Should I block it?

No, this file is 100% safe to run.

Relationships

Parent process
Related files

PE structurePE file structure

Show functions
Import table
advapi32.dll
RegQueryValueExA, RegOpenKeyExA, RegCloseKey, ReportEventA, RegisterEventSourceA, RegSetValueExA, RegQueryInfoKeyA, RegFlushKey, RegEnumKeyExA, RegCreateKeyExA, DeregisterEventSource, StartServiceCtrlDispatcherA, SetServiceStatus, RegisterServiceCtrlHandlerA, OpenServiceA, OpenSCManagerA, DeleteService, CreateServiceA, CloseServiceHandle, CryptGetProvParam, CryptImportKey, CryptExportKey, CryptReleaseContext, CryptDestroyKey, CryptGetUserKey, CryptAcquireContextA
comctl32.dll
_TrackMouseEvent, ImageList_SetIconSize, ImageList_GetIconSize, ImageList_Write, ImageList_Read, ImageList_GetDragImage, ImageList_DragShowNolock, ImageList_DragMove, ImageList_DragLeave, ImageList_DragEnter, ImageList_EndDrag, ImageList_BeginDrag, ImageList_Remove, ImageList_DrawEx, ImageList_Replace, ImageList_Draw, ImageList_GetBkColor, ImageList_SetBkColor, ImageList_Add, ImageList_GetImageCount, ImageList_Destroy, ImageList_Create, InitCommonControls
crypt32.dll
CertSetCertificateContextProperty, CertGetCertificateContextProperty, CertOpenStore, CertDuplicateCertificateContext, CertEnumCertificatesInStore, CertDeleteCertificateFromStore, CertFreeCertificateContext, CertAddEncodedCertificateToStore, CertCloseStore, CertFindCertificateInStore, CertOpenSystemStoreA
gdi32.dll
UnrealizeObject, StretchBlt, StartPage, StartDocA, SetWindowOrgEx, SetWinMetaFileBits, SetViewportOrgEx, SetTextColor, SetStretchBltMode, SetROP2, SetPixel, SetMapMode, SetEnhMetaFileBits, SetDIBColorTable, SetBrushOrgEx, SetBkMode, SetBkColor, SetAbortProc, SelectPalette, SelectObject, SelectClipRgn, SaveDC, RoundRect, RestoreDC, Rectangle, RectVisible, RealizePalette, PlayEnhMetaFile, PatBlt, MoveToEx, MaskBlt, LineTo, IntersectClipRect, GetWindowOrgEx, GetWinMetaFileBits, GetTextMetricsA, GetTextExtentPointA, GetTextExtentPoint32W, GetTextExtentPoint32A, GetSystemPaletteEntries, GetStockObject, GetRgnBox, GetPixel, GetPaletteEntries, GetObjectA, GetEnhMetaFilePaletteEntries, GetEnhMetaFileHeader, GetEnhMetaFileBits, GetDeviceCaps, GetDIBits, GetDIBColorTable, GetDCOrgEx, GetCurrentPositionEx, GetClipBox, GetBrushOrgEx, GetBitmapBits, ExtFloodFill, ExcludeClipRect, EndPage, EndDoc, DeleteObject, DeleteEnhMetaFile, DeleteDC, CreateSolidBrush, CreateRoundRectRgn, CreatePenIndirect, CreatePalette, CreateICA, CreateHalftonePalette, CreateFontIndirectA, CreateDIBitmap, CreateDIBSection, CreateDCA, CreateCompatibleDC, CreateCompatibleBitmap, CreateBrushIndirect, CreateBitmap, CopyEnhMetaFileA, BitBlt
kernel32.dll
GetACP, Sleep, VirtualFree, VirtualAlloc, GetCurrentThreadId, InterlockedDecrement, InterlockedIncrement, VirtualQuery, WideCharToMultiByte, MultiByteToWideChar, lstrlenA, lstrcpynA, LoadLibraryExA, GetThreadLocale, GetStartupInfoA, GetProcAddress, GetModuleHandleA, GetModuleFileNameA, GetLocaleInfoA, GetLastError, GetCommandLineA, FreeLibrary, FindFirstFileA, FindClose, ExitProcess, ExitThread, CreateThread, CompareStringA, WriteFile, UnhandledExceptionFilter, SetFilePointer, SetEndOfFile, RtlUnwind, ReadFile, RaiseException, GetStdHandle, GetFileSize, GetFileType, CreateFileA, CloseHandle, TlsSetValue, TlsGetValue, LocalAlloc, lstrcpyA, WaitForSingleObject, UnmapViewOfFile, SuspendThread, SizeofResource, SetThreadLocale, SetLastError, SetEvent, SetErrorMode, ResumeThread, ResetEvent, ReleaseSemaphore, QueryDosDeviceA, OutputDebugStringA, OpenProcess, MulDiv, MapViewOfFile, LockResource, LoadResource, LoadLibraryA, LeaveCriticalSection, InitializeCriticalSection, GlobalUnlock, GlobalLock, GlobalFree, GlobalFindAtomA, GlobalDeleteAtom, GlobalAlloc, GlobalAddAtomA, GetWindowsDirectoryA, GetVolumeInformationA, GetVersionExA, GetVersion, GetTimeZoneInformation, GetTickCount, GetSystemInfo, GetSystemDirectoryA, GetStringTypeExA, GetProfileStringA, GetLogicalDrives, GetLocalTime, GetFullPathNameA, GetFileAttributesA, GetExitCodeThread, GetDriveTypeA, GetDiskFreeSpaceA, GetDateFormatA, GetCurrentProcessId, GetCurrentProcess, GetComputerNameA, GetCPInfo, FreeResource, InterlockedExchange, FormatMessageA, FindResourceA, EnumCalendarInfoA, EnterCriticalSection, DeleteCriticalSection, CreateSemaphoreA, CreateFileMappingA, CreateEventA, CompareStringW
ole32.dll
OleUninitialize, OleInitialize, CoTaskMemFree, ProgIDFromCLSID, StringFromCLSID, CoCreateInstance, CoUninitialize, CoInitialize, IsEqualGUID, CoCreateGuid
oleaut32.dll
SysFreeString, SysReAllocStringLen, SysAllocStringLen, SafeArrayPtrOfIndex, SafeArrayGetUBound, SafeArrayGetLBound, SafeArrayCreate, VariantChangeType, VariantCopy, VariantClear, VariantInit, GetErrorInfo, GetActiveObject
shell32.dll
ShellExecuteW, ShellExecuteA, SHGetSpecialFolderLocation, SHGetPathFromIDListA
user32.dll
GetKeyboardType, DestroyWindow, LoadStringA, MessageBoxA, CharNextA, DllMain
version.dll
VerQueryValueA, GetFileVersionInfoSizeA, GetFileVersionInfoA
winspool.drv
OpenPrinterA, EnumPrintersA, DocumentPropertiesA, ClosePrinter

SDWinSec.exe

Spybot - Search & Destroy by Safer Networking Ltd. (Signed)

Remove SDWinSec.exe
Version:   1, 0, 0, 12
MD5:   794d4b48dfb6e999537c7c3947863463
SHA1:   d0b409bcc2c76b0f76d0b05e86bbf9d09b6006cb
SHA256:   93da8aa20d6b02a3360e7f56150f126e75266e9372e6409d42b89da588ef49c3

What is SDWinSec.exe?

Spybot-S&D Security Center integration for Spybot Search & Destroy (S&D) is a spyware and adware removal computer program that scans the computer hard disk and/or RAM for malicious software. In addition to spyware and adware detection and disinfection, Spybot-S&D can repair the registry, winsock LSPs, ActiveX objects, browser hijackers and BHOs, PUPS, computer cookies, trackerware, heavy duty, homepage hijackers, keyloggers, LSP, tracks, trojans, spybots, revision, and other kinds of malware.

About SDWinSec.exe (from Safer Networking Ltd.)

Spybot-S&D is free for private use. Even if you don’t see the symptoms, your computer may be infected. The creators of spyware are constantly developing new ways of invading your privacy. Team Spybot

DetailsDetails

File name:sdwinsec.exe
Publisher:Safer Networking Ltd.
Product name:Spybot - Search & Destroy
Description:Spybot-S&D Security Center integration
Typical file path:C:\Program Files\spybot - search & destroy\sdwinsec.exe
File version:1, 0, 0, 12
Product version:1, 6, 0, 0
Size:1.1 MB (1,153,368 bytes)
Certificate
Issued to:Safer Networking Ltd.
Digital DNA
File packed:No
.NET CLR:No
More details

ResourcesPrograms

The following programs will install this file
Safer-Networking Ltd.
6% remove
Spybot Search & Destroy (S&D) is a spyware and adware removal computer program compatible with Microsoft Windows. It scans the computer hard disk and/or RAM for malicious software. In addition to spyware and adware detection and disinfection, Spybot-S&D can repair the registry, winsock LSPs, ActiveX objects, browser hijackers and BHOs, PUPS, computer cookies, trackerware, heavy duty, homepage hijackers, keyloggers, LSP, tracks, trojans,...

BehaviorsBehaviors

Services
Runs under 'SYSTEM\CurrentControlSet\Services' by the Service Controller (services.exe)
  • 'SBSDWSCService' (SBSD Security Center Service)
  • SBSDWSCService

ResourcesResource utilization

(Note: statistics below are averages based on a minimum sample size of 200 unique participants)
Averages
 
CPU
Total CPU:0.00186794%
0.028634%
Kernel CPU:0.00121284%
0.013761%
User CPU:0.00065510%
0.014873%
Kernel CPU time:2,329,560 ms/min
100,923,805ms/min
CPU cycles:680,117/sec
17,470,203/sec
Context switches:2/sec
284/sec
Memory
Private memory:13.14 MB
21.59 MB
Private (maximum):13.5 MB
Private (minimum):6.59 MB
Non-paged memory:13.14 MB
21.59 MB
Virtual memory:75.72 MB
140.96 MB
Virtual memory (peak):77.83 MB
169.69 MB
Working set:10.26 MB
18.61 MB
Working set (peak):13.93 MB
37.95 MB
Page faults:1,258,918/min
2,039/min
I/O
I/O read transfer:5.16 KB/sec
1.02 MB/min
I/O read operations:1/sec
343/min
I/O write transfer:0 Bytes/sec
274.99 KB/min
I/O write operations:1/sec
227/min
I/O other transfer:478 Bytes/sec
448.09 KB/min
I/O other operations:33/sec
1,671/min
Resource allocations
Threads:7
12
Handles:149
600

BehaviorsProcess properties

Integrety level:System
Platform:64-bit
Command line:"C:\Program Files\spybot - search & destroy\sdwinsec.exe"
Owner:SYSTEM
Windows Service
Service name:SBSDWSCService
Display name:SBSD Security Center Service
Type:Win32OwnProcess
Parent process:services.exe (Services and Controller app by Microsoft)

ResourcesThreads

Averages
 
SDWinSec.exe (main module)
Total CPU:0.03156868%
0.272967%
Kernel CPU:0.02566550%
0.107585%
User CPU:0.00590318%
0.165382%
CPU cycles:750,647/sec
5,741,424/sec
Memory:1.14 MB
1.16 MB
ntdll.dll
Total CPU:0.00654859%
Kernel CPU:0.00000000%
User CPU:0.00654859%
CPU cycles:16,415/sec
Memory:1.66 MB
wow64cpu.dll
Total CPU:0.00111534%
Kernel CPU:0.00000000%
User CPU:0.00111534%
CPU cycles:5,337/sec
Memory:32 KB
RPCRT4.dll
Total CPU:0.00024423%
Kernel CPU:0.00015542%
User CPU:0.00008881%
CPU cycles:8,094/sec
Memory:780 KB
wow64.dll
Total CPU:0.00011059%
Kernel CPU:0.00005529%
User CPU:0.00005529%
CPU cycles:9,504/sec
Memory:276 KB
ole32.dll
Total CPU:0.00005248%
Kernel CPU:0.00000000%
User CPU:0.00005248%
CPU cycles:3,949/sec
Memory:1.36 MB

Common loaded modules

These are modules that are typiclaly loaded within the context of this process.

Windows OS versionsDistribution by Windows OS

OS versiondistribution
Windows 7 Home Premium 60.81%
Windows 7 Professional 9.46%
Windows 7 Ultimate 9.46%
Windows Vista Home Premium 9.46%
Windows 8 5.41%
Windows Vista Home Basic 2.70%
Windows Vista Business 2.70%

Distribution by countryDistribution by country

United States installs about 62.50% of Spybot - Search & Destroy.

OEM distributionDistribution by PC manufacturer

PC Manufacturerdistribution
Dell 37.97%
Hewlett-Packard 20.25%
ASUS 12.66%
Acer 11.39%
Intel 5.06%
Medion 5.06%
Lenovo 5.06%
Sahara 1.27%
GIGABYTE 1.27%
Should I remove It? Clean your PC of unwanted adware, toolbars and bloatware.

Download it for FREE