Should I block it?

No, this file is 100% safe to run.

Relationships


PE structurePE file structure

Show functions
Import table
advapi32.dll
GetAclInformation, GetSecurityDescriptorDacl, CreateServiceA, RegFlushKey, StartServiceCtrlDispatcherA, CopySid, GetAce, ChangeServiceConfigA, AddAce, RegDeleteValueA, RegCloseKey, RegQueryValueExA, RegOpenKeyA, RegDeleteKeyW, RegOpenKeyExW, RegCreateKeyExW, RegSetValueExW, RegEnumKeyA, SetSecurityInfo, SetNamedSecurityInfoA, GetNamedSecurityInfoA, RegEnumKeyExA, RegGetKeySecurity, RegCreateKeyA, GetLengthSid, AllocateAndInitializeSid, FreeSid, SetServiceStatus, RegSetKeySecurity, RegDeleteKeyA, StartServiceA, OpenSCManagerA, OpenServiceA, CloseServiceHandle, QueryServiceStatus, RegNotifyChangeKeyValue, InitializeSecurityDescriptor, RegisterServiceCtrlHandlerA, InitializeAcl, OpenProcessToken, CreateProcessAsUserA, SetSecurityDescriptorDacl, RegCreateKeyExA, RegSetValueExA, RegOpenKeyExA
kernel32.dll
LocalFree, FormatMessageA, OpenProcess, LeaveCriticalSection, EnterCriticalSection, GetLocalTime, GetPrivateProfileIntA, GetExitCodeProcess, CreateProcessA, MoveFileExA, GetWindowsDirectoryA, GetModuleHandleA, DeleteCriticalSection, ResetEvent, GlobalFree, InitializeCriticalSection, CreateEventA, SetEvent, SetConsoleTitleA, GetCurrentProcessId, GetConsoleTitleA, WaitForMultipleObjects, GetFileAttributesA, OpenEventA, GetDiskFreeSpaceExA, CreateThread, SetWaitableTimer, GetTickCount, GetVersionExW, GetFileSize, FindClose, CompareFileTime, FindNextFileA, FindFirstFileA, ReadFile, SetFilePointer, TerminateProcess, IsDBCSLeadByteEx, MoveFileA, HeapFree, HeapAlloc, GetProcessHeap, GetSystemDirectoryA, GlobalUnlock, GlobalLock, GlobalAlloc, GlobalReAlloc, SetFileTime, GetFileTime, SetFileAttributesA, CreateWaitableTimerA, HeapReAlloc, lstrcatA, lstrcpyA, lstrlenA, SetLastError, SetEndOfFile, lstrcpynA, SetStdHandle, UnhandledExceptionFilter, GetStdHandle, VirtualAlloc, VirtualFree, HeapCreate, HeapDestroy, GetEnvironmentVariableA, HeapSize, FlushFileBuffers, WriteFile, SetUnhandledExceptionFilter, Sleep, GetPrivateProfileStringA, WritePrivateProfileStringA, DeleteFileA, LoadLibraryA, GetProcAddress, GetCurrentProcess, FreeLibrary, GetModuleFileNameA, CreateMutexA, GetComputerNameA, GetLastError, WaitForSingleObject, ReleaseMutex, GetVersionExA, CloseHandle, MultiByteToWideChar, WideCharToMultiByte, GetStartupInfoA, SetHandleCount, IsBadReadPtr, IsBadWritePtr, GetCurrentDirectoryA, SetCurrentDirectoryA, CreateDirectoryA, CreateFileA, CopyFileA, lstrcmpiA, LCMapStringA, GetLocaleInfoA, GetOEMCP, TlsGetValue, GetACP, GetCPInfo, RemoveDirectoryW, GetFullPathNameA, ExitProcess, GetCommandLineA, GetFileType, ResumeThread, ExitThread, TlsSetValue, GetDriveTypeA, FileTimeToLocalFileTime, FileTimeToSystemTime, RaiseException, GetSystemTime, GetTimeZoneInformation, RtlUnwind, InterlockedIncrement, DeleteFileW, GetStringTypeA, InterlockedDecrement, FindFirstFileW, FindNextFileW, TlsAlloc, InterlockedExchange, SetEnvironmentVariableA, CompareStringW, CompareStringA, GetLocaleInfoW, IsBadCodePtr, GetUserDefaultLCID, EnumSystemLocalesA, IsValidCodePage, IsValidLocale, GetStringTypeW, GetEnvironmentStrings, FreeEnvironmentStringsW, GetEnvironmentStringsW, GetSystemDefaultLangID, FreeEnvironmentStringsA, GetVersion, GetCurrentThreadId, LCMapStringW
libtmcav.dll
StopTmCAV, StartTmCAV
ofcdog.dll
C_RegWatchDog_Ofc_TMLISTEN, C_UnRegWatchDog_Ofc_TMLISTEN
ofcpipc.dll
OIPC_SendData, OIPC_CmdDataCopy, OIPC_CreateCommand, OIPC_ReceiveStart, OIPC_FreeCommand, OIPC_Init, OIPC_ReceiveStop, OIPC_DeInit
ofcpluginapi.dll
plgin_MainInit, plgin_MainDeInit, plgin_ApiDeInit, plgin_MainGetProductID, plgin_MainGetCtrlFlag, plgin_ApiInit, plgin_MainDoSchedule, plgin_MainGetSchedule
ole32.dll
CoCreateInstance, CoInitialize, StringFromGUID2, CoUninitialize
shell32.dll
SHGetSpecialFolderLocation, SHGetMalloc, SHGetDesktopFolder
snmpapi.dll
SnmpUtilVarBindFree, SnmpUtilOidCpy, SnmpUtilOidNCmp
tmsock.dll
tmIsLocalIPChanged, tmDelObj, tmWriteBody, tmNewObj, tmRemoveICF, tmIsServerAliveByPing, tmDecrypt
user32.dll
CharUpperA, CharLowerA, MessageBoxA, EnableMenuItem, GetUserObjectSecurity, SetUserObjectSecurity, LoadStringA, GetSystemMenu, wsprintfA, RegisterWindowMessageA, PostMessageA, SendMessageA, FindWindowA
version.dll
VerQueryValueA, GetFileVersionInfoSizeA, GetFileVersionInfoA

tmlisten.exe

Trend Micro OfficeScan by Trend Micro

Remove tmlisten.exe
Version:   7.0.0.1040
MD5:   9d59a71a480602e4b7e00e40a75e9950
SHA1:   bfac0fe7e05947f167e70d257a95ce0fbf0c6199

Overview

tmlisten.exe runs as a service under the name OfficeScanNT Listener (tmlisten) with extensive SYSTEM privileges (full administrator access). This particular version is usually found on Microsoft Windows XP (5.1.2600.131072).

DetailsDetails

File name:tmlisten.exe
Publisher:Trend Micro Inc.
Product name:Trend Micro OfficeScan
Typical file path:C:\Program Files\trend micro\officescan client\tmlisten.exe
File version:7.0.0.1040
Product version:7.0
Size:576.09 KB (589,912 bytes)
Build date:3/15/2005 12:46 PM
Digital DNA
PE subsystem:Windows Console
File packed:No
.NET CLR:No
More details

BehaviorsBehaviors

Service
Runs under 'SYSTEM\CurrentControlSet\Services' by the Service Controller (services.exe)
  • 'tmlisten' (OfficeScanNT Listener)

ResourcesResource utilization

(Note: statistics below are averages based on a minimum sample size of 200 unique participants)
Averages
 
CPU
Total CPU:0.00438279%
0.028634%
Kernel CPU:0.00350623%
0.013761%
User CPU:0.00087656%
0.014873%
Kernel CPU time:813 ms/min
100,923,805ms/min
Context switches:2/sec
284/sec
Memory
Private memory:3.84 MB
21.59 MB
Private (maximum):7.23 MB
Private (minimum):7.13 MB
Non-paged memory:3.84 MB
21.59 MB
Virtual memory:50.64 MB
140.96 MB
Virtual memory (peak):56.59 MB
169.69 MB
Working set:7.23 MB
18.61 MB
Working set (peak):7.7 MB
37.95 MB
Resource allocations
Threads:11
12
Handles:160
600
GUI GDI count:8
103
GUI USER count:3
49

BehaviorsProcess properties

Integrety level:Undefined
Platform:32-bit
Command line:"C:\Program Files\trend micro\officescan client\tmlisten.exe"
Owner:SYSTEM
Windows Service
Service name:tmlisten
Display name:OfficeScanNT Listener
Type:Win32OwnProcess, InteractiveProcess
Parent process:services.exe (Services and Controller app by Microsoft)

ResourcesThreads

Averages
 
tmlisten.exe (main module)
Total CPU:0.00207928%
0.272967%
Kernel CPU:0.00158191%
0.107585%
User CPU:0.00049737%
0.165382%
Context switches:1/sec
79/sec
Memory:680 KB
1.16 MB
ADVAPI32.dll
Total CPU:0.00094129%
Kernel CPU:0.00067235%
User CPU:0.00026894%
Memory:620 KB

Common loaded modules

These are modules that are typiclaly loaded within the context of this process.

Windows OS versionsDistribution by Windows OS

OS versiondistribution
Microsoft Windows XP 100.00%

OEM distributionDistribution by PC manufacturer

PC Manufacturerdistribution
Toshiba 100.00%
Should I remove It? Clean your PC of unwanted adware, toolbars and bloatware.

Download it for FREE