag a PR as important to be merged in priority (sometimes because dependencies)

Comments

@d-rez
Copy link

d-rez commented Apr 8, 2020

EDIT from @gre:

The bug has been solved in 2.2.4. Just be aware that if the first time you installed Ledger Live was on 2.2.3 you need to fully uninstall it to correctly recover from the antivirus detection situation.

Here is the diagram we think currently cover everything.

The TLDR is that as soon as you have Ledger Live's Uninstaller being detected as a virus (or is gone), we recommend to uninstall the Live using a "valid" (not detected as a virus) Uninstaller that we will also distribute on our website soon (meanwhile => https://github.com/LedgerHQ/ledger-live-desktop/releases/download/v2.2.3/Uninstall.Ledger.Live.exe – sha256sum of
0e7245dde4d656758c3f03724e1615239cbe358f1a61db0b3b6326669b5cbd60 )

analysis_of_false_positive_uninstaller_issue


Ledger Live Version and Operating System

  • tested on Ledger Live 2.1.0
  • Platform and version: Win10

Expected behavior

Installer installs software

Actual behavior

Installer gets blocked by Windows Defender,

https://www.microsoft.com/en-us/wdsi/threats/malware-encyclopedia-description?name=Trojan%3aWin32%2fBulta!rfn&threatid=2147694403

Steps to reproduce the behavior

  • Download installer from GitHub releases, specifically the Windows installer
  • Launch the installer or go to a folder where it's downloaded to
  • Windows Defender pop-up shows up, threat is marked as "serious" and the file gets deleted

image

Note: 2.2.0 installer doesn't trigger this

@d-rez
Copy link
Author

d-rez commented Apr 10, 2020

On top of that, more resources related to 2.2.0 installation get detected as a Trojan as well:

image

@gre
Copy link
Contributor

gre commented Apr 10, 2020

Thanks for raising this issue.
We think to have fixed it in our upcoming 2.2.3.

@d-rez
Copy link
Author

d-rez commented Apr 10, 2020

No worries, I know it's not a normal issue but depending on a platform that could possibly go into a full release unnoticed. Feel free to close once addressed :)

@picatextra
Copy link

Still detected with 2.2.3

@Dviros
Copy link

Dviros commented Apr 10, 2020

Can confirm Uninstaller.exe is still triggering Defender with version 2.2.3:
image

@ftapon
Copy link

ftapon commented Apr 15, 2020

warning
Same problem.
According to the Ledger folks on Reddit, it's a false positive.

@gre gre added the important label used to flag a PR as important to be merged in priority (sometimes because dependencies) label Apr 16, 2020
@gre
Copy link
Contributor

gre commented Apr 16, 2020

we are working on it #2860

@ahsbt
Copy link

ahsbt commented Apr 16, 2020

after installing 2.2.3 , my windows immediately raised the flag for this trojan in the ledger uninstaller .exe
the problem became worse when i tried to uninstall ledger live , these files(screenshot) were made from A to Z when i finally uninstalled the program (i had to manually allow the uninstaller.exe in defender to run to be able to uninstall the program, i hope my windows is not infected , surely i wont connect my device to desktop until a solution comes up).
Untitled

@d-rez
Copy link
Author

d-rez commented Apr 17, 2020

Bracing for a tide of newcomers commenting "me too"

Please just +1 the issue on top, thanks!

@gre so it wasn't the automatic installation thingy? Just a framework update that caused it? Curious!

@d-rez d-rez changed the title Ledger Live 2.1.0 Installer for Windows is triggering Windows Defender with Trojan:Win32/Bulta!rfn detection Ledger Live 2.1.0, 2.2.0, 2.2.3 Installers and Uninstallers for Windows is triggering Windows Defender with Trojan:Win32/Bulta!rfn detection Apr 17, 2020
@d-rez d-rez changed the title Ledger Live 2.1.0, 2.2.0, 2.2.3 Installers and Uninstallers for Windows is triggering Windows Defender with Trojan:Win32/Bulta!rfn detection Ledger Live 2.1.0, 2.2.0, 2.2.3 Installers and Uninstallers for Windows are triggering Windows Defender with Trojan:Win32/Bulta!rfn detection Apr 17, 2020
@gre
Copy link
Contributor

gre commented Apr 17, 2020

Yes the issue is due to electron-userland/electron-builder#4793 that upgraded NSIS which likely is flagged by Windows antivirus.. (false positive)

The issue only affects the Uninstaller and in the meantime you can use https://github.com/LedgerHQ/ledger-live-desktop/releases/download/v2.2.3/Uninstall.Ledger.Live.exe if you want to uninstall Ledger Live. unfortunately you MUST uninstall Live if you installed a 2.2.3 from scratch because app updates won't update the Uninstaller.. only the first install of Ledger Live do.
so all users that have installed 2.2.3 for the first time need to uninstall it either by allowing the false positive virus detection or by using that separate uninstaller..

That's why we are now preparing a 2.2.4 to try to minimize number of users entering this problem. It's already a prerelease at the moment.

thanks

@gre gre pinned this issue Apr 17, 2020
@gre
Copy link
Contributor

gre commented Apr 17, 2020

2.2.4 was released. make sure to check message above. we'll try to document it better next week.

@gre gre closed this as completed Apr 17, 2020
@d-rez
Copy link
Author

d-rez commented Apr 17, 2020

Thanks! Glad that's sorted :)

btw,

unfortunately you MUST uninstall Live if you installed a 2.2.3 from scratch because app updates won't update the Uninstaller.. only the first install of Ledger Live do.
so all users that have installed 2.2.3 for the first time need to uninstall it either by allowing the false positive virus detection or by using that separate uninstaller..

Are you sure that's the case? AV removed the uninstaller and when I installed 2.2.4 over my 2.2.3 install (which was missing the uninstaller due to above), the uninstaller got recreated just fine and the entry re-appeared in Windows' Add/Remove Apps

@gre
Copy link
Contributor

gre commented Apr 17, 2020

very interesting! i guess it works if the uninstaller was removed before updating then 🤔 maybe it's just not copied if it exists. thanks for your feedback

@a1exandrovm
Copy link

Ledger Live Version Ver. 2.0.1, Ver. 2.2.3 on
Windows 7 & Windows 10 64-bit

360 Total Security detects the virus (Generic / Trojan.Downloader.251) in the installation file from your official site. Ledger Live Desktop Ver. 2.0.1, Ver. 2.2.3

On three devices I checked the distribution from your official site, and on all three devices with the pre-installed 360Total Security antivirus, I got a warning.

Additionally, I rechecked your file through the VirusTotal.com and MetaDefender.opswat.com online virus scan service (attached screenshot). This service also gives a warning, referring to the engine Qihoo-360 by 360 Total Security. Let me remind you that the previous Ledger Live distribution was installed without problems and without warnings.

Please close this bug so that users can safely install the Ledger Live application update for Windows. After all, the installation package The distribution of the previous version was installed well, without threats to the operating system.
AlertLLD223
virustotal-alert-LLD2-2-3
virus in LLD2-2-3
360 TS Detected Virus
virustotal

@gre
Copy link
Contributor

gre commented Apr 20, 2020

The bug is closed and has been solved in 2.2.4. Just be aware you need to fully uninstall 2.2.3 if you had it installed in the first time to correctly recover from the antivirus detection situation.

Here is the diagram we think currently cover everything.

The TLDR is that as soon as you have Ledger Live's Uninstaller being detected as a virus, we recommend to uninstall the Live using a "valid" (not detected as a virus) Uninstaller that we will also distribute on our website soon (but it's going to be https://github.com/LedgerHQ/ledger-live-desktop/releases/download/v2.2.3/Uninstall.Ledger.Live.exe – sha256sum of
0e7245dde4d656758c3f03724e1615239cbe358f1a61db0b3b6326669b5cbd60 )

analysis_of_false_positive_uninstaller_issue

@gre
Copy link
Contributor

gre commented Apr 20, 2020

if there is any remaining issue you are facing and even after uninstalling and reinstalling completely, please create a new Github issue or contact our tech support. Thanks!

@LedgerHQ LedgerHQ locked as resolved and limited conversation to collaborators Apr 20, 2020
@gre gre unpinned this issue Aug 14, 2020
Sign up for free to subscribe to this conversation on GitHub. Already have an account? Sign in.
Labels
important label used to flag a PR as important to be merged in priority (sometimes because dependencies)
Projects
None yet
Development

No branches or pull requests

7 participants