What is stuffer.exe brought by Statblaster 7.0??

How could they find anything, they check every file one second or less.... Thats not enuff time to decrypt a custom or unknown trojan :(

Using heuristics, known patterns of virus/trojan type activity, and known methods of hiding from the O/S. Barring that, someone could submit the .exe to a couple of the major virus companies, and they will figure it out and add it to their lists (that's a pretty slow process tho, could take a while).
 
What to do then?

Last ditch effort is always to wipe your O/S and reinstall fresh. Sucks but sometimes it ends up being the easiest thing to do. This is why I like to use VM's for questionable stuff first (although I was stupid and ran statblaster on my regular machine, just got lucky it seems)
 
Be aware!! this : after you run it, puts stuffer.exe into temp folder and runs it up right after Statblaster 7.0 does its job.

That stuffer.exe changes your internet connection option to Proxy and opens port and tries to connect to external server, etc.

:confused:

Now, come to think of it, after re-reading omoxx's post (Thanks BTW) it is probably packed with the exe .... still a chance it is (was) a trojan downloaded from a site on the last entries of the list ...hmmm, but more than likely packed with the exe.
 
So it seems that Statblaster picked up this stuffer.exe from blasting?

Just a guess on my part but looks like there is evidence to support the theory. I would highly recommend grabbing that cleaned keyword list with all the foreign domains removed if you still want to use it.. I've just ditched it all together tho, I don't need the headaches.
 
Be aware!! this : after you run it, puts stuffer.exe into temp folder and runs it up right after Statblaster 7.0 does its job.

That stuffer.exe changes your internet connection option to Proxy and opens port and tries to connect to external server, etc.

:confused:

How did you figure this out, anyway?
 
OK, found a rootkit infection from malewarebytes scan. xitld.sys, but i cant get the little cunt out.

Recovery Console is your best friend here. Write down the full path to the thing, boot off your Windows cd, get into recovery console, and del the bastard :D Alternately get a LiveCD like BartPE or any Linux one and delete from there.
 
Thanks for the share. Come to think of it, someone has been changing my internet connection too. I thought it was senuke not properly closed.
 
So far I haven't had an issue. I downloaded 7.0 about a day after the download link went up. But does anyone have the non foreign URL list?
 
okay, you guys are freaking me out here.

How do I find out if this thing is on my machine or keep it from finding it's way here?

Do I need to stop using statblaster?

Thanks.
 
okay, you guys are freaking me out here.

How do I find out if this thing is on my machine or keep it from finding it's way here?

Do I need to stop using statblaster?

Thanks.

I would. There are other ways to get indexed quick.
 
Yeh, I tried to look for the non foreign url list, but I couldn't find it anywhere.....

Anyone cares to share?

cheers
 
this is a commision thief , it is hard to remove.
plz try professional adware remover, like Icesword
 
Well, still can't find anything. Its probably the later version that got trojan whetever.

I was using vers 4.1 that was released while sycthos (the real one) was still active in the forum
 
This is bullshit.

Nothing wrong with Statsblaster, and the latest version was version 7.1.

Some people were uploading alternative mirrors in the Statsblaster thread without giving a virustotal link and of cause they were probably infected with a virus.

Also sycthos should of warned people to have adequate firewall security on their systems before running the tool, because some of the websites had placed nasty trojans on their servers obviously pissed off having their servers hit with thousands of requests from this tool. When ever my Kaspersky Firewall detects and blocks a site trying to plant a trojan on my system, i simply delete it from the url list in statsblaster.

Dodgy Urls in list:

Code:
http://www.editechial.com/?url=[URL]
http://www.zhanghangfeng.cn/catalog.asp?tags=[URL]
http://carpet-underlays.co.uk/cevcy.php?idx=login.[URL]
http://www.hotbar.com/results.aspx?page=1&sort=0&ct=204&search=http://www.[URL]/navidad_
http://www.hotbar.com/results.aspx?search=http://www.[URL]
Delete these from the list, i will post more if i find any.

This is a download of the URL list that came with Statsblaster v7.1, that has been cleaned by myself of trojan urls.

Code:
http://rapidshare.com/files/357546955/urls.txt
 
Last edited:
This is bullshit.

Nothing wrong with Statsblaster, and the latest version was version 7.1.

Some people were uploading alternative mirrors in the Statsblaster thread without giving a virustotal link and of cause they were probably infected with a virus.

Also sycthos should of warned people to have adequate firewall security on their systems before running the tool, because some of the websites had placed nasty trojans on their servers obviously pissed off having their servers hit with thousands of requests from this tool. When ever my Kaspersky Firewall detects and blocks a site trying to plant a trojan on my system, i simply delete it from the url list in statsblaster.

Dodgy Urls in list:

Code:
http://www.editechial.com/?url=[URL]
http://www.zhanghangfeng.cn/catalog.asp?tags=[URL]
http://carpet-underlays.co.uk/cevcy.php?idx=login.[URL]
http://www.hotbar.com/results.aspx?page=1&sort=0&ct=204&search=http://www.[URL]/navidad_
http://www.hotbar.com/results.aspx?search=http://www.[URL]
Delete these from the list, i will post more if i find any.

This is a download of the URL list that came with Statsblaster v7.1, that has been cleaned by myself of trojan urls.

Code:
http://rapidshare.com/files/357546955/urls.txt

Can you share Statsblaster v7.1, explain how to get rid of that stuffer.exe and how to configure the firewall to avoid that kind of freaks in the future, please?

Thanxxx
 
Could be bullshit ... buy I deleted it, and as far as what to use? ... I'll just use Scrapebox.

I just finished a 2 1/2 hour waste of time running Malwarebytes, SAS, AVG, TM RUBOTTED and a few others ... found nothing except a few cookies.

I don't need it anyway with SB. I just ran it on another machine for clients while my main machine was running SB.

Good luck all ...

jaybird
 
Can you share Statsblaster v7.1, explain how to get rid of that stuffer.exe and how to configure the firewall to avoid that kind of freaks in the future, please?

Thanxxx

I cant share Statsblaster myself, its probably been banned. My Kaspersky Firewall was setup automatically, any firewall worth its salt should be able to detect website urls attempting to install trojans and block them. Stuffer.exe hasnt ever been installed on my system, thats why i say its bullshit to blame Statsblaster. Try Spybot to see if that detects the Stuffer.exe file and helps you remove it.
 
if you want to remove it just uninstall mozilla (my case) and after that go in program files and remove the hole folder with mozilla (seems to be hidden there somewhere)
after that download a fresh copy and install it
that should work :)
 
Sycthos cant answer here at the moment because at the latest attack of hackers that posted trojaninfested software his account was one of the accounts that were hacked and misused. Together with some other accounts it seems.
Hes still shocked how this could happen because he had a strong password and no virus or trojan on its pc...

If something fishy would have been in statblaster itself it should be found by scanning. I think it came from one of these chinese sites. There were a couple of them that had viruses but sycthos cleaned them out of the list as soon someone wrote him the bad urls...

So I hope he will be back again. He couldnt contact the admins itself because the supportmail isnt monitored (why that?) so I wrote to an admin. Waiting for answer...
 
Back
Top