Spybot - Search & Destroy 2

Spybot - Search & Destroy 2

by Safer-Networking Ltd.

What is Spybot - Search & Destroy 2?

Spybot - Search & Destroy 2 is software application developed by Safer-Networking Ltd.. It is most commonly found on computers running Windows 7 with nearly 72.14% of installations running this operating system. Spybot - Search & Destroy 2's installer is typically 242.00 MB in size and installs around 59 files. The most common release is 2.0.3 with 30.00% of all installations currently using this version.

Spybot - Search & Destroy 2 is most popular in the United States with 62.96% of installations residing in this country.

Spybot - Search & Destroy 2 adds 3 scheduled tasks to the Windows Task Scheduler launching the program at randomly scheduled times. When using a computer that is connected to the internet, Spybot - Search & Destroy 2 is known to create 6 firewall exceptions to allow inbound and outbound connectivity.

About Spybot - Search & Destroy 2?

Spybot - Search & Destroy is a comprehensive spyware and adware removal software application designed for use on the Microsoft Windows operating system. The program is capable of performing scans on both the computer hard disk and RAM in order to detect and remove potentially malicious software. In addition to its spyware and adware detection and disinfection capabilities, Spybot - Search & Destroy can also repair the registry, winsock LSPs, ActiveX objects, browser hijackers and BHOs, PUPS, computer cookies, trackerware, heavy duty, homepage hijackers, keyloggers, LSP, tracks, trojans, spybots, revisions, and other forms of malware. Furthermore, the software is able to delete tracking cookies, further enhancing its security features.

Software Behaviors

Services:
  • SDUpdSvc.exe runs as a service named 'Spybot-S&D 2 Updating Service' (SDUpdateService) "Downloads updates and installs them.".
  • SDHookSvc.exe runs as a service named 'Spybot-S&D 2 Hooks Service' (SDHookService) "Helps Spybot monitoring the system.".
  • SDFSSvc.exe runs as a service named 'Spybot-S&D 2 Scanner Service' (SDScannerService) "Offers malware scanning services to Spybot-S&D modules.".
  • SDWSCSvc.exe runs as a service named 'Spybot-S&D 2 Security Center Service' (SDWSCService) "Integrates Spybot into the Windows Security Center.".
  • SDMonSvc.exe runs as a service named 'Spybot-S&D 2 Monitoring Service' (SDMonitorService) "Offers on-access protection from spyware, viruses and other malware.".
  • SDFWSvc.exe runs as a service named 'Spybot-S&D 2 Firewall Service' (SDFirewallService) "Offers various network protection services.".
Firewall:
  • SDFSSvc.exe is added as a firewall exception for 'C:\Program Files\Spybot - Search & Destroy 2\SDFSSvc.exe'.
  • SDMonSvc.exe is added as a firewall exception for 'C:\ProgramyMnouInstalovane\Spybot - Search & Destroy 2\SDMonSvc.exe'.
  • SDFWSvc.exe is added as a firewall exception for 'C:\ProgramyMnouInstalovane\Spybot - Search & Destroy 2\SDFWSvc.exe'.
  • SDUpdSvc.exe is added as a firewall exception for 'C:\Program Files\Spybot - Search & Destroy 2\SDUpdSvc.exe'.
  • SDUpdate.exe is added as a firewall exception for 'C:\Program Files\Spybot - Search & Destroy 2\SDUpdate.exe'.
  • SDTray.exe is added as a firewall exception for 'C:\Program Files\Spybot - Search & Destroy 2\SDTray.exe'.
Scheduled tasks:
  • explorer.exe is scheduled as a task named 'Scan the system (Spybot - Search & Destroy)' (runs daily at 3:00 AM).
  • SDImmunize.exe is scheduled as a task named 'Refresh immunization (Spybot - Search & Destroy)' (runs weekly on Thursdays at 10.30).
  • SDScan.exe is scheduled as a task named 'Scan the system' (runs monthly on Mondays at 12:30 AM).

Startup Entries

Startup tasks:
  • explorer.exe is automatically launched at startup through a scheduled task named Scan the system (Spybot - Search & Destroy).
  • SDImmunize.exe is automatically launched at startup through a scheduled task named Refresh immunization (Spybot - Search & Destroy).
  • SDUpdate.exe is automatically launched at startup through a scheduled task named Check for updates (Spybot - Search & Destroy).
  • SDScan.exe is automatically launched at startup through a scheduled task named Scan the system (Spybot - Search & Destroy).
Registry entries:
  • SDCleaner.exe is loaded in the current user (HKCU) registry as an auto-starting executable named 'Spybot-S&D Cleaning' and executes as "C:\Program Files\Spybot - Search & Destroy 2\SDCleaner.exe" /autoclean.
Registry entries (User):
  • SDDelFile.exe is loaded once in the current user (HKCU) registry as a startup file name 'SpybotDeletingF6579' which loads as "C:\Program Files\Spybot - Search & Destroy 2\SDDelFile.exe" "C:\Program Files\SweetIM\Toolbars\Internet Explorer\resources\yahoo.png".

Software Details

URL:
https://www.safer-networking.org/2012/spybot-2-now-available-for-download
Support:
https://www.safer-networking.org/index.php?page=support
Installation path:
C:\Program Files\Spybot - Search & Destroy 2\
Uninstaller:
"C:\Program Files\Spybot - Search & Destroy 2\unins000.exe"
Size:
242.00 MB
Language:
English

Spybot - Search & Destroy 2 Executable Details

Primary executable:
SDWelcome.exe
Name:
Spybot - Search & Destroy 2
Path:
C:\Program Files\Spybot - Search & Destroy 2\SDWelcome.exe
MD5:
SHA-1:
SHA-256:
Files installed by Spybot - Search & Destroy 2
File Type Filename MD5
EXE
89bd140c9e326eef41d7f8d209fa0075
EXE
2d4d8c6847b1a61789aa5c76f340dece
DLL
17d52881aa44847ef79ae1d3e0c9b462
EXE
ec07d28ac625f9f521d05f8cbda6dcef
DLL
951bce0127b5fbaa9bbe38a428d4f665
DLL
2275d8e9845bf04a8d1422ec7698e73a
EXE
2235f37d1225a717d98547a3b347576c
EXE
b23e94bdeb2aae7017554983fc47f628
EXE
348940e83b13a1c2840876172e8d98b2
DLL
41bd7fc1f91a0f367aca60aca2808e47