I don't remember installing it, everything about it seems "legitimate" grepping through the logs the installation date seems to be 21st January. There was always some slow down when I initially started firefox and today I had HTOP open just to see what was happening and Clamav and ClamAV freshclam process was there. How do I check if it is compromised or which user if any installed it?
SSH is disabled.
6 Comments
savvywolf@pawb.social · 12 pts · 1y
Was anything else installed on the 21st? Might have been pulled down as a dependency of something.
cypherpunks@lemmy.ml · 3 pts · 1y
to answer this question: if you're on a dpkg-based system, check
/var/log/dpkg.log(or/var/log/dpkg.log.2.gzto get logs from January, if your system rotates them once a month).signalsayge@lemm.ee · 2 pts · 1y
Or as a way for someone putting malware on the system to keep other malware away...
iii@mander.xyz · 5 pts · 1y
As a start, you can use opensnitch to see what connections it makes.
TorJansen@sh.itjust.works · 2 pts · 1y
Or Wireshark
Veraxis@lemmy.world · 4 pts · 1y
But on a serious note, no, I have no idea why that would happen.
thedeadwalking4242@lemmy.world · 1 pts · 1y