Skip to content
  • Categories
  • Recent
  • Tags
  • Popular
  • World
  • Users
  • Groups
Skins
  • Light
  • Cerulean
  • Cosmo
  • Flatly
  • Journal
  • Litera
  • Lumen
  • Lux
  • Materia
  • Minty
  • Morph
  • Pulse
  • Sandstone
  • Simplex
  • Sketchy
  • Spacelab
  • United
  • Yeti
  • Zephyr
  • Dark
  • Cyborg
  • Darkly
  • Quartz
  • Slate
  • Solar
  • Superhero
  • Vapor

  • Default (No Skin)
  • No Skin
Collapse
Brand Logo

agnos.is Forums

  1. Home
  2. Linux
  3. Mysterious installation of ClamAv on my popos system

Mysterious installation of ClamAv on my popos system

Scheduled Pinned Locked Moved Linux
linux
7 Posts 7 Posters 0 Views
  • Oldest to Newest
  • Newest to Oldest
  • Most Votes
Reply
  • Reply as topic
Log in to reply
This topic has been deleted. Only users with topic management privileges can see it.
  • A This user is from outside of this forum
    A This user is from outside of this forum
    [email protected]
    wrote on last edited by
    #1

    I don't remember installing it, everything about it seems "legitimate"
    grepping through the logs the installation date seems to be 21st January.
    There was always some slow down when I initially started firefox and today I had HTOP open just to see what was happening and Clamav and ClamAV freshclam process was there. How do I check if it is compromised or which user if any installed it?

    SSH is disabled.

    I savvywolf@pawb.socialS veraxis@lemmy.worldV 3 Replies Last reply
    0
    • System shared this topic on
    • A [email protected]

      I don't remember installing it, everything about it seems "legitimate"
      grepping through the logs the installation date seems to be 21st January.
      There was always some slow down when I initially started firefox and today I had HTOP open just to see what was happening and Clamav and ClamAV freshclam process was there. How do I check if it is compromised or which user if any installed it?

      SSH is disabled.

      I This user is from outside of this forum
      I This user is from outside of this forum
      [email protected]
      wrote on last edited by
      #2

      As a start, you can use opensnitch to see what internet connections it makes.

      ? 1 Reply Last reply
      0
      • A [email protected]

        I don't remember installing it, everything about it seems "legitimate"
        grepping through the logs the installation date seems to be 21st January.
        There was always some slow down when I initially started firefox and today I had HTOP open just to see what was happening and Clamav and ClamAV freshclam process was there. How do I check if it is compromised or which user if any installed it?

        SSH is disabled.

        savvywolf@pawb.socialS This user is from outside of this forum
        savvywolf@pawb.socialS This user is from outside of this forum
        [email protected]
        wrote on last edited by
        #3

        Was anything else installed on the 21st? Might have been pulled down as a dependency of something.

        S cypherpunks@lemmy.mlC 2 Replies Last reply
        0
        • savvywolf@pawb.socialS [email protected]

          Was anything else installed on the 21st? Might have been pulled down as a dependency of something.

          S This user is from outside of this forum
          S This user is from outside of this forum
          [email protected]
          wrote on last edited by
          #4

          Or as a way for someone putting malware on the system to keep other malware away...

          1 Reply Last reply
          0
          • A [email protected]

            I don't remember installing it, everything about it seems "legitimate"
            grepping through the logs the installation date seems to be 21st January.
            There was always some slow down when I initially started firefox and today I had HTOP open just to see what was happening and Clamav and ClamAV freshclam process was there. How do I check if it is compromised or which user if any installed it?

            SSH is disabled.

            veraxis@lemmy.worldV This user is from outside of this forum
            veraxis@lemmy.worldV This user is from outside of this forum
            [email protected]
            wrote on last edited by
            #5

            ClamAV

            But on a serious note, no, I have no idea why that would happen.

            1 Reply Last reply
            0
            • I [email protected]

              As a start, you can use opensnitch to see what internet connections it makes.

              ? Offline
              ? Offline
              Guest
              wrote on last edited by
              #6

              Or Wireshark

              1 Reply Last reply
              0
              • savvywolf@pawb.socialS [email protected]

                Was anything else installed on the 21st? Might have been pulled down as a dependency of something.

                cypherpunks@lemmy.mlC This user is from outside of this forum
                cypherpunks@lemmy.mlC This user is from outside of this forum
                [email protected]
                wrote on last edited by
                #7

                to answer this question: if you're on a dpkg-based system, check /var/log/dpkg.log (or /var/log/dpkg.log.2.gz to get logs from January, if your system rotates them once a month).

                1 Reply Last reply
                0
                • System shared this topic on
                Reply
                • Reply as topic
                Log in to reply
                • Oldest to Newest
                • Newest to Oldest
                • Most Votes


                • Login

                • Login or register to search.
                • First post
                  Last post
                0
                • Categories
                • Recent
                • Tags
                • Popular
                • World
                • Users
                • Groups