Spybot - Search & Destroy 2

Spybot - Search & Destroy 2

by Safer-Networking Ltd.

What is Spybot - Search & Destroy 2?

Spybot - Search & Destroy 2 is software application developed by Safer-Networking Ltd.. It is most commonly found on computers running Windows 7 with nearly 72.14% of installations running this operating system. Spybot - Search & Destroy 2's installer is typically 242.00 MB in size and installs around 59 files. The most common release is 2.0.3 with 30.00% of all installations currently using this version.

Spybot - Search & Destroy 2 is most popular in the United States with 62.96% of installations residing in this country.

Spybot - Search & Destroy 2 adds 3 scheduled tasks to the Windows Task Scheduler launching the program at randomly scheduled times. When using a computer that is connected to the internet, Spybot - Search & Destroy 2 is known to create 6 firewall exceptions to allow inbound and outbound connectivity.

About Spybot - Search & Destroy 2?

Spybot - Search & Destroy is a comprehensive spyware and adware removal software application designed for use on the Microsoft Windows operating system. The program is capable of performing scans on both the computer hard disk and RAM in order to detect and remove potentially malicious software. In addition to its spyware and adware detection and disinfection capabilities, Spybot - Search & Destroy can also repair the registry, winsock LSPs, ActiveX objects, browser hijackers and BHOs, PUPS, computer cookies, trackerware, heavy duty, homepage hijackers, keyloggers, LSP, tracks, trojans, spybots, revisions, and other forms of malware. Furthermore, the software is able to delete tracking cookies, further enhancing its security features.

Software Behaviors

Services:
  • SDUpdSvc.exe runs as a service named 'Spybot-S&D 2 Updating Service' (SDUpdateService) "Downloads updates and installs them.".
  • SDHookSvc.exe runs as a service named 'Spybot-S&D 2 Hooks Service' (SDHookService) "Helps Spybot monitoring the system.".
  • SDFSSvc.exe runs as a service named 'Spybot-S&D 2 Scanner Service' (SDScannerService) "Offers malware scanning services to Spybot-S&D modules.".
  • SDWSCSvc.exe runs as a service named 'Spybot-S&D 2 Security Center Service' (SDWSCService) "Integrates Spybot into the Windows Security Center.".
  • SDMonSvc.exe runs as a service named 'Spybot-S&D 2 Monitoring Service' (SDMonitorService) "Offers on-access protection from spyware, viruses and other malware.".
  • SDFWSvc.exe runs as a service named 'Spybot-S&D 2 Firewall Service' (SDFirewallService) "Offers various network protection services.".
Firewall:
  • SDFSSvc.exe is added as a firewall exception for 'C:\Program Files\Spybot - Search & Destroy 2\SDFSSvc.exe'.
  • SDMonSvc.exe is added as a firewall exception for 'C:\ProgramyMnouInstalovane\Spybot - Search & Destroy 2\SDMonSvc.exe'.
  • SDFWSvc.exe is added as a firewall exception for 'C:\ProgramyMnouInstalovane\Spybot - Search & Destroy 2\SDFWSvc.exe'.
  • SDUpdSvc.exe is added as a firewall exception for 'C:\Program Files\Spybot - Search & Destroy 2\SDUpdSvc.exe'.
  • SDUpdate.exe is added as a firewall exception for 'C:\Program Files\Spybot - Search & Destroy 2\SDUpdate.exe'.
  • SDTray.exe is added as a firewall exception for 'C:\Program Files\Spybot - Search & Destroy 2\SDTray.exe'.
Scheduled tasks:
  • explorer.exe is scheduled as a task named 'Scan the system (Spybot - Search & Destroy)' (runs daily at 3:00 AM).
  • SDImmunize.exe is scheduled as a task named 'Refresh immunization (Spybot - Search & Destroy)' (runs weekly on Thursdays at 10.30).
  • SDScan.exe is scheduled as a task named 'Scan the system' (runs monthly on Mondays at 12:30 AM).

Startup Entries

Startup tasks:
  • explorer.exe is automatically launched at startup through a scheduled task named Scan the system (Spybot - Search & Destroy).
  • SDImmunize.exe is automatically launched at startup through a scheduled task named Refresh immunization (Spybot - Search & Destroy).
  • SDUpdate.exe is automatically launched at startup through a scheduled task named Check for updates (Spybot - Search & Destroy).
  • SDScan.exe is automatically launched at startup through a scheduled task named Scan the system (Spybot - Search & Destroy).
Registry entries:
  • SDCleaner.exe is loaded in the current user (HKCU) registry as an auto-starting executable named 'Spybot-S&D Cleaning' and executes as "C:\Program Files\Spybot - Search & Destroy 2\SDCleaner.exe" /autoclean.
Registry entries (User):
  • SDDelFile.exe is loaded once in the current user (HKCU) registry as a startup file name 'SpybotDeletingF6579' which loads as "C:\Program Files\Spybot - Search & Destroy 2\SDDelFile.exe" "C:\Program Files\SweetIM\Toolbars\Internet Explorer\resources\yahoo.png".

Software Details

URL:
https://www.safer-networking.org/2012/spybot-2-now-available-for-download
Support:
https://www.safer-networking.org/index.php?page=support
Installation path:
C:\Program Files\Spybot - Search & Destroy 2\
Uninstaller:
"C:\Program Files\Spybot - Search & Destroy 2\unins000.exe"
Size:
242.00 MB
Language:
English

Spybot - Search & Destroy 2 Executable Details

Primary executable:
SDWelcome.exe
Name:
Spybot - Search & Destroy 2
Path:
C:\Program Files\Spybot - Search & Destroy 2\SDWelcome.exe
MD5:
SHA-1:
SHA-256:
Files installed by Spybot - Search & Destroy 2
File Type Filename MD5
EXE
a3a56f2483c026e3ef497f2faca5a32f
DLL
fc7cddac0bd3a2c139fb9b7a18c40db2
EXE
56ecfad9e4e4465c60db2537a12fe599
EXE
f795751d5e03832945f7ad2d21633556
EXE
e5b66ebb4a61cafb15f937ce6a31917f
DLL
95b79b0a2feffcaa2796febe83122914
EXE
9a79c35ad6643e13abd64562992671bb
EXE
ec69cafe8f47d8cee68ff5b0cab04162
DLL
a5acb5d2212f1885d233b29da64bdc07
EXE
030c5e9eb6a274464e116d1833c7fa3c