Spybot - Search & Destroy 2

Spybot - Search & Destroy 2

by Safer-Networking Ltd.

What is Spybot - Search & Destroy 2?

Spybot - Search & Destroy 2 is software application developed by Safer-Networking Ltd.. It is most commonly found on computers running Windows 7 with nearly 72.14% of installations running this operating system. Spybot - Search & Destroy 2's installer is typically 242.00 MB in size and installs around 59 files. The most common release is 2.0.3 with 30.00% of all installations currently using this version.

Spybot - Search & Destroy 2 is most popular in the United States with 62.96% of installations residing in this country.

Spybot - Search & Destroy 2 adds 3 scheduled tasks to the Windows Task Scheduler launching the program at randomly scheduled times. When using a computer that is connected to the internet, Spybot - Search & Destroy 2 is known to create 6 firewall exceptions to allow inbound and outbound connectivity.

About Spybot - Search & Destroy 2?

Spybot - Search & Destroy is a comprehensive spyware and adware removal software application designed for use on the Microsoft Windows operating system. The program is capable of performing scans on both the computer hard disk and RAM in order to detect and remove potentially malicious software. In addition to its spyware and adware detection and disinfection capabilities, Spybot - Search & Destroy can also repair the registry, winsock LSPs, ActiveX objects, browser hijackers and BHOs, PUPS, computer cookies, trackerware, heavy duty, homepage hijackers, keyloggers, LSP, tracks, trojans, spybots, revisions, and other forms of malware. Furthermore, the software is able to delete tracking cookies, further enhancing its security features.

Software Behaviors

Services:
  • SDUpdSvc.exe runs as a service named 'Spybot-S&D 2 Updating Service' (SDUpdateService) "Downloads updates and installs them.".
  • SDHookSvc.exe runs as a service named 'Spybot-S&D 2 Hooks Service' (SDHookService) "Helps Spybot monitoring the system.".
  • SDFSSvc.exe runs as a service named 'Spybot-S&D 2 Scanner Service' (SDScannerService) "Offers malware scanning services to Spybot-S&D modules.".
  • SDWSCSvc.exe runs as a service named 'Spybot-S&D 2 Security Center Service' (SDWSCService) "Integrates Spybot into the Windows Security Center.".
  • SDMonSvc.exe runs as a service named 'Spybot-S&D 2 Monitoring Service' (SDMonitorService) "Offers on-access protection from spyware, viruses and other malware.".
  • SDFWSvc.exe runs as a service named 'Spybot-S&D 2 Firewall Service' (SDFirewallService) "Offers various network protection services.".
Firewall:
  • SDFSSvc.exe is added as a firewall exception for 'C:\Program Files\Spybot - Search & Destroy 2\SDFSSvc.exe'.
  • SDMonSvc.exe is added as a firewall exception for 'C:\ProgramyMnouInstalovane\Spybot - Search & Destroy 2\SDMonSvc.exe'.
  • SDFWSvc.exe is added as a firewall exception for 'C:\ProgramyMnouInstalovane\Spybot - Search & Destroy 2\SDFWSvc.exe'.
  • SDUpdSvc.exe is added as a firewall exception for 'C:\Program Files\Spybot - Search & Destroy 2\SDUpdSvc.exe'.
  • SDUpdate.exe is added as a firewall exception for 'C:\Program Files\Spybot - Search & Destroy 2\SDUpdate.exe'.
  • SDTray.exe is added as a firewall exception for 'C:\Program Files\Spybot - Search & Destroy 2\SDTray.exe'.
Scheduled tasks:
  • explorer.exe is scheduled as a task named 'Scan the system (Spybot - Search & Destroy)' (runs daily at 3:00 AM).
  • SDImmunize.exe is scheduled as a task named 'Refresh immunization (Spybot - Search & Destroy)' (runs weekly on Thursdays at 10.30).
  • SDScan.exe is scheduled as a task named 'Scan the system' (runs monthly on Mondays at 12:30 AM).

Startup Entries

Startup tasks:
  • explorer.exe is automatically launched at startup through a scheduled task named Scan the system (Spybot - Search & Destroy).
  • SDImmunize.exe is automatically launched at startup through a scheduled task named Refresh immunization (Spybot - Search & Destroy).
  • SDUpdate.exe is automatically launched at startup through a scheduled task named Check for updates (Spybot - Search & Destroy).
  • SDScan.exe is automatically launched at startup through a scheduled task named Scan the system (Spybot - Search & Destroy).
Registry entries:
  • SDCleaner.exe is loaded in the current user (HKCU) registry as an auto-starting executable named 'Spybot-S&D Cleaning' and executes as "C:\Program Files\Spybot - Search & Destroy 2\SDCleaner.exe" /autoclean.
Registry entries (User):
  • SDDelFile.exe is loaded once in the current user (HKCU) registry as a startup file name 'SpybotDeletingF6579' which loads as "C:\Program Files\Spybot - Search & Destroy 2\SDDelFile.exe" "C:\Program Files\SweetIM\Toolbars\Internet Explorer\resources\yahoo.png".

Software Details

URL:
https://www.safer-networking.org/2012/spybot-2-now-available-for-download
Support:
https://www.safer-networking.org/index.php?page=support
Installation path:
C:\Program Files\Spybot - Search & Destroy 2\
Uninstaller:
"C:\Program Files\Spybot - Search & Destroy 2\unins000.exe"
Size:
242.00 MB
Language:
English

Spybot - Search & Destroy 2 Executable Details

Primary executable:
SDWelcome.exe
Name:
Spybot - Search & Destroy 2
Path:
C:\Program Files\Spybot - Search & Destroy 2\SDWelcome.exe
MD5:
SHA-1:
SHA-256:
Files installed by Spybot - Search & Destroy 2
File Type Filename MD5
DLL
8d30c9400e373f39331a6d0b833b3449
DLL
6d17ab09cc250b15156cc73c3dc68955
EXE
8761156b8aa3de1a8548212cb8d8f6eb
DLL
4c2fbc6b8e3843b986c8fcdf5faee226
EXE
0c8a578cbcf8232bfcce1a7858e60a8b
EXE
c99803671dff097675cc3ce9ce2d4409
DLL
07a1bdda378310359bed72d12abd17d9
DLL
0600d19da5441a49f6de562a7b1b781f
DLL
ae1a793355cef2e4b11433c02ec70b2e
EXE
369be40476ea1c2b58a514619e3d5ddc