I don’t remember installing it, everything about it seems “legitimate” grepping through the logs the installation date seems to be 21st January. There was always some slow down when I initially started firefox and today I had HTOP open just to see what was happening and Clamav and ClamAV freshclam process was there. How do I check if it is compromised or which user if any installed it?

SSH is disabled.

  • SavvyWolf@pawb.social
    link
    fedilink
    English
    arrow-up
    13
    ·
    2 days ago

    Was anything else installed on the 21st? Might have been pulled down as a dependency of something.

    • Arthur Besse@lemmy.mlM
      link
      fedilink
      English
      arrow-up
      4
      ·
      1 day ago

      to answer this question: if you’re on a dpkg-based system, check /var/log/dpkg.log (or /var/log/dpkg.log.2.gz to get logs from January, if your system rotates them once a month).