[ug-bosug] Windows Virus copied on a Solaris machine....

Anil Gulecha anil.verve at gmail.com
Tue Nov 27 17:25:24 PST 2007


> WITH THE PENDRIVE ON PORT
> turiya# mount
> / on /dev/dsk/c1d0s0
> read/write/setuid/devices/intr/largefiles/logging/xattr/onerror=panic/dev=1980000
> on Tue Nov 27 19:43:14 2007
> /devices on /devices read/write/setuid/devices/dev=4380000 on Tue Nov
> 27 19:43:01 2007
> /system/contract on ctfs read/write/setuid/devices/dev=43c0001 on Tue
> Nov 27 19:43:01 2007
> /proc on proc read/write/setuid/devices/dev=4400000 on Tue Nov 27 19:43:01 2007
> /etc/mnttab on mnttab read/write/setuid/devices/dev=4440001 on Tue Nov
> 27 19:43:01 2007
> /etc/svc/volatile on swap read/write/setuid/devices/xattr/dev=4480001
> on Tue Nov 27 19:43:01 2007
> /system/object on objfs read/write/setuid/devices/dev=44c0001 on Tue
> Nov 27 19:43:01 2007
> /lib/libc.so.1 on /usr/lib/libc/libc_hwcap2.so.1
> read/write/setuid/devices/dev=1980000 on Tue Nov 27 19:43:12 2007
> /dev/fd on fd read/write/setuid/devices/dev=4680001 on Tue Nov 27 19:43:14 2007
> /tmp on swap read/write/setuid/devices/xattr/dev=4480002 on Tue Nov 27
> 19:43:16 2007
> /var/run on swap read/write/setuid/devices/xattr/dev=4480003 on Tue
> Nov 27 19:43:16 2007
> /oasis on oasis read/write/setuid/devices/exec/atime/dev=2d50002 on
> Tue Nov 27 19:43:20 2007
> /zmirror on zmirror read/write/setuid/devices/exec/atime/dev=2d50003
> on Tue Nov 27 19:43:20 2007
> /home/Sh on /export/home/Sh read/write/setuid/devices/dev=1980000 on
> Tue Nov 27 19:50:43 2007
> turiya#


Hmm.. looks like it automount isnt working. There may be 2 reasons..
wither the USB isnt formatted correctly, or the auto mount service is
off.

Can you try with other USB drives and see if they are automounted.
Also can you post the o/p of the command 'svcs | grep vol' .. this
will tell you if the service is enabled or not.

Anil


More information about the ug-bosug mailing list