Spybot - Search & Destroy 2

Spybot - Search & Destroy 2

by Safer-Networking Ltd.

What is Spybot - Search & Destroy 2?

Spybot - Search & Destroy 2 is software application developed by Safer-Networking Ltd.. It is most commonly found on computers running Windows 7 with nearly 72.14% of installations running this operating system. Spybot - Search & Destroy 2's installer is typically 242.00 MB in size and installs around 59 files. The most common release is 2.0.3 with 30.00% of all installations currently using this version.

Spybot - Search & Destroy 2 is most popular in the United States with 62.96% of installations residing in this country.

Spybot - Search & Destroy 2 adds 3 scheduled tasks to the Windows Task Scheduler launching the program at randomly scheduled times. When using a computer that is connected to the internet, Spybot - Search & Destroy 2 is known to create 6 firewall exceptions to allow inbound and outbound connectivity.

About Spybot - Search & Destroy 2?

Spybot - Search & Destroy is a comprehensive spyware and adware removal software application designed for use on the Microsoft Windows operating system. The program is capable of performing scans on both the computer hard disk and RAM in order to detect and remove potentially malicious software. In addition to its spyware and adware detection and disinfection capabilities, Spybot - Search & Destroy can also repair the registry, winsock LSPs, ActiveX objects, browser hijackers and BHOs, PUPS, computer cookies, trackerware, heavy duty, homepage hijackers, keyloggers, LSP, tracks, trojans, spybots, revisions, and other forms of malware. Furthermore, the software is able to delete tracking cookies, further enhancing its security features.

Software Behaviors

Services:
  • SDUpdSvc.exe runs as a service named 'Spybot-S&D 2 Updating Service' (SDUpdateService) "Downloads updates and installs them.".
  • SDHookSvc.exe runs as a service named 'Spybot-S&D 2 Hooks Service' (SDHookService) "Helps Spybot monitoring the system.".
  • SDFSSvc.exe runs as a service named 'Spybot-S&D 2 Scanner Service' (SDScannerService) "Offers malware scanning services to Spybot-S&D modules.".
  • SDWSCSvc.exe runs as a service named 'Spybot-S&D 2 Security Center Service' (SDWSCService) "Integrates Spybot into the Windows Security Center.".
  • SDMonSvc.exe runs as a service named 'Spybot-S&D 2 Monitoring Service' (SDMonitorService) "Offers on-access protection from spyware, viruses and other malware.".
  • SDFWSvc.exe runs as a service named 'Spybot-S&D 2 Firewall Service' (SDFirewallService) "Offers various network protection services.".
Firewall:
  • SDFSSvc.exe is added as a firewall exception for 'C:\Program Files\Spybot - Search & Destroy 2\SDFSSvc.exe'.
  • SDMonSvc.exe is added as a firewall exception for 'C:\ProgramyMnouInstalovane\Spybot - Search & Destroy 2\SDMonSvc.exe'.
  • SDFWSvc.exe is added as a firewall exception for 'C:\ProgramyMnouInstalovane\Spybot - Search & Destroy 2\SDFWSvc.exe'.
  • SDUpdSvc.exe is added as a firewall exception for 'C:\Program Files\Spybot - Search & Destroy 2\SDUpdSvc.exe'.
  • SDUpdate.exe is added as a firewall exception for 'C:\Program Files\Spybot - Search & Destroy 2\SDUpdate.exe'.
  • SDTray.exe is added as a firewall exception for 'C:\Program Files\Spybot - Search & Destroy 2\SDTray.exe'.
Scheduled tasks:
  • explorer.exe is scheduled as a task named 'Scan the system (Spybot - Search & Destroy)' (runs daily at 3:00 AM).
  • SDImmunize.exe is scheduled as a task named 'Refresh immunization (Spybot - Search & Destroy)' (runs weekly on Thursdays at 10.30).
  • SDScan.exe is scheduled as a task named 'Scan the system' (runs monthly on Mondays at 12:30 AM).

Startup Entries

Startup tasks:
  • explorer.exe is automatically launched at startup through a scheduled task named Scan the system (Spybot - Search & Destroy).
  • SDImmunize.exe is automatically launched at startup through a scheduled task named Refresh immunization (Spybot - Search & Destroy).
  • SDUpdate.exe is automatically launched at startup through a scheduled task named Check for updates (Spybot - Search & Destroy).
  • SDScan.exe is automatically launched at startup through a scheduled task named Scan the system (Spybot - Search & Destroy).
Registry entries:
  • SDCleaner.exe is loaded in the current user (HKCU) registry as an auto-starting executable named 'Spybot-S&D Cleaning' and executes as "C:\Program Files\Spybot - Search & Destroy 2\SDCleaner.exe" /autoclean.
Registry entries (User):
  • SDDelFile.exe is loaded once in the current user (HKCU) registry as a startup file name 'SpybotDeletingF6579' which loads as "C:\Program Files\Spybot - Search & Destroy 2\SDDelFile.exe" "C:\Program Files\SweetIM\Toolbars\Internet Explorer\resources\yahoo.png".

Software Details

URL:
https://www.safer-networking.org/2012/spybot-2-now-available-for-download
Support:
https://www.safer-networking.org/index.php?page=support
Installation path:
C:\Program Files\Spybot - Search & Destroy 2\
Uninstaller:
"C:\Program Files\Spybot - Search & Destroy 2\unins000.exe"
Size:
242.00 MB
Language:
English

Spybot - Search & Destroy 2 Executable Details

Primary executable:
SDWelcome.exe
Name:
Spybot - Search & Destroy 2
Path:
C:\Program Files\Spybot - Search & Destroy 2\SDWelcome.exe
MD5:
SHA-1:
SHA-256:
Files installed by Spybot - Search & Destroy 2
File Type Filename MD5
EXE
1fad329e737035007f56aaea6d1a96fc
EXE
6dab995489baabbf6aa4aae20faa3ca9
EXE
fd40ac57811363ced2409d1f5dae17e0
DLL
205887b4a304cf59f825de472b76466d
DLL
62a14a2c2159b578b23da416ef65645c
EXE
27d73a81a28248b0a1565586affa586f
EXE
336d0146a071d46c61758b84b5f9618f
EXE
bd6820343982410852fe79ec08acfc97
EXE
927d3a9ebbc35b7fa275dee916220cf5
DLL
2034908b51435a1f912d1aee35ef756c