84,488,480 programs installed

Should I remove Spybot - Search & Destroy?

What percent of users and experts removed it?
10% remove it90% keep it
Overall Sentiment
Poor
What do people think about it?
(click star to rate)
How common is it?
Global Rank #11,966
United States Rank #9,807
Reach 0.0273%
Lifespan of installation (until removal)
< 10.85 days
320.05 days >
Average installed length: 168.16 days

Versions

VersionDistribution
1.4 100.00%

Spybot - Search & Destroy 1.4

What is Spybot - Search & Destroy?

Spybot Search & Destroy (S&D) is a spyware and adware removal computer program compatible with Microsoft Windows. It scans the computer hard disk and/or RAM for malicious software. In addition to spyware and adware detection and disinfection, Spybot-S&D can repair the registry, winsock LSPs, ActiveX objects, browser hijackers and BHOs, PUPS, computer cookies, trackerware, heavy duty, homepage hijackers, keyloggers, LSP, tracks, trojans, spybots, revision, and other kinds of malware. It can also delete tracking cookies.

About  (from Safer-Networking)

Spybot - Search & Destroy can detect and remove a multitude of adware files and modules from your computer. Spybot also can clean program and Web-usage tracks from your system, which is especially useful if you share your computer. Modules chosen for removal can be sent directly to the included file shredder, ensuring ...  Read more

Overview

During setup, the program creates a startup registration point in Windows in order to automatically start when any user boots the PC. Upon being installed, the software adds a Windows Service which is designed to run continuously in the background. Manually stopping the service has been seen to cause the program to stop functing properly. It adds a background controller service that is set to automatically run. Delaying the start of this service is possible through the service manager. The program adds a toolbar to Microsoft Internet Explorer. A scheduled task is added to Windows Task Scheduler in order to launch the program at various scheduled times (the schedule varies depending on the version). The software is designed to connect to the Internet and adds a Windows Firewall exception in order to do so without being interfered with. When installed, it will add a context menu handler to the Windows shell in order to provide quick access to the program. The primary executable is named spybotsd.exe. The setup package generally installs about 61 files and is usually about 19.14 MB (20,071,048 bytes). The installed file SDUpdate.exe is the auto-update component of the program which is designed to check for software updates and notify and apply them when new versions are discovered.

Program detailsProgram details

URL: www.safer-networking.org
Installation folder: C:\Program Files\Spybot - Search & Destroy\
Uninstaller: "C:\Program Files\Spybot - Search & Destroy\unins000.exe"
Estimated size: 19.14 MB

Program filesFiles installed by Spybot - Search & Destroy 1.4

Program executable:spybotsd.exe
Name:SpyBot-S&D
Spybot - Search & Destroy
Path:C:\Program Files\spybot - search & destroy\spybotsd.exe
MD5:3b1b5d09d3c9c4cd39d4db06ed7a0855
Additional files:
  • advcheck.dll - Spybot - Search & Destroy (Dateiüberprüfungs-Bibliothek)
  • blindman.exe - Dummy
  • explorer.exe - Malware Scanner
  • SDAdvancedCheckLibrary.dll - File check library
  • SDBootCD.exe - Create a bootable CD with Spybot-S&D on it.
  • SDCleaner.exe - Search results cleaner
  • SDDelFile.exe - Kommandozeilen-Dateientfernen-Werkzeug für Spybot-S&D
  • SDECon32.dll - Windows Explorer context menu integration
  • SDECon64.dll
  • SDEvents.dll - Event Log helper for Spybot - Search & Destroy
  • SDFiles.exe - Single file on-demand scanner
  • SDFileScanHelper.exe - File scan helper for network files.
  • SDFileScanLibrary.dll - File Scanning services library.
  • SDFSSvc.exe - Spybot-S&D 2 Scanner Service
  • SDHelper.dll - Bad download blocker
  • SDHook32.dll - Live Protection
  • SDHook64.dll
  • SDHookHelper.exe - Live Protection Helper
  • SDHookInst32.exe - Live Protection Configuration Tool
  • SDHookInst64.exe
  • SDImmunize.exe - Pro-active browser protection
  • SDImmunizeLibrary.dll - Immunization handling library
  • SDLists.dll - Malware list management library
  • SDLogReport.exe - Create report archive
  • SDOnAccess.exe - On Access protection dialog
  • SDPESetup.exe - Basic configuration for systems running PE
  • SDPEStart.exe - PE Start Menu
  • SDPhoneScan.exe - Scans local files belonging to mobile phones.
  • SDPRE.exe - Opens a protected repair desktop
  • SDPrepPos.exe - System Whitelist Preparation
  • SDQuarantine.exe - Allows to restore cleaned files.
  • SDResources.dll - Various user interface resources.
  • SDRootAlyzer.exe - Rootkit scanner
  • SDUpdate.exe - Updater for Spybot-S&D
  • spybotsd160.exe
  • TeaTimer.exe - System settings protector
  • Tools.dll - Bibliothek für Spybot-S&D
  • UninsSrv.dll - Uninstallation survey
  • Update.exe - External updater
  • SDShred.exe - Secure Shredder (File shredder formerly integrated into Spybot-S&D)
  • SDFiles.dll - SpyBot-S&D (Spybot - Search & Destroy File Scanner)
  • SDHelp.exe
  • SDLicense.dll
  • SDMain.exe - Spybot-S&D Security Center launcher
  • SDWinSec.exe - Spybot-S&D Security Center integration
  • unins000.exe - Inno Setup (Setup/Uninstall)
  • unins001.exe

Program behaviorsBehaviors exhibited

Autoplay Handler
  • SDFiles.exe is registered as an AutoPlay event handler named 'SpybotScanFiles' with the ProgID of 'SpybotFilesScanner' and the action verb 'scanfiles.
2 Context Menu Handlers
  • SDECon32.dll added to Windows Explorer under the name 'SDECon32' with a class of {44176360-2BBF-4EC1-93CE-384B8681A0BC}.
  • SDECon64.dll added to Windows Explorer under the name 'SDECon64' with a class of {44176360-2BBF-4EC1-93CE-384B8681A0BC}.
Internet Explorer BHO
  • SDHelper.dll is installed in Internet Explorer as a BHO (Browser Helper Object) under the name 'McAfee SiteAdvisor BHO' with the class of {B164E929-A1B6-4A06-B104-2CD0E90A88FF}.
Internet Explorer Extension
  • SDHelper.dll is installed as an Internet Explorer extension using the class {DFB852A3-47F8-48C4-A200-58CAB36FD2A2}.
Internet Explorer Toolbar
  • SDHelper.dll is loaded as Internet Explorer Toolbar with the name 'McAfee SiteAdvisor Toolbar' with the class of {0EBBBE48-BAD4-4B4C-8E5A-516ABECAE064} (McAfee SiteAdvisor).
Internet Explorer URL Search Hook
  • SDHelper.dll loads into IE as a URL Search Hook named 'McAfee SiteAdvisor Toolbar' with a class of {0EBBBE48-BAD4-4B4C-8E5A-516ABECAE064} in order to redirect unknown URL searches.
Internet Explorer Web Browser
  • SDHelper.dll installs an IE Web Browser in Internet Explorer named '&Crawler Toolbar' with a class of {C4D78C72-08DB-4A3F-9175-B265157283F3}.
11 Scheduled Tasks
  • SpybotSD.exe is scheduled as a task with the class '{DF53BA36-E6AD-4933-ABA4-3205B316BF82}' (runs on registration).
  • SDUpdate.exe is scheduled as a task with the class '{DB90B1BA-0DB7-416C-9776-6960F9A69ECF}' (runs on registration).
  • SDMain.exe is scheduled as a task named 'Spybot' (runs daily at 6:00 PM).
  • SDShred.exe is scheduled as a task with the class '{192F682F-8BC3-4B14-AF53-A907FE8CBCBF}' (runs on registration).
  • unins001.exe is scheduled as a task with the class '{E253CDA2-9362-4542-A47D-5D5FF5EEF4FA}' (runs on registration).
  • explorer.exe is scheduled as a task named 'Scan the system (Spybot - Search & Destroy)' (runs monthly on Saturdays at 12:30 AM).
  • Plus 5 more
2 Scheduled Tasks (Boot/Login)
  • TeaTimer.exe is automatically launched at startup through a scheduled task named 2.
  • SpybotSD.exe is automatically launched at startup through a scheduled task named Spybot - Search & Destroy.
2 Services
  • SDFSSvc.exe runs as a service named 'Spybot-S&D 2 Scanner Service' (SDScannerService) "Offers malware scanning services to Spybot-S&D modules".
  • SDWinSec.exe runs as a service named 'SBSD Security Center Service' (SBSDWSCService).
2 Startup Files (User Run)
  • SDCleaner.exe is loaded in the current user (HKCU) registry as an auto-starting executable named 'Spybot-S&D Cleaning' and executes as "C:\Program Files\Spybot - Search & Destroy 2\SDCleaner.exe" /autoclean.
  • TeaTimer.exe is loaded in the current user (HKCU) registry as an auto-starting executable named 'SpybotSD TeaTimer' and executes as C:\Program Files\Spybot - Search & Destroy\TeaTimer.exe.
4 Startup Files (All Users Run)
  • SDMain.exe is loaded in the all users (HKLM) registry as a startup file name 'Spybot' which loads as C:\Program Files\Spybot - Search & Destroy\SDMain.exe.
  • SDCleaner.exe is loaded in the all users (HKLM) registry as a startup file name 'Spybot-S&D Cleaning' which loads as "C:\Program Files\Spybot - Search & Destroy 2\SDCleaner.exe" /autoclean.
  • TeaTimer.exe is loaded in the all users (HKLM) registry as a startup file name 'TeaTimer.exe' which loads as W:\Program Files\Spybot - Search & Destroy\TeaTimer.exe.
  • SpybotSD.exe is loaded in the all users (HKLM) registry as a startup file name 'SpybotSnD' which loads as "C:\Program Files\Spybot - Search & Destroy\SpybotSD.exe".
Startup File (All Users Run Once)
  • SpybotSD.exe is loaded once in the all users (HKLM) registry as a startup file name 'SpybotSnD' which loads as "C:\Program Files\Spybot - Search & Destroy\SpybotSD.exe" /autocheck.
8 Windows Firewall Allowed Programs
  • SDFSSvc.exe is added as a firewall exception for 'C:\Program Files\Spybot - Search & Destroy 2\SDFSSvc.exe'.
  • SDUpdate.exe is added as a firewall exception for 'C:\Program Files\Spybot\SDUpdate.exe'.
  • SpybotSD.exe is added as a firewall exception for 'C:\Program Files\Spybot - Search & Destroy\SpybotSD.exe'.
  • Update.exe is added as a firewall exception for 'C:\Program Files\Spybot - Search & Destroy\Update.exe'.
  • unins001.exe is added as a firewall exception for 'C:\Program Files\Spybot - Search & Destroy\unins000.exe'.
  • SDShred.exe is added as a firewall exception for 'C:\Program Files\Spybot - Search & Destroy\SDShred.exe'.
  • Plus 2 more

Program resource utilizationResource utilization averages

TeaTimer.exe
Memory:72.11 MB
21.09 MB average
Total CPU:0.0070373328%
0.031193% average
Kernel CPU:0.00246928%
0.016088% average
User CPU:0.00456806%
0.015104% average
CPU cycles/sec:14,792,179
8,062,084 average
Switches/sec:138
70 average
I/O reads/min:83.88 KB
435.61 KB average
I/O writes/min:42.94 KB
105.02 KB average
SpybotSD.exe
Memory:44.77 MB
Total CPU:1.6544138927%
Kernel CPU:0.35269601%
User CPU:1.30171788%
Switches/sec:117
I/O reads/min:268.63 KB
I/O writes/min:45 Bytes
SDWinSec.exe
Memory:13.14 MB
Total CPU:0.0018679375%
Kernel CPU:0.00121284%
User CPU:0.00065510%
CPU cycles/sec:370,972
I/O reads/min:2.81 KB

How do I remove Spybot - Search & Destroy?

You can uninstall Spybot - Search & Destroy from your computer by using the Add/Remove Program feature in the Window's Control Panel.
  1. On the Start menu (for Windows 8, right-click the screen's bottom-left corner), click Control Panel, and then, under Programs, do one of the following:
    • Windows Vista/7/8/10: Click Uninstall a Program.
    • Windows XP: Click Add or Remove Programs.
  2. When you find the program Spybot - Search & Destroy 1.4, click it, and then do one of the following:
    • Windows Vista/7/8/10: Click Uninstall.
    • Windows XP: Click the Remove or Change/Remove tab (to the right of the program).
  3. Follow the prompts. A progress bar shows you how long it will take to remove Spybot - Search & Destroy.

How do I reset my web browser?

If your web browser homepage and search settings have been modfied by Spybot - Search & Destroy 1.4 you can restore them to their previous default settings.
Microsoft Internet Explorer
Mozilla Firefox
Google Chrome

OS VERSIONS
Win XP 49%
Win Vista 0%
 
HOW IT STARTS
Automatically starts? Yes
(Found in the run registry)
 
USER ACTIONS
Uninstall it 10%
Keep it 90%

Windows OS versionsWindows

Which Windows OS versions does it run on?
Windows XP 53.52%
Windows 7 25.56%
Windows Vista 16.11%
Windows 10 4.63%
Windows Server 2003 0.19%
Which OS releases does it run on?
Microsoft Windows XP 53.64%
Windows 7 Home Premium 13.41%
Windows Vista Home Premiu... 12.84%
Windows 7 Ultimate 6.13%
Windows 7 Professional 4.41%
Windows Vista Home Basic 2.30%

Distribution by countryGeography

55.13% of installs come from the United States
Which countries install it?
  United States 55.13%
  France 5.72%
  United Kingdom 5.57%
  Italy 4.84%
  Germany 3.96%
  Canada 3.37%
  Netherlands 2.64%
  Israel 2.35%
  Spain 1.61%
  Brazil 1.47%
  Australia 1.17%
  Belgium 0.88%
  Japan 0.88%
  Taiwan 0.73%

OEM distributionPC manufacturers

What PC manufacturers (OEMs) have it installed?
Dell 32.38%
Hewlett-Packard 18.10%
Acer 10.16%
Intel 9.21%
American Megatrends 8.57%
Sahara 6.03%
Toshiba 5.71%
GIGABYTE 5.40%
ASUS 4.44%
Common models
Dell Dell DM061 3.25%
Dell Computer Dimension 4... 2.60%
Dell Latitude D820 2.60%
NVIDIA AWRDACPI 2.60%
Dell Dell DXP051 1.95%
Dell Inspiron 530s 1.95%

About (from Safer-Networking Ltd.)

Spybot is maintained by a team of people very dedicated to privacy issues, many of which are working full-time on analysing masses of new threats each week, and the response time from our support team is better than that of many a commercial vendor.
Publisher URL: www.safer-networking.org

commentsComments

user comment
No one has commented yet. Help others learn more about this software, share your comments.