Bomgar Remote Support Service
bt-bomgar-service is a core Windows service used by Bomgar remote support deployments to maintain secure, long-running connections between technicians and client machines. It runs in the background, starts at system boot, and coordinates session handoffs, heartbeat checks, and policy enforcement. This component enables unattended access and real-time diagnostic capabilities in managed IT environments.
It operates as a Windows service (bt-bomgar-service.exe) and manages persistent connections, session lifecycle, and credential handling. It negotiates TLS channels with Bomgar gateways, routes commands from the Console to endpoints, and logs remote activities for auditing and compliance.
bt-bomgar-service is a legitimate component of Bomgar remote support deployments. When installed by your organization, it runs as a signed Windows service with restricted privileges appropriate for service operation. In normal use, it only communicates with Bomgar gateways, adheres to configured access controls, and is governed by enterprise security policies. If you legitimately require remote support, this service supports secure session orchestration without exposing the system to unmanaged access.
Under normal circumstances, bt-bomgar-service itself is not a virus; it is a signed part of Bomgar software used for remote support. However, malware can masquerade as legitimate services. Always verify vendor signatures, startup path, and network activity. If you did not install Bomgar or anticipate remote assistance, treat the binary with suspicion and conduct a thorough malware scan.
Red Flags: If the file path differs, the certificate is missing or revoked, the hash does not match the expected value, or the service shows unexpected network connections, treat bt-bomgar-service as suspicious and isolate the host until verification completes.
Reasons it's running: