SPTD.sys

User avatar
viking33
PlatinumLounger
Posts: 5685
Joined: 24 Jan 2010, 19:16
Location: Cape Cod, Massachusetts,USA

SPTD.sys

Post by viking33 »

Looking for opinions on this.
Just ran GMER rootkit tester and it turned up two instances of sptd.sys in the REG, that it claims to be malware or a rootkit.
The file sptd.sys does appear in the Windows\system32\drivers folder.
I have Googled this filename and there seems to be two opposing camps that directly contradict each other. One says this is a necessary windows file, used for CD emulation. The other says it's not necessary and a possible rootkit. Take your choice as to which opinion is correct. I'm not having any apparent problems but it would be good to know if it's a "goodie or a baddie?" A false positive?
It's just amazing how many opinions are out there on this thing.
BOB
:massachusetts: :usa:
______________________________________

If I agreed with you we'd both be wrong.

User avatar
PaulB
BronzeLounger
Posts: 1598
Joined: 26 Jan 2010, 20:28
Location: Ottawa ON

Re: SPTD.sys

Post by PaulB »

I can't offer an opinion, Bob, but I can tell you that I do not have that file on my system (Win 7 HP SP1 x64).
Regards,
Paul

The pessimist complains about the wind. The optimist expects it to change. The realist adjusts his sails.

User avatar
HansV
Administrator
Posts: 78615
Joined: 16 Jan 2010, 00:14
Status: Microsoft MVP
Location: Wageningen, The Netherlands

Re: SPTD.sys

Post by HansV »

A name that comes up frequently when I search for sptd.sys is Daemon Tools. Do you have software from them? If so, the file is probably safe - disk emulation software by its nature has aspects that resemble a rootkit.
Best wishes,
Hans

User avatar
viking33
PlatinumLounger
Posts: 5685
Joined: 24 Jan 2010, 19:16
Location: Cape Cod, Massachusetts,USA

Re: SPTD.sys

Post by viking33 »

HansV wrote:A name that comes up frequently when I search for sptd.sys is Daemon Tools. Do you have software from them? If so, the file is probably safe - disk emulation software by its nature has aspects that resemble a rootkit.
No, nothing by Daemon Tools. ( that I know of ) I wonder if perhaps some other program might be using it by agreement or not?
I think I may just rename that file temporarily and see if anything starts to complain.
BOB
:massachusetts: :usa:
______________________________________

If I agreed with you we'd both be wrong.