What is stuffer.exe brought by Statblaster 7.0??

Sycthos cant answer here at the moment because at the latest attack of hackers that posted trojaninfested software his account was one of the accounts that were hacked and misused. Together with some other accounts it seems.
Hes still shocked how this could happen because he had a strong password and no virus or trojan on its pc...

If something fishy would have been in statblaster itself it should be found by scanning. I think it came from one of these chinese sites. There were a couple of them that had viruses but sycthos cleaned them out of the list as soon someone wrote him the bad urls...

So I hope he will be back again. He couldnt contact the admins itself because the supportmail isnt monitored (why that?) so I wrote to an admin. Waiting for answer...

Good ... I hope this pans out ... it was very useful on a couple of other machines.

I suppose I didnt have it because I took the time over 2 or 3 days cleaning the list of all kinds of stuff....

Jaybird
 
the Stuffer.exe was pacted in statblaster 7.0 I don't know about other version or if this was intentional by the author or some other people who made mirrors. I can't remember if I download it from here or IJ. Anyways I know it comes pact in the program because I didn't do a blast just loaded it up to look at the interface then closed it. I noticed my internet seemed to slow down. So I looked at the taskmanager and low and behold there where 2 instances of stuffer.exe.
 
Has anyone tried if uninstalling Firefox , deleting the Mozilla folder and reinstalling the problem with stuffer.exe is solved?
 
i am really pissed off by that ..keeps changing my internet connection ..pleae anyone ?
i tried it all antivirus, antimalware, antitrojan...nothing found
 
I do not think removing Mozilla would solve the problem: you can find it in I.Explorer too!
 
The File Was Binded With A RAT (They Can Control Your PC From There PC). It Was Then Encrypted So It Will Become Undetectable. Remove Stuffer.exe ASAP. I Was Talking To Some Hacker And He Decrypted The File And Found Out This Info.
 
Is anybody willing to help us remove that f*cking stuffer.exe, please?
Thanxxx
 
Can we have any help, please?
Thank you
 
I remember sycthos mention the issue with the urls and how you could not update the list, and he later got the big updated list from a member of the forum and released it!
 
Is anybody willing to help us remove that f*cking stuffer.exe, please?
Thanxxx
 
I dont know... I had seen this stuffer.exe in my processlist someday but never had a problem with this. Its not found on my pc anywhere. So it seems Im not harmed from it.

If I would have a problem with it I would try hijackthis. Run the software, copy the list and paste it into the website that occurs when searching for hijackthis.

Then you get a list of your running processes and soft together with the risk of each entry. Dont delete everything hijackthis is finding. Its only listing everthing. good things too. So only check and delete the ones that are found as dangerous by the website.

Next thing would by Spybot S&D. He finds most bad things and I believe can delete dangerous things at startup too.

The more advanced trojans and similar dont come with one file. They have more than one file and more than one running process. So if you delete a file its written new. You dont have a chance to delete while runtime. So you need a tool that deletes that files before the os started. Because then the trojans arent started too. Only then you can delete the files and they arent recovered.

So I can only say you should try different adwareremovers and similar that are capable of detecting and deleting in bootup-process.

I arent damaged by stuffer.exe and so I cant say how it is removed.
 
the problem has been fixed for me

C:\Users\xxxxx\AppData\Roaming\Mozilla\Firefox\Profiles\7hto8twe.default

2 files have been deleted

prefs (jscript) and unfortunately i didn't see the 2nd one , but YES problem is in this folder
the name of the second one is similair to the 1st

Hope it helps
 
I do not have that 7hto8twe.default you mentioned!
Can you explain a little more, please?
 
wont be 7hto8twe for you depends on PC .but if u go to AppData\Roaming\Mozilla\Firefox\Profiles, look into it and find similair


I do not have that 7hto8twe.default you mentioned!
Can you explain a little more, please?
 
This is bullshit.

Nothing wrong with Statsblaster, and the latest version was version 7.1.

Some people were uploading alternative mirrors in the Statsblaster thread without giving a virustotal link and of cause they were probably infected with a virus.

Also sycthos should of warned people to have adequate firewall security on their systems before running the tool, because some of the websites had placed nasty trojans on their servers obviously pissed off having their servers hit with thousands of requests from this tool. When ever my Kaspersky Firewall detects and blocks a site trying to plant a trojan on my system, i simply delete it from the url list in statsblaster.

Dodgy Urls in list:

Code:
http://www.editechial.com/?url=[URL]
http://www.zhanghangfeng.cn/catalog.asp?tags=[URL]
http://carpet-underlays.co.uk/cevcy.php?idx=login.[URL]
http://www.hotbar.com/results.aspx?page=1&sort=0&ct=204&search=http://www.[URL]/navidad_
http://www.hotbar.com/results.aspx?search=http://www.[URL]
Delete these from the list, i will post more if i find any.

This is a download of the URL list that came with Statsblaster v7.1, that has been cleaned by myself of trojan urls.

Code:
http://rapidshare.com/files/357546955/urls.txt


I agree.

I never had a problem with StatBlaster.

It was an unfortunate event that the OP got his account hacked and misused, but he did give tons of warnings about watching the URLs lists and protecting your PC.

IMHO, it's common sense that you would want to protect your PC when downloading free stuff because when shit like this happens, you definitely want to be protected.
 
Back
Top