Should I block it?

No, this file is 100% safe to run.

VersionsAdditional versions

4.4.0.85 75.00%
4.0.2.317 25.00%

Relationships

Parent process
Related files

PE structurePE file structure

Show functions
Import table
advapi32.dll
RegOpenKeyExW, GetSidIdentifierAuthority, GetSidSubAuthorityCount, GetSidSubAuthority, GetTokenInformation, OpenThreadToken, OpenProcessToken, CheckTokenMembership, CreateProcessAsUserW, GetUserNameW, LookupPrivilegeValueW, RegEnumValueW, RegLoadKeyW, RegUnLoadKeyW, RegRestoreKeyW, RegSaveKeyW, RegFlushKey, SetSecurityInfo, CryptAcquireContextW, CryptCreateHash, CryptHashData, CryptGetHashParam, CryptDestroyHash, CryptReleaseContext, AdjustTokenPrivileges, StartServiceW, QueryServiceStatus, QueryServiceConfigW, AddAce, GetAclInformation, GetSecurityDescriptorDacl, GetSecurityDescriptorControl, MakeAbsoluteSD, DuplicateTokenEx, CryptDestroyKey, CryptImportKey, CryptGetUserKey, CryptSignHashW, CryptVerifySignatureW, GetSidLengthRequired, InitializeSid, CopySid, SetFileSecurityW, RegNotifyChangeKeyValue, EqualSid, CreateRestrictedToken, GetSecurityDescriptorLength, MakeSelfRelativeSD, GetSecurityDescriptorSacl, GetSecurityDescriptorGroup, GetSecurityDescriptorOwner, RegisterEventSourceW, ReportEventW, DeregisterEventSource, SetServiceStatus, InitializeSecurityDescriptor, AllocateAndInitializeSid, SetSecurityDescriptorGroup, RegQueryValueExW, SetSecurityDescriptorOwner, RegCloseKey, GetLengthSid, StartServiceCtrlDispatcherW, InitializeAcl, RegEnumKeyExW, AddAccessAllowedAce, OpenSCManagerW, SetSecurityDescriptorDacl, IsValidSecurityDescriptor, RegDeleteKeyW, SetServiceObjectSecurity, CreateServiceW, RegQueryInfoKeyW, CloseServiceHandle, OpenServiceW, FreeSid, RegisterServiceCtrlHandlerExW, ControlService, DeleteService, RegCreateKeyExW, RegDeleteValueW, RegSetValueExW, ChangeServiceConfigW, ChangeServiceConfig2W, GetAce, ConvertStringSidToSidW, IsValidSid
crypt32.dll
CryptUnprotectData, CertGetCertificateChain, CertFreeCertificateChain, CryptQueryObject, CryptMsgGetParam, CertFindCertificateInStore, CertGetNameStringW, CertFreeCertificateContext, CertCloseStore, CryptMsgClose, CryptVerifyMessageSignature, CryptProtectData
dbghelp.dll
ImageRvaToVa, MiniDumpWriteDump
imagehlp.dll
ImageGetCertificateData, ImageEnumerateCertificates
iphlpapi.dll
GetNetworkParams
kernel32.dll
DllMain
ole32.dll
CoCreateInstance, StringFromGUID2, CoUninitialize, CoCreateGuid, CoInitializeEx, StringFromCLSID, CoTaskMemAlloc, CoInitializeSecurity, CoRegisterClassObject, CoDisconnectObject, CoRevokeClassObject, CoTaskMemRealloc, CoInitialize, CoTaskMemFree
psapi.dll
GetModuleBaseNameW, GetModuleFileNameExW, GetModuleBaseNameA, GetProcessMemoryInfo
shell32.dll
SHGetFolderPathW, SHGetFolderLocation, SHGetPathFromIDListW, SHFileOperationW, CommandLineToArgvW
shlwapi.dll
PathFileExistsW, PathAppendW, PathRenameExtensionW
user32.dll
EnumDesktopsW, OpenWindowStationW, EnumDesktopWindows, CharUpperW, CharNextW, OpenDesktopW, FindWindowW, GetWindowThreadProcessId, GetWindowTextW, GetClassNameW, EnumWindowStationsW, GetSystemMetrics, EnumChildWindows, LoadStringW, UnregisterClassA, MessageBoxW, GetMessageW, TranslateMessage, PostThreadMessageW, DispatchMessageW, wsprintfW, RegisterWindowMessageW, CloseWindowStation, WaitForInputIdle
userenv.dll
DestroyEnvironmentBlock, CreateEnvironmentBlock
vdmdbg.dll
VDMEnumTaskWOWEx
version.dll
GetFileVersionInfoW, VerQueryValueW, GetFileVersionInfoSizeW
wininet.dll
GetUrlCacheEntryInfoW, DeleteUrlCacheEntryW, FindCloseUrlCache, FindFirstUrlCacheEntryExW, FindNextUrlCacheEntryExW
wintrust.dll
WinVerifyTrust
ws2_32.dll
WSCInstallProvider, WSCDeinstallProvider, WSCGetProviderPath, WSCEnumProtocols

SPYSWEEPER.exe

Spy Sweeper SDK by Webroot Software (Signed)

Remove SPYSWEEPER.exe
Version:   4.0.2.317
MD5:   cc559801ce20b8291fd816a21d192148
SHA1:   2715800c59368db4d8de2d516960f2f78a078c93

What is SPYSWEEPER.exe?

Spy Sweeper Engine for Spy Sweeper is a software product that detects and removes spyware and viruses on personal computers that run Microsoft Windows. Spy Sweeper examines files on a computer's hard disk drive, as well as objects in memory, the Windows registry and cookies, and quarantines any suspicious objects it finds. Some broadband services, such as MSN Premium, also offer rebranded versions of Spy Sweeper as part of their subscription.

About SPYSWEEPER.exe (from Webroot Software)

You need the best protection against viruses, spyware and malware. That's why we've improved the protection found in Spy Sweeper and created Webroot® SecureAnywhere™ AntiVirus, giving you online prote

DetailsDetails

File name:spysweeper.exe
Publisher:Webroot Software, Inc. (www.webroot.com)
Product name:Spy Sweeper SDK
Description:Spy Sweeper Engine
Typical file path:C:\Program Files\webroot\webrootsecurity\spysweeper.exe
File version:4.0.2.317
Size:3.43 MB (3,597,680 bytes)
Build date:11/13/2008 6:04 AM
Certificate
Issued to:Webroot Software
Authority (CA):VeriSign
Effective date:Sunday, November 16, 2008
Expiration date:Sunday, December 27, 2009
Digital DNA
Entropy:6.207831
File packed:No
.NET CLR:No
More details

BehaviorsBehaviors

Services
Runs under 'SYSTEM\CurrentControlSet\Services' by the Service Controller (services.exe)
  • 'WebrootSpySweeperService'

ResourcesResource utilization

(Note: statistics below are averages based on a minimum sample size of 200 unique participants)
Averages
 
CPU
Total CPU:0.00169169%
0.028634%
Kernel CPU:0.00145223%
0.013761%
User CPU:0.00023946%
0.014873%
Kernel CPU time:7,972 ms/min
100,923,805ms/min
CPU cycles:1,026,246/sec
17,470,203/sec
Memory
Private memory:23.74 MB
21.59 MB
Private (maximum):7.07 MB
Private (minimum):520 KB
Non-paged memory:23.74 MB
21.59 MB
Virtual memory:195 MB
140.96 MB
Virtual memory (peak):217.67 MB
169.69 MB
Working set:3.57 MB
18.61 MB
Working set (peak):74.07 MB
37.95 MB
Page faults:1,248,193/min
2,039/min
I/O
I/O read transfer:12.73 KB/sec
1.02 MB/min
I/O read operations:8/sec
343/min
I/O write transfer:705 Bytes/sec
274.99 KB/min
I/O write operations:34/sec
227/min
I/O other transfer:3.61 KB/sec
448.09 KB/min
I/O other operations:143/sec
1,671/min
Resource allocations
Threads:29
12
Handles:1792
600

BehaviorsProcess properties

Integrety level:System
Platform:64-bit
Command line:"C:\Program Files\webroot\spy sweeper\spysweeper.exe"
Owner:SYSTEM
Windows Service
Service name:WebrootSpySweeperService
Type:Win32OwnProcess
Parent process:services.exe (Services and Controller app by Microsoft)

ResourcesThreads

Averages
 
wow64.dll
Total CPU:0.01217230%
0.272967%
Kernel CPU:0.00380084%
0.107585%
User CPU:0.00837147%
0.165382%
CPU cycles:333,326/sec
5,741,424/sec
Memory:276 KB
1.16 MB
SpySweeper.exe (main module)
Total CPU:0.00620670%
Kernel CPU:0.00177159%
User CPU:0.00443511%
CPU cycles:178,627/sec
Memory:3.48 MB

Common loaded modules

These are modules that are typiclaly loaded within the context of this process.

Windows OS versionsDistribution by Windows OS

OS versiondistribution
Microsoft Windows XP 50.00%
Windows Vista Home Premium 25.00%
Windows XP Professional 25.00%

Distribution by countryDistribution by country

BG installs about 66.67% of Spy Sweeper SDK.

OEM distributionDistribution by PC manufacturer

PC Manufacturerdistribution
Sony 100.00%
Should I remove It? Clean your PC of unwanted adware, toolbars and bloatware.

Download it for FREE