Pode ter sido um falso positivo com "ndptsp.exe", que normalmente é usado por um worm.
O ndptsp.tsp real é um binários do Windows, conforme a explicação abaixo:
NDPTSP NDPTSP ( Ndptsp.tsp) is a service provider DLL that runs in the context of the TAPI service process. NDPTSP provides a TSPI interface that the TAPI service presents to TAPI-aware applications so that NDPROXY can communicate with user-mode applications. NDPTSP works with NDPROXY to convert user-mode requests to TAPI connection-oriented OIDs (OID_CO_TAPI_ Xxx). For more information about TAPI connection-oriented OIDs, see TAPI Extensions for Connection-Oriented NDIS.