jbgfiubgiw
Новичок
- 6
- 0
Спасибо за инфу, а вот как мне узнать какой именно?У тебя стилер. Скорее всего формата .ASI.
Спасибо за инфу, а вот как мне узнать какой именно?У тебя стилер. Скорее всего формата .ASI.
@DarkP1xelЗакинул антистиллер в папку с гта, пытаюсь заходить через клиент, но этого не происходит. Смотрю лог, вижу это:
[PATCHED] > [RtlCreateProcessParametersEx] > [C:\Windows\system32\kernel32.dll] > {ImagePathName->Buffer: C:\Windows\system32\rundll32.exe}
Войти в игру не получается, когда, кстати, перехожу на другую сборку, где есть так же этот антистиллер, то проблем со входом в игру не возникает.
Прошу помочь в решении проблемы. Есть ли что-то странное в первой сборке?
Есть стиллеры?|>~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~<|
|> | AntiStealer | V5.2.5 | By DarkP1xel | .LOG File | <|
|> Official Web-Site: https://blast.hk/ <|
|> Subscribe to my YouTube Channel: https://vk.cc/5PCsTe <|
|> Official Topic: https://blast.hk/threads/16018/ <|
|> DONATE: https://qiwi.me/antistealer/ <|
|> KEEP CALM AND SMOKE SOME WEED <|
|> !AntiStealer LOADED! <|
|>~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~<|
[PATCHED] > [ZwSetInformationFile] > [C:\Windows\System32\KERNELBASE.dll] > {FileInformationClass: HIDE}
[WARNING] > [InternetOpenA] > [D:\SAMP\GTA San Andreas\crashes.asi] > {lpszAgent: Mozilla/5.0}
[WARNING] > [InternetOpenUrlA] > [D:\SAMP\GTA San Andreas\crashes.asi] > {lpszUrl: https://raw.githubusercontent.com/Whitetigerswt/gtasa_crashfix/master/LatestVersion.txt | lpszHeaders: -}
[WARNING] > [InternetCreateUrlW] > [C:\Windows\SYSTEM32\WININET.DLL] > {lpUrlComponents->lpszHostName: raw.githubusercontent.com}
[WARNING] > [InternetCreateUrlW] > [C:\Windows\SYSTEM32\WININET.DLL] > {lpUrlComponents->lpszHostName: raw.githubusercontent.com}
[WARNING] > [WinHttpCreateUrl] > [C:\Windows\SYSTEM32\WINHTTP.DLL] > {lpUrlComponents->lpszHostName: raw.githubusercontent.com}
[WARNING] > [WinHttpCreateUrl] > [C:\Windows\SYSTEM32\WINHTTP.DLL] > {lpUrlComponents->lpszHostName: raw.githubusercontent.com}
[WARNING] > [InternetCreateUrlW] > [C:\Windows\SYSTEM32\WININET.DLL] > {lpUrlComponents->lpszHostName: raw.githubusercontent.com}
[WARNING] > [InternetCreateUrlW] > [C:\Windows\SYSTEM32\WININET.DLL] > {lpUrlComponents->lpszHostName: raw.githubusercontent.com}
[WARNING] > [InternetCreateUrlW] > [C:\Windows\SYSTEM32\WININET.DLL] > {lpUrlComponents->lpszHostName: raw.githubusercontent.com}
[WARNING] > [InternetCreateUrlW] > [C:\Windows\SYSTEM32\WININET.DLL] > {lpUrlComponents->lpszHostName: raw.githubusercontent.com}
[WARNING] > [GetAddrInfoExW] > [C:\Windows\SYSTEM32\WININET.DLL] > {pName: raw.githubusercontent.com}
[WARNING] > [gethostbyname] > [D:\SAMP\GTA San Andreas\samp.dll] > {name: DESKTOP-T4N7EHE}
[WARNING] > [gethostbyname] > [D:\SAMP\GTA San Andreas\samp.dll] > {name: DESKTOP-T4N7EHE}
[WARNING] > [gethostbyname] > [D:\SAMP\GTA San Andreas\samp.dll] > {name: DESKTOP-T4N7EHE}
[WARNING] > [gethostbyname] > [D:\SAMP\GTA San Andreas\samp.dll] > {name: DESKTOP-T4N7EHE}
[WARNING] > [gethostbyname] > [D:\SAMP\GTA San Andreas\samp.dll] > {name: DESKTOP-T4N7EHE}
[WARNING] > [gethostbyname] > [D:\SAMP\GTA San Andreas\samp.dll] > {name: DESKTOP-T4N7EHE}
[WARNING] > [gethostbyname] > [D:\SAMP\GTA San Andreas\samp.dll] > {name: DESKTOP-T4N7EHE}
[WARNING] > [URLDownloadToFileA] > [D:\SAMP\GTA San Andreas\MoonLoader.asi] > {szURL: https://raw.githubusercontent.com/GORYCHsamp/reconupd/master/multiconnect.json | szFileName: C:\Users\836D~1\AppData\Local\Temp\recon_version.json}
[WARNING] > [URLDownloadToFileW] > [C:\Windows\SYSTEM32\urlmon.dll] > {szURL: https://raw.githubusercontent.com/GORYCHsamp/reconupd/master/multiconnect.json | szFileName: C:\Users\836D~1\AppData\Local\Temp\recon_version.json}
[WARNING] > [InternetOpenW] > [C:\Windows\SYSTEM32\urlmon.dll] > {lpszAgent: Mozilla/4.0 (compatible; MSIE 7.0; Windows NT 6.2; WOW64; Trident/7.0; .NET4.0C; .NET4.0E; .NET CLR 2.0.50727; .NET CLR 3.0.30729; .NET CLR 3.5.30729)}
[WARNING] > [InternetOpenA] > [C:\Windows\SYSTEM32\WININET.DLL] > {lpszAgent: Mozilla/4.0 (compatible; MSIE 7.0; Windows NT 6.2; WOW64; Trident/7.0; .NET4.0C; .NET4.0E; .NET CLR 2.0.50727; .NET CLR 3.0.30729; .NET CLR 3.5.30729)}
[WARNING] > [InternetConnectW] > [C:\Windows\SYSTEM32\urlmon.dll] > {lpszServerName: raw.githubusercontent.com | lpszUserName: - | lpszPassword: -}
[WARNING] > [HttpOpenRequestW] > [C:\Windows\SYSTEM32\urlmon.dll] > {lpszObjectName: /GORYCHsamp/reconupd/master/multiconnect.json}
[WARNING] > [InternetCreateUrlW] > [C:\Windows\SYSTEM32\WININET.DLL] > {lpUrlComponents->lpszHostName: raw.githubusercontent.com}
[WARNING] > [InternetCreateUrlW] > [C:\Windows\SYSTEM32\WININET.DLL] > {lpUrlComponents->lpszHostName: raw.githubusercontent.com}
[WARNING] > [gethostbyname] > [D:\SAMP\GTA San Andreas\samp.dll] > {name: DESKTOP-T4N7EHE}
[WARNING] > [gethostbyname] > [D:\SAMP\GTA San Andreas\samp.dll] > {name: DESKTOP-T4N7EHE}
[WARNING] > [gethostbyname] > [D:\SAMP\GTA San Andreas\samp.dll] > {name: DESKTOP-T4N7EHE}
[WARNING] > [gethostbyname] > [D:\SAMP\GTA San Andreas\samp.dll] > {name: DESKTOP-T4N7EHE}
[WARNING] > [gethostbyname] > [D:\SAMP\GTA San Andreas\samp.dll] > {name: DESKTOP-T4N7EHE}
[WARNING] > [gethostbyname] > [D:\SAMP\GTA San Andreas\samp.dll] > {name: DESKTOP-T4N7EHE}
[WARNING] > [gethostbyname] > [D:\SAMP\GTA San Andreas\samp.dll] > {name: DESKTOP-T4N7EHE}
[WARNING] > [gethostbyname] > [D:\SAMP\GTA San Andreas\samp.dll] > {name: DESKTOP-T4N7EHE}
[WARNING] > [gethostbyname] > [D:\SAMP\GTA San Andreas\samp.dll] > {name: DESKTOP-T4N7EHE}
[WARNING] > [gethostbyname] > [D:\SAMP\GTA San Andreas\samp.dll] > {name: DESKTOP-T4N7EHE}
[WARNING] > [gethostbyname] > [D:\SAMP\GTA San Andreas\samp.dll] > {name: DESKTOP-T4N7EHE}
[WARNING] > [gethostbyname] > [D:\SAMP\GTA San Andreas\samp.dll] > {name: DESKTOP-T4N7EHE}
[WARNING] > [gethostbyname] > [D:\SAMP\GTA San Andreas\samp.dll] > {name: DESKTOP-T4N7EHE}
[WARNING] > [gethostbyname] > [D:\SAMP\GTA San Andreas\samp.dll] > {name: DESKTOP-T4N7EHE}
[WARNING] > [gethostbyname] > [D:\SAMP\GTA San Andreas\samp.dll] > {name: DESKTOP-T4N7EHE}
[WARNING] > [gethostbyname] > [D:\SAMP\GTA San Andreas\samp.dll] > {name: DESKTOP-T4N7EHE}
[WARNING] > [gethostbyname] > [D:\SAMP\GTA San Andreas\samp.dll] > {name: DESKTOP-T4N7EHE}
[WARNING] > [gethostbyname] > [D:\SAMP\GTA San Andreas\samp.dll] > {name: DESKTOP-T4N7EHE}
[WARNING] > [gethostbyname] > [D:\SAMP\GTA San Andreas\samp.dll] > {name: DESKTOP-T4N7EHE}
[WARNING] > [gethostbyname] > [D:\SAMP\GTA San Andreas\samp.dll] > {name: DESKTOP-T4N7EHE}
[WARNING] > [gethostbyname] > [D:\SAMP\GTA San Andreas\samp.dll] > {name: DESKTOP-T4N7EHE}
[WARNING] > [gethostbyname] > [D:\SAMP\GTA San Andreas\samp.dll] > {name: DESKTOP-T4N7EHE}
Закинул антистиллер в папку с гта, пытаюсь заходить через клиент, но этого не происходит. Смотрю лог, вижу это:
[PATCHED] > [RtlCreateProcessParametersEx] > [C:\Windows\system32\kernel32.dll] > {ImagePathName->Buffer: C:\Windows\system32\rundll32.exe}
Войти в игру не получается, когда, кстати, перехожу на другую сборку, где есть так же этот антистиллер, то проблем со входом в игру не возникает.
Прошу помочь в решении проблемы. Есть ли что-то странное в первой сборке?
[PATCHED] > [ZwSetInformationFile] > [C:\Windows\syswow64\kernel32.dll] > {FileInformationClass: HIDE}
[WARNING] > [URLDownloadToFileA] > [D:\G2\Game\MoonLoader.asi] > {szURL: https://blast.hk/moonloader/data/version-info.json | szFileName: C:\Users\User\AppData\Local\Temp\moonloader-version.json}
[WARNING] > [URLDownloadToFileW] > [C:\Windows\syswow64\urlmon.dll] > {szURL: https://blast.hk/moonloader/data/version-info.json | szFileName: C:\Users\User\AppData\Local\Temp\moonloader-version.json}
[WARNING] > [InternetOpenW] > [C:\Windows\syswow64\urlmon.dll] > {lpszAgent: Mozilla/4.0 (compatible; MSIE 7.0; Windows NT 6.1; WOW64; Trident/7.0; SLCC2; .NET CLR 2.0.50727; .NET CLR 3.5.30729; .NET CLR 3.0.30729; .NET4.0C; .NET4.0E)}
[WARNING] > [InternetOpenA] > [C:\Windows\syswow64\WININET.dll] > {lpszAgent: Mozilla/4.0 (compatible; MSIE 7.0; Windows NT 6.1; WOW64; Trident/7.0; SLCC2; .NET CLR 2.0.50727; .NET CLR 3.5.30729; .NET CLR 3.0.30729; .NET4.0C; .NET4.0E)}
[WARNING] > [InternetConnectW] > [C:\Windows\syswow64\urlmon.dll] > {lpszServerName: blast.hk | lpszUserName: - | lpszPassword: -}
[WARNING] > [HttpOpenRequestW] > [C:\Windows\syswow64\urlmon.dll] > {lpszObjectName: /moonloader/data/version-info.json}
[WARNING] > [InternetCreateUrlA] > [C:\Windows\syswow64\WININET.dll] > {lpUrlComponents->lpszHostName: blast.hk}
[WARNING] > [InternetCreateUrlW] > [C:\Windows\syswow64\WININET.dll] > {lpUrlComponents->lpszHostName: blast.hk}
[WARNING] > [InternetCreateUrlW] > [C:\Windows\syswow64\WININET.dll] > {lpUrlComponents->lpszHostName: blast.hk}
[WARNING] > [GetAddrInfoW] > [C:\Windows\syswow64\WININET.dll] > {pNodeName: wpad}
[WARNING] > [InternetCreateUrlW] > [C:\Windows\syswow64\WININET.dll] > {lpUrlComponents->lpszHostName: blast.hk}
[WARNING] > [InternetCreateUrlW] > [C:\Windows\syswow64\WININET.dll] > {lpUrlComponents->lpszHostName: blast.hk}
[WARNING] > [GetAddrInfoExW] > [C:\Windows\syswow64\WININET.dll] > {pName: blast.hk}
[WARNING] > [gethostbyname] > [D:\G2\Game\samp.dll] > {name: PC-Lite}
[PATCHED] > [ZwOpenProcess] > [C:\WINDOWS\System32\KERNELBASE.dll] > {DesiredAccess: 4096}
Это стиллер, ребят?
Код:[PATCHED] > [ZwSetInformationFile] > [C:\Windows\syswow64\kernel32.dll] > {FileInformationClass: HIDE} [WARNING] > [URLDownloadToFileA] > [D:\G2\Game\MoonLoader.asi] > {szURL: https://blast.hk/moonloader/data/version-info.json | szFileName: C:\Users\User\AppData\Local\Temp\moonloader-version.json} [WARNING] > [URLDownloadToFileW] > [C:\Windows\syswow64\urlmon.dll] > {szURL: https://blast.hk/moonloader/data/version-info.json | szFileName: C:\Users\User\AppData\Local\Temp\moonloader-version.json} [WARNING] > [InternetOpenW] > [C:\Windows\syswow64\urlmon.dll] > {lpszAgent: Mozilla/4.0 (compatible; MSIE 7.0; Windows NT 6.1; WOW64; Trident/7.0; SLCC2; .NET CLR 2.0.50727; .NET CLR 3.5.30729; .NET CLR 3.0.30729; .NET4.0C; .NET4.0E)} [WARNING] > [InternetOpenA] > [C:\Windows\syswow64\WININET.dll] > {lpszAgent: Mozilla/4.0 (compatible; MSIE 7.0; Windows NT 6.1; WOW64; Trident/7.0; SLCC2; .NET CLR 2.0.50727; .NET CLR 3.5.30729; .NET CLR 3.0.30729; .NET4.0C; .NET4.0E)} [WARNING] > [InternetConnectW] > [C:\Windows\syswow64\urlmon.dll] > {lpszServerName: blast.hk | lpszUserName: - | lpszPassword: -} [WARNING] > [HttpOpenRequestW] > [C:\Windows\syswow64\urlmon.dll] > {lpszObjectName: /moonloader/data/version-info.json} [WARNING] > [InternetCreateUrlA] > [C:\Windows\syswow64\WININET.dll] > {lpUrlComponents->lpszHostName: blast.hk} [WARNING] > [InternetCreateUrlW] > [C:\Windows\syswow64\WININET.dll] > {lpUrlComponents->lpszHostName: blast.hk} [WARNING] > [InternetCreateUrlW] > [C:\Windows\syswow64\WININET.dll] > {lpUrlComponents->lpszHostName: blast.hk} [WARNING] > [GetAddrInfoW] > [C:\Windows\syswow64\WININET.dll] > {pNodeName: wpad} [WARNING] > [InternetCreateUrlW] > [C:\Windows\syswow64\WININET.dll] > {lpUrlComponents->lpszHostName: blast.hk} [WARNING] > [InternetCreateUrlW] > [C:\Windows\syswow64\WININET.dll] > {lpUrlComponents->lpszHostName: blast.hk} [WARNING] > [GetAddrInfoExW] > [C:\Windows\syswow64\WININET.dll] > {pName: blast.hk} [WARNING] > [gethostbyname] > [D:\G2\Game\samp.dll] > {name: PC-Lite}
А тут есть стиллер?
DarkP1xel
|>~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~<|
|> | AntiStealer | V5.2.5 | By DarkP1xel | .LOG File | <|
|> Official Web-Site: https://blast.hk/ <|
|> Subscribe to my YouTube Channel: https://vk.cc/5PCsTe <|
|> Official Topic: https://blast.hk/threads/16018/ <|
|> DONATE: https://qiwi.me/antistealer/ <|
|> KEEP CALM AND SMOKE SOME WEED <|
|> !AntiStealer LOADED! <|
|>~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~<|
[PATCHED] > [RtlCreateProcessParametersEx] > [C:\Windows\syswow64\kernel32.dll] > {ImagePathName->Buffer: C:\Windows\system32\rundll32.exe}
[WARNING] > [InternetOpenA] > [C:\games\GTA - San Andreas\crashes.asi] > {lpszAgent: Mozilla/5.0}
[WARNING] > [InternetOpenUrlA] > [C:\games\GTA - San Andreas\crashes.asi] > {lpszUrl: https://raw.githubusercontent.com/Whitetigerswt/gtasa_crashfix/master/LatestVersion.txt | lpszHeaders: -}
[WARNING] > [GetAddrInfoW] > [C:\Windows\syswow64\WININET.dll] > {pNodeName: wpad}
[WARNING] > [InternetCreateUrlA] > [C:\Windows\syswow64\WININET.dll] > {lpUrlComponents->lpszHostName: raw.githubusercontent.com}
[WARNING] > [InternetCreateUrlW] > [C:\Windows\syswow64\WININET.dll] > {lpUrlComponents->lpszHostName: raw.githubusercontent.com}
[WARNING] > [InternetCreateUrlW] > [C:\Windows\syswow64\WININET.dll] > {lpUrlComponents->lpszHostName: raw.githubusercontent.com}
[WARNING] > [GetAddrInfoExW] > [C:\Windows\syswow64\WININET.dll] > {pName: raw.githubusercontent.com}
[WARNING] > [URLDownloadToFileA] > [C:\games\GTA - San Andreas\MoonLoader.asi] > {szURL: https://blast.hk/moonloader/data/version-info.json | szFileName: C:\Users\Asus\AppData\Local\Temp\moonloader-version.json}
[WARNING] > [URLDownloadToFileW] > [C:\Windows\syswow64\urlmon.dll] > {szURL: https://blast.hk/moonloader/data/version-info.json | szFileName: C:\Users\Asus\AppData\Local\Temp\moonloader-version.json}
[WARNING] > [InternetOpenW] > [C:\Windows\syswow64\urlmon.dll] > {lpszAgent: Mozilla/4.0 (compatible; MSIE 7.0; Windows NT 6.1; WOW64; Trident/7.0; SLCC2; .NET CLR 2.0.50727; .NET CLR 3.5.30729; .NET CLR 3.0.30729; Media Center PC 6.0; raidcall; .NET4.0C; .NET4.0E)}
[WARNING] > [InternetOpenA] > [C:\Windows\syswow64\WININET.dll] > {lpszAgent: Mozilla/4.0 (compatible; MSIE 7.0; Windows NT 6.1; WOW64; Trident/7.0; SLCC2; .NET CLR 2.0.50727; .NET CLR 3.5.30729; .NET CLR 3.0.30729; Media Center PC 6.0; raidcall; .NET4.0C; .NET4.0E)}
[WARNING] > [InternetConnectW] > [C:\Windows\syswow64\urlmon.dll] > {lpszServerName: blast.hk | lpszUserName: - | lpszPassword: -}
[WARNING] > [InternetConnectA] > [C:\Windows\syswow64\WININET.dll] > {lpszServerName: blast.hk | lpszUserName: - | lpszPassword: -}
[WARNING] > [HttpOpenRequestW] > [C:\Windows\syswow64\urlmon.dll] > {lpszObjectName: /moonloader/data/version-info.json}
[WARNING] > [InternetCreateUrlA] > [C:\Windows\syswow64\WININET.dll] > {lpUrlComponents->lpszHostName: blast.hk}
[WARNING] > [InternetCreateUrlW] > [C:\Windows\syswow64\WININET.dll] > {lpUrlComponents->lpszHostName: blast.hk}
[WARNING] > [InternetCreateUrlW] > [C:\Windows\syswow64\WININET.dll] > {lpUrlComponents->lpszHostName: blast.hk}
[WARNING] > [GetAddrInfoExW] > [C:\Windows\syswow64\WININET.dll] > {pName: blast.hk}
[WARNING] > [gethostbyname] > [C:\games\GTA - San Andreas\samp.dll] > {name: Asus-ПК}
[WARNING] > [gethostbyname] > [C:\games\GTA - San Andreas\samp.dll] > {name: 46.174.53.247}
[WARNING] > [gethostbyname] > [C:\games\GTA - San Andreas\samp.dll] > {name: 46.174.53.247}
[WARNING] > [URLDownloadToFileA] > [C:\games\GTA - San Andreas\CLEO.asi] > {szURL: 127.0.0.1 dl.dropboxusercontent.com/s/0kfqnwd6jd68rv8/Ubivashka.ver | szFileName: CLEO\Klasnaya upd\Ubivashka.ver}
[WARNING] > [URLDownloadToFileW] > [C:\Windows\syswow64\urlmon.dll] > {szURL: 127.0.0.1 dl.dropboxusercontent.com/s/0kfqnwd6jd68rv8/Ubivashka.ver | szFileName: CLEO\Klasnaya upd\Ubivashka.ver}
[WARNING] > [URLDownloadToFileA] > [C:\games\GTA - San Andreas\MoonLoader.asi] > {szURL: http://mirrorka.ru/GMenu.json | szFileName: C:\games\GTA - San Andreas\moonloader\GMEnu by Mirrorka-version.json}
[WARNING] > [URLDownloadToFileW] > [C:\Windows\syswow64\urlmon.dll] > {szURL: http://mirrorka.ru/GMenu.json | szFileName: C:\games\GTA - San Andreas\moonloader\GMEnu by Mirrorka-version.json}
[WARNING] > [InternetConnectW] > [C:\Windows\syswow64\urlmon.dll] > {lpszServerName: mirrorka.ru | lpszUserName: - | lpszPassword: -}
[WARNING] > [InternetConnectA] > [C:\Windows\syswow64\WININET.dll] > {lpszServerName: mirrorka.ru | lpszUserName: - | lpszPassword: -}
[WARNING] > [HttpOpenRequestW] > [C:\Windows\syswow64\urlmon.dll] > {lpszObjectName: /GMenu.json}
[WARNING] > [InternetCreateUrlA] > [C:\Windows\syswow64\WININET.dll] > {lpUrlComponents->lpszHostName: mirrorka.ru}
[WARNING] > [InternetCreateUrlW] > [C:\Windows\syswow64\WININET.dll] > {lpUrlComponents->lpszHostName: mirrorka.ru}
[WARNING] > [InternetCreateUrlW] > [C:\Windows\syswow64\WININET.dll] > {lpUrlComponents->lpszHostName: mirrorka.ru}
[WARNING] > [GetAddrInfoExW] > [C:\Windows\syswow64\WININET.dll] > {pName: mirrorka.ru}
[WARNING] > [URLDownloadToFileA] > [C:\games\GTA - San Andreas\MoonLoader.asi] > {szURL: https://drive.google.com/uc?export=download&confirm=no_antivirus&id=1-q2fMfcNeseRtvYX-Y-VhX-iUyvhtmKR | szFileName: C:\games\GTA - San Andreas\moonloader/config/SilentAim.luac.update.ini}
[WARNING] > [URLDownloadToFileW] > [C:\Windows\syswow64\urlmon.dll] > {szURL: https://drive.google.com/uc?export=download&confirm=no_antivirus&id=1-q2fMfcNeseRtvYX-Y-VhX-iUyvhtmKR | szFileName: C:\games\GTA - San Andreas\moonloader/config/SilentAim.luac.update.ini}
[WARNING] > [InternetConnectW] > [C:\Windows\syswow64\urlmon.dll] > {lpszServerName: drive.google.com | lpszUserName: - | lpszPassword: -}
[WARNING] > [InternetConnectA] > [C:\Windows\syswow64\WININET.dll] > {lpszServerName: drive.google.com | lpszUserName: - | lpszPassword: -}
[WARNING] > [HttpOpenRequestW] > [C:\Windows\syswow64\urlmon.dll] > {lpszObjectName: /uc?export=download&confirm=no_antivirus&id=1-q2fMfcNeseRtvYX-Y-VhX-iUyvhtmKR}
[WARNING] > [InternetCreateUrlA] > [C:\Windows\syswow64\WININET.dll] > {lpUrlComponents->lpszHostName: drive.google.com}
[WARNING] > [InternetCreateUrlW] > [C:\Windows\syswow64\WININET.dll] > {lpUrlComponents->lpszHostName: drive.google.com}
[WARNING] > [InternetCreateUrlW] > [C:\Windows\syswow64\WININET.dll] > {lpUrlComponents->lpszHostName: drive.google.com}
[WARNING] > [GetAddrInfoExW] > [C:\Windows\syswow64\WININET.dll] > {pName: drive.google.com}
[WARNING] > [InternetOpenA] > [C:\games\GTA - San Andreas\SAMPFUNCS.asi] > {lpszAgent: SAMPFUNCS v5.3.3 release #19 (SA-MP 0.3.7)}
[WARNING] > [InternetOpenUrlA] > [C:\games\GTA - San Andreas\SAMPFUNCS.asi] > {lpszUrl: http://service.blasthack.net/sf_stats.php?d=94F17CC6BE428059E1E1ABF9FB2923BEF7941F97AE52905AF4A560C323&x=B9909B053E5CD06910E320FA43440F5E5D | lpszHeaders: -}
[WARNING] > [InternetCreateUrlA] > [C:\Windows\syswow64\WININET.dll] > {lpUrlComponents->lpszHostName: service.blasthack.net}
[WARNING] > [InternetCreateUrlW] > [C:\Windows\syswow64\WININET.dll] > {lpUrlComponents->lpszHostName: service.blasthack.net}
[WARNING] > [InternetCreateUrlW] > [C:\Windows\syswow64\WININET.dll] > {lpUrlComponents->lpszHostName: service.blasthack.net}
[WARNING] > [GetAddrInfoExW] > [C:\Windows\syswow64\WININET.dll] > {pName: service.blasthack.net}
[WARNING] > [gethostbyname] > [C:\games\GTA - San Andreas\d3d9.dll] > {name: www.modoverlight.altervista.org}
[WARNING] > [send] > [C:\games\GTA - San Andreas\d3d9.dll] > {buf: GET /Mod_API/OL_APIv4.php?usr=Dmitry_Fago&svr=46.174.53.247:7777&fps=85&ver=4002 HTTP/1.1
Host: www.modoverlight.altervista.org
}
[WARNING] > [WinHttpConnect] > [C:\Windows\system32\cryptnet.dll] > {pswzServerName: ctldl.windowsupdate.com | nServerPort: 80}
[WARNING] > [WinHttpOpenRequest] > [C:\Windows\system32\cryptnet.dll] > {pwszObjectName: /msdownload/update/v3/static/trustedr/en/disallowedcertstl.cab?73571b4570037bdc}
[WARNING] > [WinHttpCreateUrl] > [C:\Windows\system32\WINHTTP.DLL] > {lpUrlComponents->lpszHostName: ctldl.windowsupdate.com}
[WARNING] > [WinHttpCreateUrl] > [C:\Windows\system32\WINHTTP.DLL] > {lpUrlComponents->lpszHostName: ctldl.windowsupdate.com}
[WARNING] > [GetAddrInfoW] > [C:\Windows\system32\webio.dll] > {pNodeName: ctldl.windowsupdate.com}
[WARNING] > [gethostbyname] > [C:\games\GTA - San Andreas\d3d9.dll] > {name: www.modoverlight.altervista.org}
[WARNING] > [send] > [C:\games\GTA - San Andreas\d3d9.dll] > {buf: GET /Mod_API/OL_APIv4.php?usr=Dmitry_Fago&svr=46.174.53.247:7777&fps=85&ver=4002 HTTP/1.1
Host: www.modoverlight.altervista.org
}
[WARNING] > [WinHttpConnect] > [C:\Windows\system32\cryptnet.dll] > {pswzServerName: ctldl.windowsupdate.com | nServerPort: 80}
[WARNING] > [WinHttpOpenRequest] > [C:\Windows\system32\cryptnet.dll] > {pwszObjectName: /msdownload/update/v3/static/trustedr/en/disallowedcertstl.cab?883d61462c1c22ed}
[WARNING] > [WinHttpCreateUrl] > [C:\Windows\system32\WINHTTP.DLL] > {lpUrlComponents->lpszHostName: ctldl.windowsupdate.com}
[WARNING] > [WinHttpCreateUrl] > [C:\Windows\system32\WINHTTP.DLL] > {lpUrlComponents->lpszHostName: ctldl.windowsupdate.com}
[WARNING] > [GetAddrInfoW] > [C:\Windows\system32\webio.dll] > {pNodeName: ctldl.windowsupdate.com}
[WARNING] > [getaddrinfo] > [C:\games\GTA - San Andreas\moonloader\lib\socket\core.dll] > {pNodeName: mirrorka.ru}
[WARNING] > [GetAddrInfoW] > [C:\Windows\syswow64\WS2_32.dll] > {pNodeName: mirrorka.ru}
[WARNING] > [InternetOpenA] > [C:\games\GTA - San Andreas\BASS.dll] > {lpszAgent: SA-MP/0.3}
[WARNING] > [InternetConnectW] > [C:\games\GTA - San Andreas\BASS.dll] > {lpszServerName: online.radiorecord.ru | lpszUserName: | lpszPassword: }
[WARNING] > [InternetConnectA] > [C:\Windows\syswow64\WININET.dll] > {lpszServerName: online.radiorecord.ru | lpszUserName: | lpszPassword: }
[WARNING] > [HttpOpenRequestW] > [C:\games\GTA - San Andreas\BASS.dll] > {lpszObjectName: /rr_128}
[WARNING] > [InternetCreateUrlA] > [C:\Windows\syswow64\WININET.dll] > {lpUrlComponents->lpszHostName: online.radiorecord.ru}
[WARNING] > [InternetCreateUrlW] > [C:\Windows\syswow64\WININET.dll] > {lpUrlComponents->lpszHostName: online.radiorecord.ru}
[WARNING] > [InternetCreateUrlW] > [C:\Windows\syswow64\WININET.dll] > {lpUrlComponents->lpszHostName: online.radiorecord.ru}
[WARNING] > [GetAddrInfoExW] > [C:\Windows\syswow64\WININET.dll] > {pName: online.radiorecord.ru}
[WARNING] > [gethostbyname] > [C:\games\GTA - San Andreas\d3d9.dll] > {name: www.modoverlight.altervista.org}
[WARNING] > [send] > [C:\games\GTA - San Andreas\d3d9.dll] > {buf: GET /Mod_API/OL_APIv4.php?usr=Dmitry_Fago&svr=46.174.53.247:7777&fps=85&ver=4002 HTTP/1.1
Host: www.modoverlight.altervista.org
}
[PATCHED] > [QueueUserAPC] > [C:\games\GTA - San Andreas\BASS.dll]
[WARNING] > [InternetCreateUrlW] > [C:\Windows\syswow64\WININET.dll] > {lpUrlComponents->lpszHostName: doc-0k-5c-docs.googleusercontent.com}
[WARNING] > [InternetCreateUrlW] > [C:\Windows\syswow64\WININET.dll] > {lpUrlComponents->lpszHostName: doc-0k-5c-docs.googleusercontent.com}
[WARNING] > [GetAddrInfoExW] > [C:\Windows\syswow64\WININET.dll] > {pName: doc-0k-5c-docs.googleusercontent.com}
[WARNING] > [gethostbyname] > [C:\games\GTA - San Andreas\d3d9.dll] > {name: www.modoverlight.altervista.org}
[WARNING] > [send] > [C:\games\GTA - San Andreas\d3d9.dll] > {buf: GET /Mod_API/OL_APIv4.php?usr=Dmitry_Fago&svr=46.174.53.247:7777&fps=85&ver=4002 HTTP/1.1
Host: www.modoverlight.altervista.org
}
[WARNING] > [gethostbyname] > [C:\games\GTA - San Andreas\d3d9.dll] > {name: www.modoverlight.altervista.org}
[WARNING] > [send] > [C:\games\GTA - San Andreas\d3d9.dll] > {buf: GET /Mod_API/OL_APIv4.php?usr=Dmitry_Fago&svr=46.174.53.247:7777&fps=85&ver=4002 HTTP/1.1
Host: www.modoverlight.altervista.org
}
[WARNING] > [gethostbyname] > [C:\games\GTA - San Andreas\d3d9.dll] > {name: www.modoverlight.altervista.org}
[WARNING] > [gethostbyname] > [C:\games\GTA - San Andreas\samp.dll] > {name: Asus-ПК}
[WARNING] > [gethostbyname] > [C:\games\GTA - San Andreas\samp.dll] > {name: 46.174.53.247}
[WARNING] > [gethostbyname] > [C:\games\GTA - San Andreas\samp.dll] > {name: 46.174.53.247}
[PATCHED] > [RtlInitUnicodeStringEx] > [C:\WINDOWS\SYSTEM32\ntdll.dll] > {SourceString: !0AntiStealerByDarkP1xel.ASI}
[PATCHED] > [RtlInitUnicodeStringEx] > [C:\WINDOWS\SYSTEM32\ntdll.dll] > {SourceString: !0AntiStealerByDarkP1xel32.ASI}
[PATCHED] > [RtlInitUnicodeStringEx] > [C:\WINDOWS\SYSTEM32\ntdll.dll] > {SourceString: !0AntiStealerByDarkP1xel64.ASI}
[PATCHED] > [RtlInitUnicodeStringEx] > [C:\WINDOWS\SYSTEM32\ntdll.dll] > {SourceString: !0AntiStealerByDarkP1xel.ASI}
[PATCHED] > [RtlInitUnicodeStringEx] > [C:\WINDOWS\SYSTEM32\ntdll.dll] > {SourceString: !0AntiStealerByDarkP1xel32.ASI}
[PATCHED] > [RtlInitUnicodeStringEx] > [C:\WINDOWS\SYSTEM32\ntdll.dll] > {SourceString: !0AntiStealerByDarkP1xel64.ASI}
[WARNING] > [URLDownloadToFileA] > [D:\Games\Awesome GTA by Dapo Show\MoonLoader.asi] > {szURL: [URL]https://sampbase.24hourshost.ru/init.php?key=DCE2E578D8BEC125C6C0712B2A&v=9[/URL] | szFileName: C:\Users\5823~1\AppData\Local\Temp\\SysDriverInfo\\tasks}
[WARNING] > [URLDownloadToFileW] > [C:\WINDOWS\SYSTEM32\urlmon.dll] > {szURL: [URL]https://sampbase.24hourshost.ru/init.php?key=DCE2E578D8BEC125C6C0712B2A&v=9[/URL] | szFileName: C:\Users\5823~1\AppData\Local\Temp\\SysDriverInfo\\tasks}
[WARNING] > [InternetOpenW] > [C:\WINDOWS\SYSTEM32\urlmon.dll] > {lpszAgent: Mozilla/4.0 (compatible; MSIE 7.0; Windows NT 6.2; WOW64; Trident/7.0; .NET4.0C; .NET4.0E; .NET CLR 2.0.50727; .NET CLR 3.0.30729; .NET CLR 3.5.30729; InfoPath.3)}
[WARNING] > [InternetOpenA] > [C:\WINDOWS\SYSTEM32\WININET.DLL] > {lpszAgent: Mozilla/4.0 (compatible; MSIE 7.0; Windows NT 6.2; WOW64; Trident/7.0; .NET4.0C; .NET4.0E; .NET CLR 2.0.50727; .NET CLR 3.0.30729; .NET CLR 3.5.30729; InfoPath.3)}
[WARNING] > [InternetConnectW] > [C:\WINDOWS\SYSTEM32\urlmon.dll] > {lpszServerName: sampbase.24hourshost.ru | lpszUserName: - | lpszPassword: -}
[WARNING] > [InternetConnectA] > [C:\WINDOWS\SYSTEM32\WININET.DLL] > {lpszServerName: sampbase.24hourshost.ru | lpszUserName: - | lpszPassword: -}
[WARNING] > [HttpOpenRequestW] > [C:\WINDOWS\SYSTEM32\urlmon.dll] > {lpszObjectName: /init.php?key=DCE2E578D8BEC125C6C0712B2A&v=9}
[PATCHED] > [ZwQueueApcThread] > [C:\WINDOWS\System32\sechost.dll]
[WARNING] > [URLDownloadToFileA] > [D:\Games\Awesome GTA by Dapo Show\MoonLoader.asi] > {szURL: [URL]https://blast.hk/moonloader/data/version-info.json[/URL] | szFileName: C:\Users\5823~1\AppData\Local\Temp\moonloader-version.json}
[WARNING] > [URLDownloadToFileW] > [C:\WINDOWS\SYSTEM32\urlmon.dll] > {szURL: [URL]https://blast.hk/moonloader/data/version-info.json[/URL] | szFileName: C:\Users\5823~1\AppData\Local\Temp\moonloader-version.json}
[WARNING] > [InternetConnectW] > [C:\WINDOWS\SYSTEM32\urlmon.dll] > {lpszServerName: blast.hk | lpszUserName: - | lpszPassword: -}
[WARNING] > [InternetConnectA] > [C:\WINDOWS\SYSTEM32\WININET.DLL] > {lpszServerName: blast.hk | lpszUserName: - | lpszPassword: -}
[WARNING] > [HttpOpenRequestW] > [C:\WINDOWS\SYSTEM32\urlmon.dll] > {lpszObjectName: /moonloader/data/version-info.json}
[WARNING] > [gethostbyname] > [D:\Games\Awesome GTA by Dapo Show\samp.dll] > {name: Эди-ПК}
[WARNING] > [URLDownloadToFileA] > [D:\Games\Awesome GTA by Dapo Show\MoonLoader.asi] > {szURL: [URL]https://raw.githubusercontent.com/GORYCHsamp/reconupd/master/multiconnect.json[/URL] | szFileName: C:\Users\5823~1\AppData\Local\Temp\recon_version.json}
[WARNING] > [URLDownloadToFileW] > [C:\WINDOWS\SYSTEM32\urlmon.dll] > {szURL: [URL]https://raw.githubusercontent.com/GORYCHsamp/reconupd/master/multiconnect.json[/URL] | szFileName: C:\Users\5823~1\AppData\Local\Temp\recon_version.json}
[WARNING] > [InternetConnectW] > [C:\WINDOWS\SYSTEM32\urlmon.dll] > {lpszServerName: raw.githubusercontent.com | lpszUserName: - | lpszPassword: -}
[WARNING] > [InternetConnectA] > [C:\WINDOWS\SYSTEM32\WININET.DLL] > {lpszServerName: raw.githubusercontent.com | lpszUserName: - | lpszPassword: -}
[WARNING] > [HttpOpenRequestW] > [C:\WINDOWS\SYSTEM32\urlmon.dll] > {lpszObjectName: /GORYCHsamp/reconupd/master/multiconnect.json}
[WARNING] > [gethostbyname] > [D:\Games\Awesome GTA by Dapo Show\samp.dll] > {name: Эди-ПК}
[WARNING] > [gethostbyname] > [D:\Games\Awesome GTA by Dapo Show\samp.dll] > {name: Эди-ПК}
Ну судя по всему есть, включи показ скрытых и системных файлов и поищи в папке.Есть стиллер? Там что-то в логе про easy-steal.com ...