Is spcmdcon.sys a Virus?

April 23rd, 2010

Are you getting a BSOD (Blue Screen od Death) which references a file named spcmdcon.sys? It is more than likely that this is a virus. It usually means you have a  Rouge Security Tool installed on your machine.

One of my customers in Chicago called to let me know she was getting a Blue Screen on her Windows XP box which referenced the file named spcmdcon.sys which is a legitimate Windows XP system file but when I actually got on site and looked at the error message, I could see that the Blue Screen was fake.

Some viruses will pop up screens that give fake error messages to get you to click on a link to other, more harmful software. These are what are known as Trojans or Trojan Horses which make you believe you are clicking on something good but in reality you are opening a security hole to let in other spyware, malware or viruses to infect your computer.

I was able to do a Ctrl+Alt+Del and get to the Task Manager. That proved it was a fake BSOD and I was able to see the desktop normally. There was a message in the bottom right corner of the screen asking me to update Security Tool, which is not an antivirus program I know of,  so I rebooted and logged in as Administrator. I then ran my favorite virus removal tool which found 5 malicious programs.

In C:\Documents and Settings\All Users\Application Data\  — it found a directory named 61520216 which contained a file named 61520216.exe and deleted both. These were defined as Rouge.Multiple

In C:\Documents and Settings\username\Desktop\Security Tool.LNK which was defined as Rouge.SecurityTool

In C:\Documents and Settings\username\Start Menu\Programs\Security Tool\.LNK defined as Rouge.SecurityTool

In C:\Documents and Settings\username.domain\Local Settings\Temp\d.exe was defined as Trojan.Dropper

DO NOT DELETE spcmdcon.sys

If you are not completely sure of what you are doing please contact a Spyware Removal Specialist

Chicago Virus Removal

March 28th, 2010

TechPunk offers virus removal, spyware removal and anitvirus services in Chicago.