"bndaemon.exe" Process on Windows 7

Q

What is the "bndaemon.exe" process on windows 7? Is the "bndaemon.exe" process a virus? Can I terminate the "bndaemon.exe" process?

✍: FYIcenter.com

A

"bndaemon.exe" process represents "Persistent Agent Service" program. "bndaemon.exe" is for "Bradford Persistent Agent Service" which is the Client Security Agent Service provided by Bradford Networks to support Network Access Control (NAC). This allows the network administrator to remotely manage securities on your computer.

"bndaemon.exe" process is normally running under the parent process "services" as shown in the process tree below:

Boot
   wininit
      services
         bndaemon

On the Processes tab of "Task Manager", "bndaemon.exe" process may be listed as:

Image Name                 Memory   Description
--------------------   ----------   -----------
bndaemon.exe             12,580 K   Persistent Agent Service

Additional information about "bndaemon.exe" process:

Command line:
   "C:\Program Files (x86)\Bradford Networks\Persistent Agent\bndaemon.exe"

Programe file information:
   Name: bndaemon.exe
   Location: C:\Program Files (x86)\Bradford Networks\Persistent Agent\bndaemon.exe
   Description: Persistent Agent Service
   Version: 
   Size: 4401800 bytes
   Last modified: 1/26/2016 4:32:36 PM
   Company Name: Bradford Networks
   
Some data files used:
C:\Windows
C:\Windows\SysWOW64
C:\Windows\SysWOW64\en-US\setupapi.dll.mui
C:\ProgramData\Bradford Networks\stderr.txt
C:\ProgramData\Bradford Networks\stdout.txt
C:\ProgramData\Bradford Networks\bndaemon_log.txt

Some registry keys used:
HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options
HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options
HKLM\SYSTEM\ControlSet001\Control\Nls\Sorting\Versions
HKLM\SYSTEM\ControlSet001\Control\SESSION MANAGER
HKLM\SYSTEM\ControlSet001\Control\Nls\CustomLocale
HKLM\SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\explorer\FolderDescriptions\{905E63B6-C1BF-494E-B29C-65B732D3D21A}\PropertyBag
HKLM\SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\explorer\FolderDescriptions\{7C5A40EF-A0FB-4BFC-874A-C0F2E0B9FA8E}\PropertyBag
HKLM\SOFTWARE\Wow6432Node\Bradford Networks\Client Security Agent
HKLM\SOFTWARE\Policies\Bradford Networks\Persistent Agent
HKLM\SYSTEM\ControlSet001\Control\Nls\CodePage

Some DLL libraries used:
C:\windows\SYSTEM32\ntdll.dll
C:\windows\SYSTEM32\wow64.dll
C:\windows\SYSTEM32\wow64win.dll
C:\windows\SYSTEM32\wow64cpu.dll
C:\Program Files (x86)\Bradford Networks\Persistent Agent\bndaemon.exe
C:\windows\SysWOW64\ntdll.dll
C:\windows\syswow64\kernel32.dll
C:\windows\syswow64\KERNELBASE.dll
C:\windows\SysWOW64\WSOCK32.dll
C:\windows\syswow64\WS2_32.dll

"bndaemon.exe" process is not a virus. You can terminate "bndaemon.exe" process or stop "Bradford Persistent Agent Service". But your network administrator may want you keep it running, so he/she can control your computer remotely.

 

Application Service Processes on Windows 7

⇒⇒Windows 7 Processes Tutorials

2016-07-21, 1716👍, 0💬