<?xml version="1.0" encoding="UTF-8"?><rss version="2.0"
	xmlns:content="http://purl.org/rss/1.0/modules/content/"
	xmlns:dc="http://purl.org/dc/elements/1.1/"
	xmlns:atom="http://www.w3.org/2005/Atom"
	xmlns:sy="http://purl.org/rss/1.0/modules/syndication/"
		>
<channel>
	<title>Comments on: The Developing Story of Bravesentry</title>
	<atom:link href="http://www.netsato.com/2006/03/12/the-developing-story-of-bravesentry/feed/" rel="self" type="application/rss+xml" />
	<link>http://www.netsato.com/2006/03/12/the-developing-story-of-bravesentry/</link>
	<description>Homestay, Japan, Hawaii, Parenting &#038; Computers</description>
	<lastBuildDate>Sat, 22 Jan 2011 06:29:37 +0800</lastBuildDate>
	<generator>http://wordpress.org/?v=2.8.6</generator>
	<sy:updatePeriod>hourly</sy:updatePeriod>
	<sy:updateFrequency>1</sy:updateFrequency>
		<item>
		<title>By: Joshua</title>
		<link>http://www.netsato.com/2006/03/12/the-developing-story-of-bravesentry/comment-page-1/#comment-733</link>
		<dc:creator>Joshua</dc:creator>
		<pubDate>Thu, 29 Mar 2007 06:17:53 +0000</pubDate>
		<guid isPermaLink="false">http://www.netsato.com/2006/03/12/the-developing-story-of-bravesentry/#comment-733</guid>
		<description>I am the onwer of a very small startup, and I received a desktop support call from a UPS store in Concord, Ca.

I successfully tracked down and remove the Brave Sentry file folder, and all of the necessarry files.  I am now working on cleaning the registry out and getting rid of the .dll files.  

The Dcom Prcess Server has become active, and continues to fail.  

Does anyone have a fix for the Dcom besides changing the settings to disabled?

Josh</description>
		<content:encoded><![CDATA[<p>I am the onwer of a very small startup, and I received a desktop support call from a UPS store in Concord, Ca.</p>
<p>I successfully tracked down and remove the Brave Sentry file folder, and all of the necessarry files.  I am now working on cleaning the registry out and getting rid of the .dll files.  </p>
<p>The Dcom Prcess Server has become active, and continues to fail.  </p>
<p>Does anyone have a fix for the Dcom besides changing the settings to disabled?</p>
<p>Josh</p>
]]></content:encoded>
	</item>
	<item>
		<title>By: Manesh</title>
		<link>http://www.netsato.com/2006/03/12/the-developing-story-of-bravesentry/comment-page-1/#comment-438</link>
		<dc:creator>Manesh</dc:creator>
		<pubDate>Wed, 17 Jan 2007 09:56:34 +0000</pubDate>
		<guid isPermaLink="false">http://www.netsato.com/2006/03/12/the-developing-story-of-bravesentry/#comment-438</guid>
		<description>It seems that one or more of the msconfig startup items are responsible for administering the effects of the bravesentry trojan</description>
		<content:encoded><![CDATA[<p>It seems that one or more of the msconfig startup items are responsible for administering the effects of the bravesentry trojan</p>
]]></content:encoded>
	</item>
	<item>
		<title>By: Gary</title>
		<link>http://www.netsato.com/2006/03/12/the-developing-story-of-bravesentry/comment-page-1/#comment-113</link>
		<dc:creator>Gary</dc:creator>
		<pubDate>Sat, 23 Sep 2006 08:26:52 +0000</pubDate>
		<guid isPermaLink="false">http://www.netsato.com/2006/03/12/the-developing-story-of-bravesentry/#comment-113</guid>
		<description>Yesterday, I seem to have picked up BraveSentry. I&#039;m not certain how/where I picked it up, but I realised that I&#039;d only recently set up the computer (not this one - the infected one&#039;s running a scan right now) and didn&#039;t have a firewall running ... so I guess I asked for it. It&#039;s a clever, but evil, piece of software ... luckily, a search in Google turned up your page!</description>
		<content:encoded><![CDATA[<p>Yesterday, I seem to have picked up BraveSentry. I&#8217;m not certain how/where I picked it up, but I realised that I&#8217;d only recently set up the computer (not this one &#8211; the infected one&#8217;s running a scan right now) and didn&#8217;t have a firewall running &#8230; so I guess I asked for it. It&#8217;s a clever, but evil, piece of software &#8230; luckily, a search in Google turned up your page!</p>
]]></content:encoded>
	</item>
	<item>
		<title>By: Michael Brennan</title>
		<link>http://www.netsato.com/2006/03/12/the-developing-story-of-bravesentry/comment-page-1/#comment-110</link>
		<dc:creator>Michael Brennan</dc:creator>
		<pubDate>Tue, 12 Sep 2006 18:11:57 +0000</pubDate>
		<guid isPermaLink="false">http://www.netsato.com/2006/03/12/the-developing-story-of-bravesentry/#comment-110</guid>
		<description>This illustration from spywarewarrior&#039;s website shows what I saw when &quot;Brave Sentry&quot; began to unpack and install itself:

http://www.spywarewarrior.com/pics/bs-2.jpg

One can imagine the jam a nOOb would feel himself or herself in, confronted by this aggressive pest.  This is abject abuse of skills against the uninitiated and helpless, the equivalent of a crude robbery-by-force.</description>
		<content:encoded><![CDATA[<p>This illustration from spywarewarrior&#8217;s website shows what I saw when &#8220;Brave Sentry&#8221; began to unpack and install itself:</p>
<p><a href="http://www.spywarewarrior.com/pics/bs-2.jpg" rel="nofollow">http://www.spywarewarrior.com/pics/bs-2.jpg</a></p>
<p>One can imagine the jam a nOOb would feel himself or herself in, confronted by this aggressive pest.  This is abject abuse of skills against the uninitiated and helpless, the equivalent of a crude robbery-by-force.</p>
]]></content:encoded>
	</item>
	<item>
		<title>By: Michael Brennan</title>
		<link>http://www.netsato.com/2006/03/12/the-developing-story-of-bravesentry/comment-page-1/#comment-109</link>
		<dc:creator>Michael Brennan</dc:creator>
		<pubDate>Tue, 12 Sep 2006 17:10:32 +0000</pubDate>
		<guid isPermaLink="false">http://www.netsato.com/2006/03/12/the-developing-story-of-bravesentry/#comment-109</guid>
		<description>First, my system specs.  My computer is an older IBM ThinkPad 1411i, 4.3GB HDD, 160 megs SDRAM, 300MHz P-II MMX processor running Win 98.  Browsers:  IE 5.5, Firefox 1.0.5, Netscape 4.77.  Mail client OE 5.5 (also NS for newsgroup posting).  Net connection:  pair-gain loop-limited dialup, 26.4 KBaud (courtesy of SBC, which is holding the neighborhood&#039;s head underwater in hopes we&#039;ll all sign up for their DSL deal =&gt; more yummy income).

I just had an experience of my own with Brave Sentry.  I noticed a &quot;meatball&quot; in my system tray a couple of days ago while working online and assumed it had been generated by an update of my Grisoft AVG.  I began scanning with various tools and found real Trojans and worms:  

ByteVerify [Java worm] (Spyware Nuker XT)
Proxy.ENI
Downloader2.QUS (AVG)
Spy Sheriff
Counter Spy
Child Safe / WinGuardian [monitor/logger]

The Spy Sheriff detection (and possibly WinGuardian as well) , by a freeware scanner based on an older release of SpySweeper that is distributed by Earthlink through their homepage (the removal tools are available to Earthlink subscribers), was really Brave Sentry.  The near-identity of these malware apps is discussed by spywarewarrior.com, whose link I followed here to NetSato.

After chasing the various infected/infecting files around with AVG and Spyware Nuker XT for a couple of days, I thought I had finally stamped out the Trojan infection.  A partial listing of files I removed:

BlackBox.class
VerifierBug.class
Beyond.class
Proxy.ENI  (see also below)

These were discovered by Spyware Nuker XT and Spy Sweeper (Earthlink&#039;s ELspyaudit.exe) together with Task Man and closely-spaced AVG scans of the WINDOWS/SYSTEM files.

In addition, here is a copy of my AVG log of the malware files found by its scans:

Trojan horse Downloader.Generic2.DQC   C:\WINDOWS\SYSTEM\vxgamet3.exe   9/10/06 8:19:47 PM   
vxgamet3.exe   11.22 KB
     
 Trojan horse Downloader.Generic.QUS   C:\WINDOWS\SYSTEM\vxgamet4.exe   9/10/06 8:19:47 PM   vxgamet4.exe   1.59 KB
      
Trojan horse Downloader.Generic.QUS   C:\WINDOWS\TEMP\1.dlb   9/10/06 8:19:47 PM   1.dlb   2.46 KB
      
Trojan horse Downloader.Generic2.MWW   C:\WINDOWS\TEMP\5.dlb   9/10/06 8:19:48 PM   5.dlb   4.17 KB
      
Trojan horse Proxy.ENI   C:\WINDOWS\TEMP\vx6.game   9/10/06 8:19:48 PM   vx6.game   14.73 KB
      
Trojan horse Downloader.Generic2.DQC   C:\WINDOWS\TEMP\vxt3.game   9/10/06 8:19:48 PM   vxt3.game   11.22 KB
      
Trojan horse Downloader.Generic.QUS   C:\WINDOWS\TEMP\vxt4.game   9/10/06 8:19:48 PM   vxt4.game   1.59 KB
      
Trojan horse Downloader.Generic.QUS   C:\WINDOWS\TEMP\1.dlb   9/10/06 3:21:38 PM   1.dlb   2.46 KB
      
Trojan horse Downloader.Generic2.MWW   C:\WINDOWS\TEMP\5.dlb   9/10/06 3:21:38 PM   5.dlb   4.17 KB
      
Trojan horse Downloader.Generic2.LGI   C:\WINDOWS\TEMP\vx3.game   9/10/06 8:19:48 PM   vx3.game   2 KB
      
Trojan horse Generic.YZR   C:\WINDOWS\TEMP\vx4.game   9/10/06 8:19:48 PM   vx4.game   14 KB
      
Virus found SpySheriff   C:\WINDOWS\DESKTOP.HTML   9/11/06 11:52:49 AM   DESKTOP.HTML   1.95 KB
      
Trojan horse Downloader.Generic.QUS   C:\WINDOWS\SYSTEM\DLH9JKDQ1.EXE   9/10/06 7:00:11 PM   DLH9JKDQ1.EXE   2.46 KB
      
Trojan horse Downloader.Generic2.MWW   C:\WINDOWS\SYSTEM\DLH9JKDQ5.EXE   9/10/06 7:00:52 PM   DLH9JKDQ5.EXE   4.17 KB
      
Trojan horse Downloader.Generic2.LGI   C:\WINDOWS\SYSTEM\VXGAME3.EXE   9/10/06 7:04:28 PM   VXGAME3.EXE   2 KB
      
Trojan horse Generic.YZR   C:\WINDOWS\SYSTEM\VXGAME4.EXE   9/10/06 7:05:23 PM   VXGAME4.EXE   14 KB
      
Trojan horse Proxy.ENI   C:\WINDOWS\SYSTEM\VXGAME6.EXE   9/10/06 7:06:23 PM   VXGAME6.EXE   14.73 KB

After a system secure shutdown with Evidence Eliminator (deletion of all TEMP files, cookies, and recycling-bin contents, followed by overwriting of the deleted material and all free space on the hard drive), I booted up to discover the meatball was back.  Curious -- and apprehending that I hadn&#039;t gotten the installation .EXE file -- I double-clicked on the meatball.  Brave Sentry immediately began to unpack from whatever (probably encrypted as well as hidden) zipfile it had been lurking in and began to install.  I called Task Manager right away and stopped the installation.  I noticed that two suspect processes I&#039;d seen and killed the previous day were back:  

xpupdate  (nice ute to have, considering I&#039;m running Win98)
dlh9jkdq1.exe

I killed them and then systematically began deleting the Brave Sentry folders and files (avoiding the Uninstal.exe utility) from the Program Files/ and Windows/Start Menu directories.

Since that point, the malware processes associated with Brave Sentry and its companion Trojans have not yet reappeared, so far, but I expect to see them again at the next restart, if I don&#039;t locate a removal tool for the hidden file which is dropping fresh copies of everything on reboot.  This task is what led me, chasing links, to the NetSato weblog.

I am in the dark about the source of the infection.  There are two possibilities:  one is spammers looking for ways to distribute remote-administration Trojans with their spew, which I handle daily with OE 5.5, and the other is a drive-by, stealth download acquired while visiting Epinions.com two days ago with IE 5.5 and reading product-review wiki entries there.

I, too, would like to receive communications with more information about this pest and where I could find a removal tool that will allow me to avoid reformatting or deploying backup copies of configuration files.</description>
		<content:encoded><![CDATA[<p>First, my system specs.  My computer is an older IBM ThinkPad 1411i, 4.3GB HDD, 160 megs SDRAM, 300MHz P-II MMX processor running Win 98.  Browsers:  IE 5.5, Firefox 1.0.5, Netscape 4.77.  Mail client OE 5.5 (also NS for newsgroup posting).  Net connection:  pair-gain loop-limited dialup, 26.4 KBaud (courtesy of SBC, which is holding the neighborhood&#8217;s head underwater in hopes we&#8217;ll all sign up for their DSL deal =&gt; more yummy income).</p>
<p>I just had an experience of my own with Brave Sentry.  I noticed a &#8220;meatball&#8221; in my system tray a couple of days ago while working online and assumed it had been generated by an update of my Grisoft AVG.  I began scanning with various tools and found real Trojans and worms:  </p>
<p>ByteVerify [Java worm] (Spyware Nuker XT)<br />
Proxy.ENI<br />
Downloader2.QUS (AVG)<br />
Spy Sheriff<br />
Counter Spy<br />
Child Safe / WinGuardian [monitor/logger]</p>
<p>The Spy Sheriff detection (and possibly WinGuardian as well) , by a freeware scanner based on an older release of SpySweeper that is distributed by Earthlink through their homepage (the removal tools are available to Earthlink subscribers), was really Brave Sentry.  The near-identity of these malware apps is discussed by spywarewarrior.com, whose link I followed here to NetSato.</p>
<p>After chasing the various infected/infecting files around with AVG and Spyware Nuker XT for a couple of days, I thought I had finally stamped out the Trojan infection.  A partial listing of files I removed:</p>
<p>BlackBox.class<br />
VerifierBug.class<br />
Beyond.class<br />
Proxy.ENI  (see also below)</p>
<p>These were discovered by Spyware Nuker XT and Spy Sweeper (Earthlink&#8217;s ELspyaudit.exe) together with Task Man and closely-spaced AVG scans of the WINDOWS/SYSTEM files.</p>
<p>In addition, here is a copy of my AVG log of the malware files found by its scans:</p>
<p>Trojan horse Downloader.Generic2.DQC   C:\WINDOWS\SYSTEM\vxgamet3.exe   9/10/06 8:19:47 PM<br />
vxgamet3.exe   11.22 KB</p>
<p> Trojan horse Downloader.Generic.QUS   C:\WINDOWS\SYSTEM\vxgamet4.exe   9/10/06 8:19:47 PM   vxgamet4.exe   1.59 KB</p>
<p>Trojan horse Downloader.Generic.QUS   C:\WINDOWS\TEMP\1.dlb   9/10/06 8:19:47 PM   1.dlb   2.46 KB</p>
<p>Trojan horse Downloader.Generic2.MWW   C:\WINDOWS\TEMP\5.dlb   9/10/06 8:19:48 PM   5.dlb   4.17 KB</p>
<p>Trojan horse Proxy.ENI   C:\WINDOWS\TEMP\vx6.game   9/10/06 8:19:48 PM   vx6.game   14.73 KB</p>
<p>Trojan horse Downloader.Generic2.DQC   C:\WINDOWS\TEMP\vxt3.game   9/10/06 8:19:48 PM   vxt3.game   11.22 KB</p>
<p>Trojan horse Downloader.Generic.QUS   C:\WINDOWS\TEMP\vxt4.game   9/10/06 8:19:48 PM   vxt4.game   1.59 KB</p>
<p>Trojan horse Downloader.Generic.QUS   C:\WINDOWS\TEMP\1.dlb   9/10/06 3:21:38 PM   1.dlb   2.46 KB</p>
<p>Trojan horse Downloader.Generic2.MWW   C:\WINDOWS\TEMP\5.dlb   9/10/06 3:21:38 PM   5.dlb   4.17 KB</p>
<p>Trojan horse Downloader.Generic2.LGI   C:\WINDOWS\TEMP\vx3.game   9/10/06 8:19:48 PM   vx3.game   2 KB</p>
<p>Trojan horse Generic.YZR   C:\WINDOWS\TEMP\vx4.game   9/10/06 8:19:48 PM   vx4.game   14 KB</p>
<p>Virus found SpySheriff   C:\WINDOWS\DESKTOP.HTML   9/11/06 11:52:49 AM   DESKTOP.HTML   1.95 KB</p>
<p>Trojan horse Downloader.Generic.QUS   C:\WINDOWS\SYSTEM\DLH9JKDQ1.EXE   9/10/06 7:00:11 PM   DLH9JKDQ1.EXE   2.46 KB</p>
<p>Trojan horse Downloader.Generic2.MWW   C:\WINDOWS\SYSTEM\DLH9JKDQ5.EXE   9/10/06 7:00:52 PM   DLH9JKDQ5.EXE   4.17 KB</p>
<p>Trojan horse Downloader.Generic2.LGI   C:\WINDOWS\SYSTEM\VXGAME3.EXE   9/10/06 7:04:28 PM   VXGAME3.EXE   2 KB</p>
<p>Trojan horse Generic.YZR   C:\WINDOWS\SYSTEM\VXGAME4.EXE   9/10/06 7:05:23 PM   VXGAME4.EXE   14 KB</p>
<p>Trojan horse Proxy.ENI   C:\WINDOWS\SYSTEM\VXGAME6.EXE   9/10/06 7:06:23 PM   VXGAME6.EXE   14.73 KB</p>
<p>After a system secure shutdown with Evidence Eliminator (deletion of all TEMP files, cookies, and recycling-bin contents, followed by overwriting of the deleted material and all free space on the hard drive), I booted up to discover the meatball was back.  Curious &#8212; and apprehending that I hadn&#8217;t gotten the installation .EXE file &#8212; I double-clicked on the meatball.  Brave Sentry immediately began to unpack from whatever (probably encrypted as well as hidden) zipfile it had been lurking in and began to install.  I called Task Manager right away and stopped the installation.  I noticed that two suspect processes I&#8217;d seen and killed the previous day were back:  </p>
<p>xpupdate  (nice ute to have, considering I&#8217;m running Win98)<br />
dlh9jkdq1.exe</p>
<p>I killed them and then systematically began deleting the Brave Sentry folders and files (avoiding the Uninstal.exe utility) from the Program Files/ and Windows/Start Menu directories.</p>
<p>Since that point, the malware processes associated with Brave Sentry and its companion Trojans have not yet reappeared, so far, but I expect to see them again at the next restart, if I don&#8217;t locate a removal tool for the hidden file which is dropping fresh copies of everything on reboot.  This task is what led me, chasing links, to the NetSato weblog.</p>
<p>I am in the dark about the source of the infection.  There are two possibilities:  one is spammers looking for ways to distribute remote-administration Trojans with their spew, which I handle daily with OE 5.5, and the other is a drive-by, stealth download acquired while visiting Epinions.com two days ago with IE 5.5 and reading product-review wiki entries there.</p>
<p>I, too, would like to receive communications with more information about this pest and where I could find a removal tool that will allow me to avoid reformatting or deploying backup copies of configuration files.</p>
]]></content:encoded>
	</item>
	<item>
		<title>By: jessica bowen</title>
		<link>http://www.netsato.com/2006/03/12/the-developing-story-of-bravesentry/comment-page-1/#comment-49</link>
		<dc:creator>jessica bowen</dc:creator>
		<pubDate>Thu, 15 Jun 2006 19:35:46 +0000</pubDate>
		<guid isPermaLink="false">http://www.netsato.com/2006/03/12/the-developing-story-of-bravesentry/#comment-49</guid>
		<description>I also got hijacked by Brave Sentry.  Maybe we should spread a rumor that they are spying for Al Queda and should be demolished.

Anyway, I sent an email to interpol with their supposed address in the Netherlands.

Argh!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!</description>
		<content:encoded><![CDATA[<p>I also got hijacked by Brave Sentry.  Maybe we should spread a rumor that they are spying for Al Queda and should be demolished.</p>
<p>Anyway, I sent an email to interpol with their supposed address in the Netherlands.</p>
<p>Argh!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!</p>
]]></content:encoded>
	</item>
	<item>
		<title>By: Netsato</title>
		<link>http://www.netsato.com/2006/03/12/the-developing-story-of-bravesentry/comment-page-1/#comment-21</link>
		<dc:creator>Netsato</dc:creator>
		<pubDate>Thu, 23 Mar 2006 03:29:58 +0000</pubDate>
		<guid isPermaLink="false">http://www.netsato.com/2006/03/12/the-developing-story-of-bravesentry/#comment-21</guid>
		<description>I would be very suspect of what Bravesentry claims to detect. If it is finding &quot;problems&quot; that no other software can find, then I would look to verify those findings elsewhere. Afterall, what better way to sell a lot of anti-virus/anti-spyware/anti-hacker software than to scare you into buying them with false positives. 

Think about it another way, if Bravesentry was really any good, why would it stoop to such aggressive &quot;hijacking&quot; tactics to get itself installed.</description>
		<content:encoded><![CDATA[<p>I would be very suspect of what Bravesentry claims to detect. If it is finding &#8220;problems&#8221; that no other software can find, then I would look to verify those findings elsewhere. Afterall, what better way to sell a lot of anti-virus/anti-spyware/anti-hacker software than to scare you into buying them with false positives. </p>
<p>Think about it another way, if Bravesentry was really any good, why would it stoop to such aggressive &#8220;hijacking&#8221; tactics to get itself installed.</p>
]]></content:encoded>
	</item>
	<item>
		<title>By: Nico from Austin, TX</title>
		<link>http://www.netsato.com/2006/03/12/the-developing-story-of-bravesentry/comment-page-1/#comment-19</link>
		<dc:creator>Nico from Austin, TX</dc:creator>
		<pubDate>Mon, 20 Mar 2006 19:32:44 +0000</pubDate>
		<guid isPermaLink="false">http://www.netsato.com/2006/03/12/the-developing-story-of-bravesentry/#comment-19</guid>
		<description>I&#039;ve been infected simultanelty by Bravesentry and many other trojans. I ran all the anti-virus I know and none is able to delete it. The only one who seems to detect and to be able to do so is bravesentry.... the problem is that you have to buy a license before being able to delete worms detected by the demo version...

Then Blackmailing or not?</description>
		<content:encoded><![CDATA[<p>I&#8217;ve been infected simultanelty by Bravesentry and many other trojans. I ran all the anti-virus I know and none is able to delete it. The only one who seems to detect and to be able to do so is bravesentry&#8230;. the problem is that you have to buy a license before being able to delete worms detected by the demo version&#8230;</p>
<p>Then Blackmailing or not?</p>
]]></content:encoded>
	</item>
</channel>
</rss>

