84,488,480 programs installed

Should I remove Spybot - Search & Destroy?

What percent of users and experts removed it?
8% remove it92% keep it
Overall Sentiment
Poor
What do people think about it?
(click star to rate)
How common is it?
Global Rank #165
United States Rank #152
Reach 3.1579%
(Not enough data to show 30 day installation trends)
Uninstallation trends (last 30 days)
Lifespan of installation (until removal)
< 14.62 days
431.16 days >
Average installed length: 226.54 days

Versions

VersionDistribution
2.7.64.0 0.26%
2.6.46 1.83%
2.5.43 5.61%
2.4.40 41.42%
2.3.39 5.97%
2.3.37 0.50%
2.2.25 18.48%
2.1.21 5.51%
2.1.20 1.64%
2.1.19 4.38%
2.1.17 0.01%
2.0.12 14.05%
2.0.11 0.16%
2.0.10 0.08%
2.0.9 0.02%
2.0.8 0.07%

Spybot - Search & Destroy

What is Spybot - Search & Destroy?

Spybot Search & Destroy (S&D) is a spyware and adware removal computer program compatible with Microsoft Windows. It scans the computer hard disk and/or RAM for malicious software. In addition to spyware and adware detection and disinfection, Spybot-S&D can repair the registry, winsock LSPs, ActiveX objects, browser hijackers and BHOs, PUPS, computer cookies, trackerware, heavy duty, homepage hijackers, keyloggers, LSP, tracks, trojans, spybots, revision, and other kinds of malware. Spybot – Search & Destroy is released as freeware for personal users, and available on purchase of an annual licence to corporate users.

About  (from Safer-Networking)

Spybot - Search & Destroy can detect and remove a multitude of adware files and modules from your computer. Spybot also can clean program and Web-usage tracks from your system, which is especially useful if you share your computer. Modules chosen for removal can be sent directly to the included file shredder, ensuring ...  Read more
Overview
  • Starts automatically
  • Integrates into the web browser
  • Connects to the Internet
  • Adds a Windows Service

Program detailsProgram details

URL: www.safer-networking.org
Help link: www.safer-networking.org/contact
Installation folder: C:\Program Files\Spybot - Search & Destroy 2\
Uninstaller: "C:\Program Files\Spybot - Search & Destroy 2\unins000.exe"
Estimated size: 162.69 MB

Program filesFiles installed by Spybot - Search & Destroy

Program executable:sdwelcome.exe
Name:Spybot - Search & Destroy
Start Center
Signed by:Safer Networking Ltd.
Path:C:\Program Files\spybot - search & destroy 2\sdwelcome.exe
MD5:1e95079afdb035878460d797be585d3d
Additional files:
  • spybotsd2-install-bdcore-update.exe - Spybot - Search & Destroy - Antivirus Update (Antivirus update for Spybot - Search & Destroy)
  • blindman.exe - Spybot - Search & Destroy (Dummy)
  • DelZip192.dll - Freeware Zip compression
  • explorer.exe - Malware Scanner
  • libeay32.dll - OpenSSL Shared Library
  • NotificationSpreader.dll - Support library for notifying user
  • sd2-installer.exe
  • SDAdvancedCheckLibrary.dll - File check library
  • SDAV.dll
  • SDBootCD.exe - Create a bootable CD with Spybot-S&D on it.
  • SDCleaner.exe - Search results cleaner
  • SDDelFile.exe - File remover for stubborn files
  • SDECon32.dll - Windows Explorer context menu integration
  • SDECon64.dll
  • SDEvents.dll - Event Log helper for Spybot - Search & Destroy
  • SDFiles.exe - Single file on-demand scanner
  • SDFileScanHelper.exe - File scan helper for network files.
  • SDFileScanLibrary.dll - File Scanning services library.
  • SDFSSvc.exe - Spybot-S&D 2 Scanner Service
  • SDHelp.exe
  • SDHelper.dll - Blocks URLs that could install spyware, malware etc.
  • SDHook32.dll - Live Protection
  • SDHook64.dll
  • SDHookDrv32.sys
  • SDHookDrv64.sys
  • SDHookHelper.exe - Live Protection Helper
  • SDHookInst32.exe - Live Protection Configuration Tool
  • SDHookInst64.exe
  • SDImmunize.exe - Pro-active browser protection
  • SDImmunizeLibrary.dll - Immunization handling library
  • SDLicense.dll
  • SDLists.dll - Malware list management library
  • SDLogReport.exe - Create report archive
  • SDOnAccess.exe - On Access protection dialog
  • SDPESetup.exe - Basic configuration for systems running PE
  • SDPEStart.exe - PE Start Menu
  • SDPhoneScan.exe - Scans local files belonging to mobile phones.
  • SDPRE.exe - Opens a protected repair desktop
  • SDPrepPos.exe - System Whitelist Preparation
  • SDQuarantine.exe - Allows to restore cleaned files.
  • SDResources.dll - Various user interface resources.
  • SDRootAlyzer.exe - Rootkit scanner
  • SDSBIEdit.exe - Detection database editor
  • SDScan.exe
  • SDScanLibrary.dll - Spybot - Search & Destroy Scan Engine
  • SDScript.exe - Script editor
  • SDSettings.exe - Settings
  • SDShred.exe - Permanently removes (shreds) files.
  • SDSysRepair.exe - System Repair
  • SDTasks.dll - Library to help managing scheduled tasks
  • SDTools.exe - Autostart and Configuration Manager
  • SDTray.exe - Spybot - Search & Destroy tray access
  • SDUpdate.exe - Update
  • SDUpdSvc.exe - Spybot-S&D 2 Background update service
  • SDWinLogon.dll - Logon time cleaner
  • SDWSCSvc.exe - Windows Security Center integration.
  • Tools.dll - Library for various small tasks.
  • UninsSrv.dll - Uninstallation survey
  • SDLicense.exe
  • SDShell.exe

Program behaviorsBehaviors exhibited

2 Autoplay Handlers
  • SDFiles.exe is registered as an AutoPlay event handler named 'SpybotScanFiles' with the ProgID of 'SpybotFilesScanner' and the action verb 'scanfiles.
  • SDSettings.exe is registered as an AutoPlay event handler named 'SpybotScanFiles' with the ProgID of 'SpybotFilesScanner' and the action verb 'scanfiles.
2 Context Menu Handlers
  • SDECon32.dll added to Windows Explorer under the name 'SDECon32' with a class of {44176360-2BBF-4EC1-93CE-384B8681A0BC}.
  • SDECon64.dll added to Windows Explorer under the name 'SDECon64' with a class of {44176360-2BBF-4EC1-93CE-384B8681A0BC}.
Internet Explorer BHO
  • SDHelper.dll is installed in Internet Explorer as a BHO (Browser Helper Object) under the name 'Spybot-S&D IE Protection' with the class of {53707962-6F74-2D53-2644-206D7942484F}.
Internet Explorer Extension
  • SDHelper.dll is installed as an Internet Explorer extension using the class {DFB852A3-47F8-48C4-A200-58CAB36FD2A2}.
10 Scheduled Tasks
  • SDOnAccess.exe is scheduled as a task named 'Scan most recently used file in the background' (runs when idle).
  • explorer.exe is scheduled as a task named 'Scan the system' (runs monthly on Wednesdays at 00:30).
  • SDImmunize.exe is scheduled as a task named 'Refresh immunization' (runs weekly on Wednesdays at 12:30 AM).
  • SDFiles.exe is scheduled as a task with the class '{43A7D852-3703-4DE5-9DB9-0F3AFCA7836C}' (runs on registration).
  • SDLogReport.exe is scheduled as a task with the class '{F5305E2F-3AAF-4595-A84F-54430F09A73A}' (runs on registration).
  • SDUpdate.exe is scheduled as a task named 'Spybot - Search & Destroy Updater - Scheduled Task' (runs weekly on Mondays at 9:00 AM).
  • Plus 4 more
6 Scheduled Tasks (Boot/Login)
  • SDCleaner.exe is automatically launched at startup through a scheduled task named Spybot-S&D Cleaning.
  • SDUpdate.exe is automatically launched at startup through a scheduled task named Check for updates (Spybot - Search & Destroy).
  • SDImmunize.exe is automatically launched at startup through a scheduled task named Refresh immunization.
  • SDOnAccess.exe is automatically launched at startup through a scheduled task named Scan most recently used file in the background.
  • explorer.exe is automatically launched at startup through a scheduled task named Scan the system (Spybot - Search & Destroy).
  • SDWelcome.exe is automatically launched at startup through a scheduled task named Spybot-S&D Start Center.
3 Services
  • SDFSSvc.exe runs as a service named 'Spybot-S&D 2 Scanner Service' (SDScannerService) "Offers malware scanning services to Spybot-S&D modules".
  • SDWSCSvc.exe runs as a service named 'Spybot-S&D 2 Security Center Service' (SDWSCService) "Integrates Spybot into the Windows Security Center.".
  • SDUpdSvc.exe runs as a service named 'Spybot-S&D 2 Aktualisierungsdienst' (SDUpdateService) "Systemdienst zum Herunterladen und Installieren von Aktualisierungen im Hintergrund.".
4 Startup Files (User Run)
  • SDCleaner.exe is loaded in the current user (HKCU) registry as an auto-starting executable named 'Spybot-S&D Cleaning' and executes as "C:\Program Files\Spybot - Search & Destroy 2\SDCleaner.exe" /autoclean.
  • SDPEStart.exe is loaded in the current user (HKCU) registry as an auto-starting executable named 'PE Start Menu' and executes as C:\Program Files\Spybot - Search & Destroy 2\SDPEStart.exe.
  • SDOnAccess.exe is loaded in the current user (HKCU) registry as an auto-starting executable named 'On Access protection dialog' and executes as C:\Program Files\Spybot - Search & Destroy 2\SDOnAccess.exe.
  • SDHookHelper.exe is loaded in the current user (HKCU) registry as an auto-starting executable named 'Live Protection Helper' and executes as C:\Program Files\Spybot - Search & Destroy 2\SDHookHelper.exe.
Startup File (User Run Once)
  • SDDelFile.exe is loaded once in the current user (HKCU) registry as a startup file name 'SpybotDeletingF3712' which loads as "C:\Program Files\Spybot - Search & Destroy 2\SDDelFile.exe" "C:\ProgramData\WPM\wprotectmanager.exe".
2 Startup Files (All Users Run)
  • SDCleaner.exe is loaded in the all users (HKLM) registry as a startup file name 'Spybot-S&D Cleaning' which loads as "C:\Program Files\Spybot - Search & Destroy 2\SDCleaner.exe" /autoclean.
  • SDTray.exe is loaded in the all users (HKLM) registry as a startup file name 'SDTray' which loads as "C:\Program Files\Spybot - Search & Destroy 2\SDTray.exe".
Startup File (All Users Run Once)
  • SDDelFile.exe is loaded once in the all users (HKLM) registry as a startup file name 'SpybotDeletingE1712' which loads as "C:\Program Files\Spybot - Search & Destroy 2\SDDelFile.exe" "C:\WINDOWS\SchedLgU.Txt".
9 Windows Firewall Allowed Programs
  • SDFSSvc.exe is added as a firewall exception for 'C:\Program Files\Spybot - Search & Destroy 2\SDFSSvc.exe'.
  • explorer.exe is added as a firewall exception for 'C:\Program Files\Spybot - Search & Destroy 2\SDScan.exe'.
  • SDRootAlyzer.exe is added as a firewall exception for 'C:\Program Files\Spybot - Search & Destroy 2\SDRootAlyzer.exe'.
  • SDImmunize.exe is added as a firewall exception for 'C:\Program Files\Spybot - Search & Destroy 2\SDImmunize.exe'.
  • SDFiles.exe is added as a firewall exception for 'C:\Program Files\Spybot - Search & Destroy 2\SDFiles.exe'.
  • SDTray.exe is added as a firewall exception for 'C:\pcwWinCleaner\Tools\Spybot - Search & Destroy 2\SDTray.exe'.
  • Plus 3 more
Network connections
  • SDUpdSvc.exe connects to 188.165.126.152 (port 80).

Program resource utilizationResource utilization averages

sdwelcome.exe
Memory:15.63 MB
21.09 MB average
Total CPU:0.0008050855%
0.031193% average
Kernel CPU:0.00042458%
0.016088% average
User CPU:0.00038051%
0.015104% average
CPU cycles/sec:14,557,397
8,062,084 average
Switches/sec:32
70 average
I/O reads/min:70.24 KB
435.61 KB average
I/O writes/min:138 Bytes
105.02 KB average
explorer.exe
Memory:726.4 MB
Total CPU:0.0005641614%
Kernel CPU:0.00023626%
User CPU:0.00032790%
CPU cycles/sec:87,464,714
Switches/sec:15
I/O reads/min:14.46 MB
I/O writes/min:101 Bytes
SDFSSvc.exe
Memory:64.24 MB
Total CPU:0.0003057671%
Kernel CPU:0.00013028%
User CPU:0.00017549%
CPU cycles/sec:7,225,273
Switches/sec:47
I/O reads/min:108.3 KB
I/O writes/min:22.13 KB

How do I remove Spybot - Search & Destroy?

You can uninstall Spybot - Search & Destroy from your computer by using the Add/Remove Program feature in the Window's Control Panel.
  1. On the Start menu (for Windows 8, right-click the screen's bottom-left corner), click Control Panel, and then, under Programs, do one of the following:
    • Windows Vista/7/8/10: Click Uninstall a Program.
    • Windows XP: Click Add or Remove Programs.
  2. When you find the program Spybot - Search & Destroy, click it, and then do one of the following:
    • Windows Vista/7/8/10: Click Uninstall.
    • Windows XP: Click the Remove or Change/Remove tab (to the right of the program).
  3. Follow the prompts. A progress bar shows you how long it will take to remove Spybot - Search & Destroy.

How do I reset my web browser?

If your web browser homepage and search settings have been modfied by Spybot - Search & Destroy you can restore them to their previous default settings.
Microsoft Internet Explorer
Mozilla Firefox
Google Chrome

HOW IT STARTS
Automatically starts? Yes
(Found in the run registry)
 
USER ACTIONS
Uninstall it 8%
Keep it 92%
 
GLOBAL RANK
#165

Windows OS versionsWindows

Which Windows OS versions does it run on?
Windows 7 55.76%
Windows 10 34.06%
Windows Vista 5.32%
Windows XP 4.83%
Windows Server 2003 0.03%
Which OS releases does it run on?
Windows 7 Home Premium 32.87%
Windows 8.1 11.60%
Windows 7 Professional 10.91%
Windows 7 Ultimate 10.02%
Windows 10 Home 8.54%
Microsoft Windows XP 4.77%

Distribution by countryGeography

52.45% of installs come from the United States
Which countries install it?
  United States 52.45%
  Germany 9.99%
  France 6.79%
  United Kingdom 5.24%
  Italy 3.58%
  Canada 3.38%
  Australia 1.76%
  Netherlands 1.52%
  Brazil 1.33%
  Spain 1.17%
  Belgium 1.07%
  Sweden 0.76%
  Austria 0.75%
  Switzerland 0.50%

OEM distributionPC manufacturers

What PC manufacturers (OEMs) have it installed?
Hewlett-Packard 27.26%
Dell 20.89%
Acer 17.49%
ASUS 11.16%
Toshiba 6.95%
GIGABYTE 5.68%
Lenovo 4.10%
Samsung 3.32%
Intel 1.25%
Medion 1.04%
American Megatrends 0.86%
Common models
HP Pavilion dv6 Notebook ... 6.00%
ASUS All Series 5.81%
HP Pavilion dv7 Notebook ... 5.27%
HP Pavilion g6 Notebook P... 4.72%
HP Pavilion g7 Notebook P... 3.40%
HP 2000 Notebook PC 2.48%

About (from Safer-Networking Ltd.)

Spybot is maintained by a team of people very dedicated to privacy issues, many of which are working full-time on analysing masses of new threats each week, and the response time from our support team is better than that of many a commercial vendor.
Publisher URL: www.safer-networking.org

commentsComments

user comment
No one has commented yet. Help others learn more about this software, share your comments.