I don’t remember installing it, everything about it seems “legitimate” grepping through the logs the installation date seems to be 21st January. There was always some slow down when I initially started firefox and today I had HTOP open just to see what was happening and Clamav and ClamAV freshclam process was there. How do I check if it is compromised or which user if any installed it?

SSH is disabled.

  • iii@mander.xyz
    link
    fedilink
    English
    arrow-up
    0
    ·
    edit-2
    1 month ago

    As a start, you can use opensnitch to see what connections it makes.