Spybot - Search & Destroy

Spybot - Search & Destroy

by Safer-Networking Ltd.

What is Spybot - Search & Destroy?

Spybot - Search & Destroy is software application developed by Safer-Networking Ltd.. It is most commonly found on computers running Windows 7 with nearly 63.60% of installations running this operating system. Spybot - Search & Destroy's installer is typically 65.00 MB in size and installs around 114 files. The most common release is 1.3 with 30.93% of all installations currently using this version.

Spybot - Search & Destroy is most popular in the United States with 61.58% of installations residing in this country.

Spybot - Search & Destroy adds 1 scheduled task to the Windows Task Scheduler launching the program at randomly scheduled times. When using a computer that is connected to the internet, Spybot - Search & Destroy is known to create 1 firewall exception to allow inbound and outbound connectivity.

About Spybot - Search & Destroy?

Spybot Search & Destroy (S&D) is a professional-grade spyware and adware removal software designed specifically for Microsoft Windows operating systems. It conducts a thorough scan of the computer's hard disk and RAM to identify and eliminate malicious software. In addition to detecting and disinfecting spyware and adware, Spybot-S&D can also address issues with the registry, winsock LSPs, ActiveX objects, browser hijackers, PUPS, computer cookies, trackerware, homepage hijackers, keyloggers, LSP, tracks, trojans, spybots, revision, and various other types of malware. The program is also capable of removing tracking cookies for an added layer of protection.

Software Behaviors

Services:
  • SDWinSec.exe runs as a service named 'SBSD Security Center Service' (SBSDWSCService).
Firewall:
  • SDMain.exe is added as a firewall exception for 'C:\Program Files\Spybot - Search & Destroy\SDMain.exe'.
Scheduled tasks:
  • SDWinSec.exe is scheduled as a task with the class '{FC9AC3CC-0EC6-4CF1-96F3-CF906C157937}' (runs on registration).

Startup Entries

Startup tasks:
  • TeaTimer.exe is automatically launched at startup through a scheduled task named 2.
  • SpybotSD.exe is automatically launched at startup through a scheduled task named Spybot - Search & Destroy.
Registry entries:
  • TeaTimer.exe is loaded in the current user (HKCU) registry as an auto-starting executable named 'SpybotSD TeaTimer' and executes as C:\Program Files\Spybot - Search & Destroy\TeaTimer.exe.
  • SDCleaner.exe is loaded in the current user (HKCU) registry as an auto-starting executable named 'Spybot-S&D Cleaning' and executes as "C:\Program Files\Spybot - Search & Destroy 2\SDCleaner.exe" /autoclean.
  • TeaTimer_original.exe is loaded in the current user (HKCU) registry as an auto-starting executable named 'SpybotSD TeaTimer' and executes as C:\Program Files\Spybot - Search & Destroy\TeaTimer.exe.

Software Details

URL:
https://www.safer-networking.org
Support:
https://www.safer-networking.org/index.php?page=support
Installation path:
C:\Program Files\Spybot - Search & Destroy\
Uninstaller:
"C:\Program Files\Spybot - Search & Destroy\unins000.exe"
Size:
65.00 MB
Language:
English

Spybot - Search & Destroy Executable Details

Primary executable:
SpybotSD.exe
Name:
Spybot - Search & Destroy
Path:
C:\Program Files\Spybot - Search & Destroy\SpybotSD.exe
MD5:
SHA-1:
SHA-256:
Files installed by Spybot - Search & Destroy
File Type Filename MD5
EXE
0e7fbf50f87b3b7c384a2471154a7558
EXE
86886a4fdfcf46c982cf40365f992877
EXE
c6ecbbad00855d5a385ae669d701b08e
EXE
0861729511040ceeb6a327d57c15b826
EXE
86052a629365f227b20c1d435ceda72d
EXE
de1415654a49bd8262dd945fd4c54d7c
EXE
3b3cbcb12f6cb6ca00c6a08f0f1b7d15
EXE
322208cd558a6bb7f4952f8dd90cb165
EXE
2ba9affde36331cc9bac4f4af51655f2
DLL
2c7ced993b865ad900bc00abd3aeb977