PowerArchiver Home

  #1  
Old 09-14-2011, 08:49 AM
Kai Fieabach Kai Fieabach is offline
Senior Members
 
Join Date: Feb 2003
Location: Lübeck, Germany
Posts: 8
Thanks: 0
Thanked 3 Times in 3 Posts
Exclamation SPTD triggers Antimalware warnings

I just wasted half of a day with Antimalware support because of Powerarchiver.

After installing the Microsoft Security Essentials (MSE), with each boot MSE logs the following warning:
Name: Behavior/ModifiedKernel
ID: 2790572135
Description: http://go.microsoft.com/fwlink/?link...tid=4294967289

With this, MSE also logs a random filename in the shape of "sp??.sys" that DOES NOT EXIST on the system, like "spco.sys" or "spla.sys". This made it extremely difficult to find out what was wrong. I finally found out that PowerArchiver installs the driver Windows\system32\drivers\SPTD.SYS, and this driver disguises itself with a random name on each boot. I also managed to find the company Duplexsecure, maker of SPTD. They offer a download to update or uninstall SPTD: http://duplexsecure.com

After uninstalling SPTD, MSE finally is calm. I hope this thread helps other people with the same problem. I wonder why PowerArchiver installs disguising stuff? At least there should be a warning about possible consequences for Antimalmare software. So far I could not find any negative effect on PowerArchiver after uninstalling SPTD.

Last edited by Kai Fieabach; 09-14-2011 at 08:55 AM.
Reply With Quote
The Following User Says Thank You to Kai Fieabach For This Useful Post:
spwolf (09-14-2011)
  #2  
Old 09-14-2011, 10:18 AM
Luxor's Avatar
Luxor Luxor is offline
Alpha Tester
 
Join Date: Jul 2001
Location: Scotland
Posts: 772
Thanks: 19
Thanked 119 Times in 95 Posts
Quote:
Originally Posted by Kai Fieabach View Post
I wonder why PowerArchiver installs disguising stuff? At least there should be a warning about possible consequences for Antimalmare software. So far I could not find any negative effect on PowerArchiver after uninstalling SPTD.
I would say it's a problem with MSE rather than Powerarchiver. False positives happen from time to time with malware and antivirus software. Best to report it to them.
__________________
Vista home premium SP2. Always the latest Powerarchiver Toolbox
Reply With Quote
The Following User Says Thank You to Luxor For This Useful Post:
spwolf (09-14-2011)
  #3  
Old 09-14-2011, 10:41 AM
Kai Fieabach Kai Fieabach is offline
Senior Members
 
Join Date: Feb 2003
Location: Lübeck, Germany
Posts: 8
Thanks: 0
Thanked 3 Times in 3 Posts
Quote:
Originally Posted by Luxor View Post
I would say it's a problem with MSE rather than Powerarchiver. False positives happen from time to time with malware and antivirus software. Best to report it to them.
I do not regard this as a false positive. If a software disguises itself with false file names, so that it cannot be detected, and gives "signs of tampering in the state of the running operating system kernel" as SPTD does, I am thankful for a warning of Antimalware software. I still do not understand why Powerarchiver installs disguising drivers. When I bought Powerarchiver, I expected clean software, not something that hides and behaves like a root kit.
Reply With Quote
The Following User Says Thank You to Kai Fieabach For This Useful Post:
spwolf (09-14-2011)
  #4  
Old 09-14-2011, 12:46 PM
spwolf's Avatar
spwolf spwolf is offline
Administrator
 
Join Date: Jun 2001
Posts: 7,820
Thanks: 676
Thanked 207 Times in 192 Posts
Quote:
Originally Posted by Kai Fieabach View Post
I just wasted half of a day with Antimalware support because of Powerarchiver.

After installing the Microsoft Security Essentials (MSE), with each boot MSE logs the following warning:
Name: Behavior/ModifiedKernel
ID: 2790572135
Description: http://go.microsoft.com/fwlink/?link...tid=4294967289

With this, MSE also logs a random filename in the shape of "sp??.sys" that DOES NOT EXIST on the system, like "spco.sys" or "spla.sys". This made it extremely difficult to find out what was wrong. I finally found out that PowerArchiver installs the driver Windows\system32\drivers\SPTD.SYS, and this driver disguises itself with a random name on each boot. I also managed to find the company Duplexsecure, maker of SPTD. They offer a download to update or uninstall SPTD: http://duplexsecure.com

After uninstalling SPTD, MSE finally is calm. I hope this thread helps other people with the same problem. I wonder why PowerArchiver installs disguising stuff? At least there should be a warning about possible consequences for Antimalmare software. So far I could not find any negative effect on PowerArchiver after uninstalling SPTD.
eh, if your antivirus software has an issue with CD/DVD burner drivers, which are completely fine, then it is not our fault :-).

It is best if you report it to MSE and we will also do the same. They usually fix false positives quickly.
__________________
ConeXware, Inc.
latest PA release info on Facebook, Twitter | Follow us and win free PowerArchiver.
Reply With Quote
  #5  
Old 09-14-2011, 12:55 PM
spwolf's Avatar
spwolf spwolf is offline
Administrator
 
Join Date: Jun 2001
Posts: 7,820
Thanks: 676
Thanked 207 Times in 192 Posts
btw these are the drivers that get installed with Virtual Drive, they allow for direct access to burner devices, and they are much better to use than standard Windows SPTI.

PowerArchiver Burner can use: SPTD, SPTI or ASPI for burning drivers, but SPTD is by far the best of 3 and recomended for fastest operation and least number of issues.
__________________
ConeXware, Inc.
latest PA release info on Facebook, Twitter | Follow us and win free PowerArchiver.
Reply With Quote
Reply

Bookmarks

Tags
duplexsecure, malware, sptd.sys, uninstall, virus

Thread Tools
Display Modes Rate This Thread
Rate This Thread:

Posting Rules
You may not post new threads
You may not post replies
You may not post attachments
You may not edit your posts

BB code is On
Smilies are On
[IMG] code is On
HTML code is Off

Forum Jump

Similar Threads
Thread Thread Starter Forum Replies Last Post
Missing SPTD driver after PAVD install Keith Weisshar Tech Support 7 01-11-2012 07:37 AM
[BUG] PA 11.60.22 triggers "Windows - No Disk" error on startup welhaux Tech Support 18 10-25-2009 03:50 AM
Antivirus Warnings spiker19 Tech Support 6 02-01-2006 06:10 PM
warnings that paths not extracted davidsplash Wishlist 3 10-26-2005 05:41 AM


All times are GMT -5. The time now is 03:00 AM.


Powered by vBulletin® Version 3.8.1
Copyright ©2000 - 2013, Jelsoft Enterprises Ltd.