Click here to get back home

bmss.exe running on boot

 HomeNewsGroups | Search | About
 microsoft.public.windows.server.security    Post an article   get this group's latest topics as an RSS feed add this group's latest topics to your My MSN content add this group's latest topics to your My Yahoo content
Subject Author Date
bmss.exe running on boot Sean Stromberg 02-26-2006
Posted by Sean Stromberg on February 26, 2006, 2:56 am
Please log in for more thread options
I have a process that is starting on reboot of my server that is found in
C:\Windows\System32 called bmss.exe.

The description of the file is 'Windows NT BMonitor Session Manager'
File Version: 5.2.3571.0 (JASBR(ntvbl07).010424-2101}

I found it under the following entry in the registry:
HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\Session Manager
with a REG_MULTI_SZ called BootExecute with the following values:
bmssldr
autocheck autochk *
SsiEfr.ex

This seems like a huge security hole as it opens up a ton of ports that my
Firewall is blocking.

MVP's is this legit or is it someone masquerading as a proper process?

Thanks,
Sean



Posted by Steven L Umbach on February 28, 2006, 11:53 pm
Please log in for more thread options
I did a search for that file on Google and did not find anything definitive
but nothing that seemed to indicate malware. Other users have found it and
were also curious as to what it was. A search of Microsoft.com showed
nothing for that file which certainly makes it suspect. I checked my Windows
2003 and Windows 2000 test domain controllers and it does not exist on
either one. In addition to routine malware scans with the latest definitions
from the publishers website you should scan for spyware with something like
AdAware SE to see if anything is found.

You could use the tools Process Explorer, TCPView, and Autoruns all free
from SysInternals to gain more information about the process. Process
Explorer will for instance show what ports it uses and if it is associated
with any services. If nothing indicates it is a legitimate or needed process
you could use Autoruns to disable it from being started when the computer
starts up. The first link below shows Windows server port usage which my be
able to help determine if it is something that is indeed used by Windows
Server. --- Steve

http://support.microsoft.com/default.aspx?scid=kb;en-us;832017
http://www.sysinternals.com/Utilities/ProcessExplorer.html --- Process
Explorer
http://www.lavasoftusa.com/software/adaware/ --- AdAware

>I have a process that is starting on reboot of my server that is found in
>C:\Windows\System32 called bmss.exe.
>
> The description of the file is 'Windows NT BMonitor Session Manager'
> File Version: 5.2.3571.0 (JASBR(ntvbl07).010424-2101}
>
> I found it under the following entry in the registry:
> HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\Session Manager
> with a REG_MULTI_SZ called BootExecute with the following values:
> bmssldr
> autocheck autochk *
> SsiEfr.ex
>
> This seems like a huge security hole as it opens up a ton of ports that my
> Firewall is blocking.
>
> MVP's is this legit or is it someone masquerading as a proper process?
>
> Thanks,
> Sean
>



Similar ThreadsPosted
running .bat files January 9, 2008, 11:00 am
services running under a certain account August 15, 2005, 9:19 am
What's danger of running dcgpofix /target:both June 14, 2005, 12:41 pm
Running a program with elevated privilages November 12, 2007, 9:59 am
Anti Virus Solutions That Use Their Own Boot CD? July 2, 2008, 1:47 pm
Issuing of server/client authentication certs from an Ent. CA running on W2k3 Standard Edition May 14, 2007, 2:43 am
Boot Volume NTFS Permissions for Network Service July 3, 2006, 10:45 pm
KDC service hangs on start + cert error in event log at every boot March 30, 2007, 2:58 am
Re: Windows Update Agent not found, or the computer is not running Windows 2000 SP3 or later. October 18, 2005, 4:15 pm
SP-1 to a Windows 2003 Server running SQL Server 2000 with out SP- July 5, 2005, 5:20 pm

Our other projects:

Art Dolls, Fairies and Mermaids - Sunnyfaces.net

Roy's Linux, Programming and Search Engines messages

1-Script XML SitemapXML Sitemap