Gridinsoft Logo

The sdengin2.dll (Microsoft® Windows Backup Engine) File Analysis

Technical Analysis

File Name sdengin2.dll
File Type
PE32+ executable (DLL) (GUI) x86-64, for MS Windows
Scanner Version 1.0.231.174
Database Version 2026-01-04 20:00:36 UTC

Clean File

No threats detected by our scanner

0%
Detection Rate
1,244,672
File Size (bytes)
2026-01-04
Analysis Date

Scan Another File

File Identification

Hash Type Value Action
MD5
66ec7f3200b6134bfbad5bb1b6161d54
SHA1
68c1475e707440ba4d0965ec030d18c7af60be8e
SHA256
9ec4fa6370412a3e07050b0803259e43e1c5898a2a833839870a62c640b7c5ba
SHA512
7c4fec21293c9a71753a259e5150091282cc0c8631d07b021b4249c5dc0567a60e1df7eeb7389373de031d6fe04b8383245e1649f999bd1ad927a13c984f398e
ImpHash
110521e204317dc23dfb8e31e9e2b4e8

PE Analysis

Basic Information

Image Base 0x180000000
Entry Point 0x1800da6e0
Compilation Time 1994-04-12 08:33:41
Checksum 0x001358fb (Actual: 0x001358fb)
OS Version 10.0
PEiD Signatures PE32+ executable (DLL) (GUI) x86-64, for MS Windows
PDB Path sdengin2.pdb
Digital Signature No valid SignedData structure was found.
Imports 44 libraries
Exports 7 functions
Resources 4 Resources
Sections 7 Sections

Version Information

CompanyName Microsoft Corporation
FileDescription Microsoft® Windows Backup Engine
FileVersion 10.0.19041.3636 (WinBuild.160101.0800)
InternalName SDENGINE.DLL
LegalCopyright © Microsoft Corporation. All rights reserved.
OriginalFilename SDENGINE.DLL
ProductName Microsoft® Windows® Operating System
ProductVersion 10.0.19041.3636
Translation 0x0409 0x04b0

PE Sections

Name Virtual Address Virtual Size Raw Size Entropy Characteristics MD5
.text 0x00001000 899,377 bytes 899,584 bytes 6.37 (Normal) IMAGE_SCN_CNT_CODE|IMAGE_SCN_MEM_EXECUTE|IMAGE_SCN_MEM_READ B53CBF7C06DDE03573D4AE3F055BDFBD
.rdata 0x000dd000 198,132 bytes 198,144 bytes 5.20 (Normal) IMAGE_SCN_CNT_INITIALIZED_DATA|IMAGE_SCN_MEM_READ 3F169816CCB3FD70C233666D2B4BAEB2
.data 0x0010e000 8,112 bytes 5,120 bytes 4.00 (Normal) IMAGE_SCN_CNT_INITIALIZED_DATA|IMAGE_SCN_MEM_READ|IMAGE_SCN_MEM_WRITE 2321556F0130908A77CFE60631F2A75F
.pdata 0x00110000 24,648 bytes 25,088 bytes 5.90 (Normal) IMAGE_SCN_CNT_INITIALIZED_DATA|IMAGE_SCN_MEM_READ 747178E583215875BD412AE5CE106B58
.didat 0x00117000 456 bytes 512 bytes 2.79 (Normal) IMAGE_SCN_CNT_INITIALIZED_DATA|IMAGE_SCN_MEM_READ|IMAGE_SCN_MEM_WRITE 8845DA519A3D3C46C324A219F82BA2A1
.rsrc 0x00118000 107,160 bytes 107,520 bytes 6.62 (Compressed) IMAGE_SCN_CNT_INITIALIZED_DATA|IMAGE_SCN_MEM_READ 931F42B19C022C91F699628B4F0061AD
.reloc 0x00133000 7,628 bytes 7,680 bytes 5.37 (Normal) IMAGE_SCN_CNT_INITIALIZED_DATA|IMAGE_SCN_MEM_DISCARDABLE|IMAGE_SCN_MEM_READ 1B2CEFE0EE88BB3F626938DEDD54C13D
Entropy Analysis Alert

1 section(s) with elevated entropy (≥6.5) - possible compression

Resource Analysis

Total Resources: 4 (106,766 bytes)
Resource Type Count Total Size Percentage
ICONBINARY 1 101,212 bytes
94.8%
MUI 1 248 bytes
0.2%
REGISTRY 1 4,354 bytes
4.1%
RT_VERSION 1 952 bytes
0.9%

Certificate Chain Analysis

Certificate Information
Product Microsoft® Windows® Operating System
Description Microsoft® Windows Backup Engine
File Version 10.0.19041.3636 (WinBuild.160101.0800)
Original Name SDENGINE.DLL
Internal Name SDENGINE.DLL
Copyright © Microsoft Corporation. All rights reserved.

✓ This file has been digitally signed and the certificate chain has been verified

  • The signature ensures file integrity and authenticity from the publisher
  • Timestamping proves when the signature was applied
Certificate Verification Status

No valid SignedData structure was found.

Recommendation: Verify the file source and ensure it comes from a trusted publisher.

Remember: This is Result of Online Virus Scanner

Gridinsoft Anti-Malware has a much more powerful virus scanning engine. We recommend using it for a more precise diagnosis of infected systems. This brief guide will help you install our flagship product for more accurate diagnostics:

Download Anti-Malware

Keep Your System Protected

This file appears clean, but regular security maintenance is important

  1. Regular Scans: Run weekly system scans to detect new threats before they can cause damage.
  2. Keep Software Updated: Ensure your operating system and all applications have the latest security patches.
  3. Safe Browsing: Avoid suspicious websites and never download software from untrusted sources.
  4. Email Security: Be cautious with email attachments and links, even from known contacts.
Proactive Protection
This file passed all security checks, but stay vigilant. New malware variants appear daily that can evade detection. Always verify files come from official sources and check digital signatures when available.

Leave a Comment

Share your thoughts or insights about this file. Do you align with our conclusion?

Your feedback could influence our rating, and rest assured, your email will remain confidential and will only be used to communicate with you if necessary.

Your Score for
/

Gridinsoft Anti-Malware

Stay Malware-Free: Keep Your PC Protected with Gridinsoft Anti-Malware

Gridinsoft Anti-Malware offers just that—peace of mind with a robust, user-friendly solution that’s constantly updated to combat the latest threats. Designed by cybersecurity experts, it provides real-time protection and effortless malware removal. It’s not just about detecting threats; it's about enhancing your digital life with uninterrupted security. Give it a try and experience what it feels like to browse worry-free!

Gridinsoft Anti-Malware