Hi Michael! > virus is to restart so kernel memory is cleared. If F-Prot says that > the data in /proc/kcore is a Windows virus, we can only hope so. ;-) I suspect, but am not sure, that F-Prot is detecting it's own profile of the said virus, as it has to have some sort of comparrison, to determine, if any of your files contains such a virus. So I think, but am not sure, it's just seen itself in the mirror of /proc/kcore. Best Regards Jan Rasmussen