# Is this strange behavior a computer virus?

**URL:** <https://boards.straightdope.com/t/is-this-strange-behavior-a-computer-virus/214275>\
**Category:** Factual Questions\
**Created:** [November 20, 2003, 8:05am UTC](https://boards.straightdope.com/t/is-this-strange-behavior-a-computer-virus/214275 "2003-11-20T08:05:58Z")\
**Posts on this page:** 11\
**Page:** 1

<div class="post-metadata">

**Author:** ![Grousser](https://avatars.discourse-cdn.com/v4/letter/g/9d8465/32.png) [@Grousser](https://boards.straightdope.com/u/Grousser)\
**Post date:** [November 20, 2003, 8:05am UTC](https://boards.straightdope.com/t/is-this-strange-behavior-a-computer-virus/214275/1 "2003-11-20T08:05:58Z")

</div>

Suddenly, with no noticeable cause, the icons in explorer can’t be dragged and droped. I thought first it was a graphical problem, but when I try to paste it, paste appears disabled in the right-click menu.

Later I found that it was not only my PC. Other people had the same problem (no connection between our computers). Norton Antivirus and others av don’t report anything. The solution is simple: restarting Windows does the trick.

Very weird. What do you think? Some kind of strange mutation or what?

---

<div class="post-metadata">

**Author:** ![Mangetout](https://sea3.discourse-cdn.com/straightdope/user_avatar/boards.straightdope.com/mangetout/32/19_2.png) [@Mangetout](https://boards.straightdope.com/u/Mangetout)\
**Post date:** [November 20, 2003, 9:08am UTC](https://boards.straightdope.com/t/is-this-strange-behavior-a-computer-virus/214275/2 "2003-11-20T09:08:35Z")

</div>

I had a rather similar problem on an older machine of mine; I couldn’t drag anything to a folder in Windows Explorer’s left-hand pane - the cursor would change to a barred circle. I believe it was related to a problem with some of the system folders (I had previously managed to delete the My Documents folder (which wasn’t supposed to be possible) - in the end, a complete wipe and reinstall of Windows was the only way I could fix it - not that I particularly recommend this.

---

<div class="post-metadata">

**Author:** ![milk\_milk\_lemonade](https://avatars.discourse-cdn.com/v4/letter/m/ecccb3/32.png) [@milk\_milk\_lemonade](https://boards.straightdope.com/u/milk_milk_lemonade)\
**Post date:** [November 20, 2003, 10:55am UTC](https://boards.straightdope.com/t/is-this-strange-behavior-a-computer-virus/214275/3 "2003-11-20T10:55:25Z")

</div>

I don’t have a definitive answer but it may be a resources problem caused by a common driver - do the PCs in question have the same video cards for instance?

You used to see this sort of thing a lot with Win3/95/98 when the heaps ran out of space.

---

<div class="post-metadata">

**Author:** ![APOC](https://avatars.discourse-cdn.com/v4/letter/a/5f8ce5/32.png) [@APOC](https://boards.straightdope.com/u/APOC)\
**Post date:** [November 20, 2003, 11:02am UTC](https://boards.straightdope.com/t/is-this-strange-behavior-a-computer-virus/214275/4 "2003-11-20T11:02:37Z")

</div>

This sounds like classic Blaster activity.  
You may not be infected but you may be being hit.  
The resart is easily explained by the traffic hitting you from another infected system.

If it occurs again have a look at the resources being used by SVChost.exe (also consider using [F-Port](http://www.foundstone.com/index.htm?subnav=resources/navigation.htm&subcontent=/resources/proddesc/fport.htm) from foundstone to have a looksee at teh ports in use )

Make sure you patch the box to stop it happening again.

---

<div class="post-metadata">

**Author:** ![Grousser](https://avatars.discourse-cdn.com/v4/letter/g/9d8465/32.png) [@Grousser](https://boards.straightdope.com/u/Grousser)\
**Post date:** [November 20, 2003, 10:17pm UTC](https://boards.straightdope.com/t/is-this-strange-behavior-a-computer-virus/214275/5 "2003-11-20T22:17:36Z")

</div>

Yes! Norton suddenly reports me that it found blaster in a strange file in Winnt/system32/tftp or something, it says the virus has been erased but svchost suddenly pops an error dialog.

How can I have a look at the resources being used by SVChost.exe? Please explain with more detail… thanks in advance.

I use Windows 2000.

---

<div class="post-metadata">

**Author:** ![Grousser](https://avatars.discourse-cdn.com/v4/letter/g/9d8465/32.png) [@Grousser](https://boards.straightdope.com/u/Grousser)\
**Post date:** [November 21, 2003, 1:20am UTC](https://boards.straightdope.com/t/is-this-strange-behavior-a-computer-virus/214275/6 "2003-11-21T01:20:12Z")

</div>

May I solve this problem with the Service Pack 4, **APOC**?

---

<div class="post-metadata">

**Author:** ![APOC](https://avatars.discourse-cdn.com/v4/letter/a/5f8ce5/32.png) [@APOC](https://boards.straightdope.com/u/APOC)\
**Post date:** [November 21, 2003, 9:15am UTC](https://boards.straightdope.com/t/is-this-strange-behavior-a-computer-virus/214275/7 "2003-11-21T09:15:55Z")

</div>

[Ask Microsoft](http://www.microsoft.com/security/incident/blast.asp)

I’m concerned that the rogue was found in TFTP.  
This is more indicitative of Welchia  
so MY recommendations :

[Dowload this](http://securityresponse.symantec.com/avcenter/FixBlast.exe) [and this](http://www.symantec.com/avcenter/FixWelch.exe)

run and patch thusly :

[Apply This](http://www.microsoft.com/technet/treeview/default.asp?url=/technet/security/bulletin/MS03-026.asp)[and this](http://www.microsoft.com/technet/treeview/default.asp?url=/technet/security/bulletin/MS03-007.asp)

Screw the SVChost files stuff. That’s only if your interested in the beastie itself  
I’m going to recommend that you use Windows Update and install all of the “Critical Security Patches”. Personally I am staying away from SP4 , it’s caused me no end of grief. It does not contain all of the current patches.

---

<div class="post-metadata">

**Author:** ![APOC](https://avatars.discourse-cdn.com/v4/letter/a/5f8ce5/32.png) [@APOC](https://boards.straightdope.com/u/APOC)\
**Post date:** [November 21, 2003, 9:17am UTC](https://boards.straightdope.com/t/is-this-strange-behavior-a-computer-virus/214275/8 "2003-11-21T09:17:32Z")

</div>

Yeah and this too :

[http://www.microsoft.com/security/security\_bulletins/ms03-039.asp](http://www.microsoft.com/security/security_bulletins/ms03-039.asp)

---

<div class="post-metadata">

**Author:** ![Futile\_Gesture](https://avatars.discourse-cdn.com/v4/letter/f/f05b48/32.png) [@Futile\_Gesture](https://boards.straightdope.com/u/Futile_Gesture)\
**Post date:** [November 21, 2003, 2:55pm UTC](https://boards.straightdope.com/t/is-this-strange-behavior-a-computer-virus/214275/9 "2003-11-21T14:55:16Z")

</div>

What you’re seeing is indicative of SVChost having crashed out. This is often the result of the Blaster virus infecting, or **trying** to infect, your Win2k.

Removing the virus isn’t going to help you unless you patch your computer to prevent future infection attempts. Somewhere, probably on the same network or ISP, there is a computer spewing Blaster out and it’s going to keep causing you the same problem until you apply the patch.

---

<div class="post-metadata">

**Author:** ![Grousser](https://avatars.discourse-cdn.com/v4/letter/g/9d8465/32.png) [@Grousser](https://boards.straightdope.com/u/Grousser)\
**Post date:** [November 21, 2003, 10:24pm UTC](https://boards.straightdope.com/t/is-this-strange-behavior-a-computer-virus/214275/10 "2003-11-21T22:24:50Z")

</div>

Applying the patches won’t affect my system, right? I mean, I will apply them even I didn’t need them.

I don’t think my system is actually infected with blaster. I think they are only attempts. May I run the fixblast.exe and fixwelch anyway?

My real question is _may I apply everything_, without a risk?

Thanks to all for your support.

---

<div class="post-metadata">

**Author:** ![APOC](https://avatars.discourse-cdn.com/v4/letter/a/5f8ce5/32.png) [@APOC](https://boards.straightdope.com/u/APOC)\
**Post date:** [November 22, 2003, 8:00am UTC](https://boards.straightdope.com/t/is-this-strange-behavior-a-computer-virus/214275/11 "2003-11-22T08:00:46Z")

</div>

Yes indeedy.

The patches will shut down the vulnerability that allows your system to get hit (infected or not) by Blaster traffic. You can confidently apply them in the knowledge that they are simly fixing the Tiny File Transfer Protocol (TFTP) hole. They are certified and delivered by Microsoft so go for it.

Fixwelch and fixblast will try to find either virus on your systems. If they do they will fix it , if they dont they do nothing .
