I was shocked by the number of processes detected on my system, which I believe I take good care of.
SUMMARY:
Scan at: 06/18/20 07:43:09 (1592458989)
Finished scan in: 81782 milliseconds
[+] Total Suspicious: 15
[+] List of suspicious:
[ 0]: PID: 3164, Name: HsMgr.exe
[ 1]: PID: 9176, Name: HsMgr64.exe
[ 2]: PID: 1936, Name: steam.exe
[ 3]: PID: 7564, Name: Skype.exe
[ 4]: PID: 11396, Name: Skype.exe
[ 5]: PID: 5648, Name: Skype.exe
[ 6]: PID: 10412, Name: purevpn.exe
[ 7]: PID: 15632, Name: Discord.exe
[ 8]: PID: 15748, Name: flux.exe
[ 9]: PID: 16204, Name: Discord.exe
[10]: PID: 6688, Name: Discord.exe
[11]: PID: 10120, Name: browser_assistant.exe
[12]: PID: 11688, Name: browser_assistant.exe
[13]: PID: 10640, Name: onenotem.exe
[14]: PID: 8540, Name: Launchy.exe
The Wiki says
Keep in mind that the detected processes are not necessarily malicious, so it should be used with care.
So I now need to decide whether these 15 processes are malicious or not. I started by taking SysInternals Process Explorer and turning on the verification of signatures (Options / Verify Image Signatures).
I would appreciate if Hollows Hunter would have that built-in, so it tells me in the summary which processes are code signed and which are not. Maybe like so:
SUMMARY:
Scan at: 06/18/20 07:43:09 (1592458989)
Finished scan in: 81782 milliseconds
[+] Total Suspicious: 15
[+] List of suspicious:
[ 0]: PID: 3164, Name: HsMgr.exe (no signature)
[ 1]: PID: 9176, Name: HsMgr64.exe (no signature)
[ 2]: PID: 1936, Name: steam.exe (verified: Valve)
[ 3]: PID: 7564, Name: Skype.exe (verified: Skype Software Sarl)
[ 4]: PID: 11396, Name: Skype.exe (verified: Skype Software Sarl)
[ 5]: PID: 5648, Name: Skype.exe (verified: Skype Software Sarl)
[ 6]: PID: 10412, Name: purevpn.exe (verified: GZ Systems Limited)
[ 7]: PID: 15632, Name: Discord.exe (verified: Discord Inc.)
[ 8]: PID: 15748, Name: flux.exe (verified: F.lux Software LLC)
[ 9]: PID: 16204, Name: Discord.exe (verified: Discord Inc.)
[10]: PID: 6688, Name: Discord.exe (verified: Discord Inc.)
[11]: PID: 10120, Name: browser_assistant.exe (verified: Opera Software AS)
[12]: PID: 11688, Name: browser_assistant.exe (verified: Opera Software AS)
[13]: PID: 10640, Name: onenotem.exe (verified: Microsoft Corporation)
[14]: PID: 8540, Name: Launchy.exe (no signature)