Which was a bit of a pointless exercise as this is the anti-rootkit scan that is flagging this, something which can't be run from VT. So I wouldn't expect it to find anything and that is the same reason why the standard scans of avast don't detect anything.
What is considered suspicious I don't completely know, but most certainly it must be a hidden process/driver, why it needs to be run hidden is beyond me.
As for why after asking avast to delete it and it coming back, well I don't know if avast is only removing the hidden driver and not the actual file from the system32\drivers folder. So there is some program which uses this driver and is reloading it. Finding what that might be is going to be the hard part.
I don't have the sptd.sys file on my XP Pro SP3 system, is your alert on the XP or win7 system ?