"bncsaui.exe" Process on Windows 7

Q

What is the "bncsaui.exe" process on windows 7? Is the "bncsaui.exe" process a virus? Can I terminate the "bncsaui.exe" process?

✍: FYIcenter.com

A

"bncsaui.exe" process is part of Client Security Agent provided by Bradford Networks to support Network Access Control (NAC). This allows the network administrator to remotely manage securities on your computer.

"bncsaui.exe" process is normally running under the parent process "Boot" as shown in the process tree below:

Boot
   bncsaui

On the Processes tab of "Task Manager", "bncsaui.exe" process may be listed as:

Image Name                 Memory   Description
--------------------   ----------   -----------
bncsaui.exe               9,556 K   

Additional information about "bncsaui.exe" process:

Command line:
   "C:\Program Files (x86)\Bradford Networks\Persistent Agent\bncsaui.exe" 

Programe file information:
   Name: bncsaui.exe
   Location: C:\Program Files (x86)\Bradford Networks\Persistent Agent\bncsaui.exe
   Description: 
   Version: 
   Size: 8223368 bytes
   Last modified: 1/26/2016 4:32:38 PM
   Company Name: 
   
Some data files used:
C:\Windows
C:\Windows\SysWOW64
C:\Users\fyicenter\AppData\Local\Temp\1-bncsaui.txt
C:\Windows\Fonts\StaticCache.dat

Some registry keys used:
HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options
HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options
HKLM\SYSTEM\ControlSet001\Control\Nls\Sorting\Versions
HKLM\SYSTEM\ControlSet001\Control\SESSION MANAGER
HKLM\SYSTEM\ControlSet001\Control\Nls\Locale\Alternate Sorts
HKLM\SYSTEM\ControlSet001\Control\Nls\CustomLocale
HKLM\SYSTEM\ControlSet001\services\WinSock2\Parameters\Protocol_Catalog9
HKLM\SYSTEM\ControlSet001\services\WinSock2\Parameters\NameSpace_Catalog5
HKLM\SYSTEM\ControlSet001\Control\Nls\Language Groups
HKLM\SYSTEM\ControlSet001\Control\Nls\Locale

Some DLL libraries used:
C:\windows\SYSTEM32\ntdll.dll
C:\windows\SYSTEM32\wow64.dll
C:\windows\SYSTEM32\wow64win.dll
C:\windows\SYSTEM32\wow64cpu.dll
C:\Program Files (x86)\Bradford Networks\Persistent Agent\bncsaui.exe
C:\windows\SysWOW64\ntdll.dll
C:\windows\syswow64\kernel32.dll
C:\windows\syswow64\KERNELBASE.dll
C:\windows\syswow64\IMM32.dll
C:\windows\syswow64\USER32.dll

"bncsaui.exe" process is not a virus. You can terminate "bncsaui.exe" process or remote the startup program entry "bncsaui". But your network administrator may want you keep it running, so he/she can control your computer remotely.

 

Startup Program Processes on Windows 7

⇒⇒Windows 7 Processes Tutorials

2016-07-14, 1859👍, 0💬