If you haven't yet discovered Microsoft's Baseline Security Analyzer (MBSA), you should go download and run it. I did so a few weeks ago and discovered that a port scanner I'd tried (GFI Languard) had created an Administrator account on my PC . . . with no password! Can you believe that? A *SECURITY* company put that on my computer.
They sure fooled me. I hope they're proud of themselves. Fortunately, only a week passed before I found it with MBSA and removed it.
Anyway, MBSA is a great FREE tool that you can trust. No agent... easy installation... runs very quickly and only when you tell it to... results and recommendations that couldn't be clearer.
http://www.microsoft.com/download/en/details.aspx?id=7558