Статус
В этой теме нельзя размещать новые ответы.

LOOOKING

Новичок
4
0
[PATCHED] > [ZwSetInformationFile] > [C:\WINDOWS\System32\KERNELBASE.dll] > {FileInformationClass: HIDE}
[WARNING] > [InternetOpenA] > [C:\Users\pronn\Desktop\[RP] GameWorld - GTA San Andreas\crashes.asi] > {lpszAgent: Mozilla/5.0}
[WARNING] > [InternetOpenUrlA] > [C:\Users\pronn\Desktop\[RP] GameWorld - GTA San Andreas\crashes.asi] > {lpszUrl: https://raw.githubusercontent.com/Whitetigerswt/gtasa_crashfix/master/LatestVersion.txt | lpszHeaders: -}
[PATCHED] > [ZwQueueApcThread] > [C:\WINDOWS\System32\sechost.dll]
[WARNING] > [gethostbyname] > [C:\Users\pronn\Desktop\[RP] GameWorld - GTA San Andreas\samp.dll] > {name: LookingFuture}
[WARNING] > [gethostbyname] > [C:\Users\pronn\Desktop\[RP] GameWorld - GTA San Andreas\samp.dll] > {name: 5.254.123.6}
[WARNING] > [gethostbyname] > [C:\Users\pronn\Desktop\[RP] GameWorld - GTA San Andreas\samp.dll] > {name: 5.254.123.6}
[PATCHED] > [ZwSetInformationFile] > [C:\WINDOWS\System32\KERNELBASE.dll] > {FileInformationClass: HIDE}
 
Последнее редактирование:

TheBadZero

Gachi Solider
Проверенный
356
164
!0AntiStealerByDarkP1xel32.LOG написал(а):
[PATCHED] > [ZwOpenProcess] > [C:\WINDOWS\System32\KERNELBASE.dll] > {DesiredAccess: 4096}
[PATCHED] > [ZwOpenProcess] > [C:\WINDOWS\System32\KERNELBASE.dll] > {DesiredAccess: 4096}
[PATCHED] > [ZwOpenProcess] > [C:\WINDOWS\System32\KERNELBASE.dll] > {DesiredAccess: 4096}
[PATCHED] > [ZwOpenProcess] > [C:\WINDOWS\System32\KERNELBASE.dll] > {DesiredAccess: 4096}
[PATCHED] > [ZwOpenProcess] > [C:\WINDOWS\System32\KERNELBASE.dll] > {DesiredAccess: 4096}
[PATCHED] > [ZwOpenProcess] > [C:\WINDOWS\System32\KERNELBASE.dll] > {DesiredAccess: 4096}
[PATCHED] > [ZwOpenProcess] > [C:\WINDOWS\System32\KERNELBASE.dll] > {DesiredAccess: 4096}
[PATCHED] > [ZwOpenProcess] > [C:\WINDOWS\System32\KERNELBASE.dll] > {DesiredAccess: 4096}
[PATCHED] > [ZwOpenProcess] > [C:\WINDOWS\System32\KERNELBASE.dll] > {DesiredAccess: 4096}
[PATCHED] > [ZwOpenProcess] > [C:\WINDOWS\System32\KERNELBASE.dll] > {DesiredAccess: 4096}
[PATCHED] > [ZwOpenProcess] > [C:\WINDOWS\System32\KERNELBASE.dll] > {DesiredAccess: 4096}
[PATCHED] > [ZwOpenProcess] > [C:\WINDOWS\System32\KERNELBASE.dll] > {DesiredAccess: 4096}
[PATCHED] > [ZwOpenProcess] > [C:\WINDOWS\System32\KERNELBASE.dll] > {DesiredAccess: 4096}
[PATCHED] > [ZwOpenProcess] > [C:\WINDOWS\System32\KERNELBASE.dll] > {DesiredAccess: 4096}
[PATCHED] > [ZwOpenProcess] > [C:\WINDOWS\System32\KERNELBASE.dll] > {DesiredAccess: 4096}
[PATCHED] > [ZwOpenProcess] > [C:\WINDOWS\System32\KERNELBASE.dll] > {DesiredAccess: 4096}
[WARNING] > [gethostbyname] > [C:\Games\GTA San Andreas - SA-MP\samp.dll] > {name: LAPTOP-1H3EMHL3}
[WARNING] > [getaddrinfo] > [C:\Games\GTA San Andreas - SA-MP\moonloader\lib\socket\core.dll] > {pNodeName: natribu.org}
[WARNING] > [GetAddrInfoW] > [C:\WINDOWS\System32\WS2_32.dll] > {pNodeName: natribu.org}
[WARNING] > [send] > [C:\Games\GTA San Andreas - SA-MP\moonloader\lib\socket\core.dll] > {buf: GET /creep/shkolniks/king/eto/cleimoo.php=3973969262 HTTP/1.1

}
[WARNING] > [send] > [C:\Games\GTA San Andreas - SA-MP\moonloader\lib\socket\core.dll] > {buf: User-Agent: LuaSocket 3.0-rc1

TE: trailers

Content-Length: 0

Connection: close, TE

Host: natribu.org



}
[WARNING] > [URLDownloadToFileA] > [C:\Games\GTA San Andreas - SA-MP\MoonLoader.asi] > {szURL: https://drive.google.com/uc?export=...ntivirus&id=1-q2fMfcNeseRtvYX-Y-VhX-iUyvhtmKR | szFileName: C:\Games\GTA San Andreas - SA-MP\moonloader/config/SilentAim.luac.update.ini}
[WARNING] > [URLDownloadToFileW] > [C:\WINDOWS\SYSTEM32\urlmon.dll] > {szURL: https://drive.google.com/uc?export=...ntivirus&id=1-q2fMfcNeseRtvYX-Y-VhX-iUyvhtmKR | szFileName: C:\Games\GTA San Andreas - SA-MP\moonloader/config/SilentAim.luac.update.ini}
[WARNING] > [InternetOpenW] > [C:\WINDOWS\SYSTEM32\urlmon.dll] > {lpszAgent: Mozilla/4.0 (compatible; MSIE 7.0; Windows NT 6.2; WOW64; Trident/7.0; .NET4.0C; .NET4.0E; .NET CLR 2.0.50727; .NET CLR 3.0.30729; .NET CLR 3.5.30729)}
[WARNING] > [InternetOpenA] > [C:\WINDOWS\SYSTEM32\WININET.DLL] > {lpszAgent: Mozilla/4.0 (compatible; MSIE 7.0; Windows NT 6.2; WOW64; Trident/7.0; .NET4.0C; .NET4.0E; .NET CLR 2.0.50727; .NET CLR 3.0.30729; .NET CLR 3.5.30729)}
[WARNING] > [InternetConnectW] > [C:\WINDOWS\SYSTEM32\urlmon.dll] > {lpszServerName: drive.google.com | lpszUserName: - | lpszPassword: -}
[WARNING] > [InternetOpenA] > [C:\Games\GTA San Andreas - SA-MP\SAMPFUNCS.asi] > {lpszAgent: SAMPFUNCS v5.3.3 release #19 (SA-MP 0.3.7)}
[WARNING] > [InternetOpenUrlA] > [C:\Games\GTA San Andreas - SA-MP\SAMPFUNCS.asi] > {lpszUrl: http://service.blasthack.net/sf_sta...A22731C3&x=B9909B053E5CD06910E320FA43440F5E5D | lpszHeaders: -}
[WARNING] > [HttpOpenRequestW] > [C:\WINDOWS\SYSTEM32\urlmon.dll] > {lpszObjectName: /uc?export=download&confirm=no_antivirus&id=1-q2fMfcNeseRtvYX-Y-VhX-iUyvhtmKR}
[PATCHED] > [ZwQueueApcThread] > [C:\WINDOWS\System32\sechost.dll]
почему меня посылают нахуй? из-за core.dll?
 

D1namick

Новичок
8
0
  1. upload_2019-5-18_18-30-51.png
    '
Это что почему ничего не пишет?
 

Вложения

  • upload_2019-5-18_18-30-26.png
    upload_2019-5-18_18-30-26.png
    68.1 KB · Просмотры: 168

D1namick

Новичок
8
0
Скорее всего у тебя всё нормально, и стиллеров нету.
Ты не прав это копия моей сборки я установил новый сампфункс и новый анти стилер от сюда. И у меня ничего не пишут туда а на той сборке пишет (старый антистилер и сампфунк) Но я такую махинацию делал и со старыми тоже не писало
 

D1namick

Новичок
8
0
[PATCHED] > [ZwSetInformationFile] > [C:\Windows\SYSTEM32\KERNELBASE.dll] > {FileInformationClass: HIDE} что это? где лять стилер?
 

Fix_ir

Активный
88
25
Вроде всё нормально, но на почту приходит сообщение, что пароль сменить пытаются. Может я что-то не так делаю?
LOG
[WARNING] > [gethostbyname] > [D:\Folder\Games\GTA\GTA San Andreas\samp.dll] > {name: XTREME-828OP2AF}
[WARNING] > [gethostbyname] > [D:\Folder\Games\GTA\GTA San Andreas\samp.dll] > {name: XTREME-828OP2AF}
[PATCHED] > [RtlInitUnicodeString] > [C:\Windows\syswow64\KERNELBASE.dll] > {SourceString: .\!0AntiStealerByDarkP1xel32.dbg\*}
[PATCHED] > [RtlInitUnicodeStringEx] > [C:\Windows\SysWOW64\ntdll.dll] > {SourceString: D:\Folder\Games\GTA\GTA San Andreas\!0AntiStealerByDarkP1xel32.dbg\*}
[PATCHED] > [RtlInitUnicodeStringEx] > [C:\Windows\SysWOW64\ntdll.dll] > {SourceString: .\!0AntiStealerByDarkP1xel32.dbg\*}
[PATCHED] > [RtlInitUnicodeString] > [C:\Windows\syswow64\KERNELBASE.dll] > {SourceString: .\!0AntiStealerByDarkP1xel32.pdb\*}
[PATCHED] > [RtlInitUnicodeStringEx] > [C:\Windows\SysWOW64\ntdll.dll] > {SourceString: D:\Folder\Games\GTA\GTA San Andreas\!0AntiStealerByDarkP1xel32.pdb\*}
[PATCHED] > [RtlInitUnicodeStringEx] > [C:\Windows\SysWOW64\ntdll.dll] > {SourceString: .\!0AntiStealerByDarkP1xel32.pdb\*}
Есть Стиллер

Ты не прав это копия моей сборки я установил новый сампфункс и новый анти стилер от сюда. И у меня ничего не пишут туда а на той сборке пишет (старый антистилер и сампфунк) Но я такую махинацию делал и со старыми тоже не писало
Дай стиллеру пароль. Тогда будет работа стиллера)))0)

Кстати, админы
Screenshot_2019-05-19-07-19-03-060_com.chrome.canary.jpg
 

Evil_Rabbit

Новичок
3
0
Скажите пожалуйста есть ли стиллер?



[PATCHED] > [ZwSetInformationFile] > [C:\Windows\SYSTEM32\KERNELBASE.dll] > {FileInformationClass: HIDE}
[PATCHED] > [ZwSetInformationFile] > [C:\Windows\SYSTEM32\KERNELBASE.dll] > {FileInformationClass: HIDE}
[WARNING] > [InternetOpenA] > [D:\!0\crashes.asi] > {lpszAgent: Mozilla/5.0}
[WARNING] > [InternetOpenUrlA] > [D:\!0\crashes.asi] > {lpszUrl: https://raw.githubusercontent.com/Whitetigerswt/gtasa_crashfix/master/LatestVersion.txt | lpszHeaders: -}
[WARNING] > [WinHttpCreateUrl] > [C:\Windows\SYSTEM32\WINHTTP.DLL] > {lpUrlComponents->lpszHostName: raw.githubusercontent.com}
[WARNING] > [WinHttpCreateUrl] > [C:\Windows\SYSTEM32\WINHTTP.DLL] > {lpUrlComponents->lpszHostName: raw.githubusercontent.com}
[PATCHED] > [ZwQueueApcThread] > [C:\Windows\SYSTEM32\sechost.dll]
[PATCHED] > [RtlInitUnicodeStringEx] > [C:\Windows\SYSTEM32\ntdll.dll] > {SourceString: !0AntiStealerByDarkP1xel.ASI}
[WARNING] > [gethostbyname] > [D:\!0\samp.dll] > {name: pc}
[WARNING] > [URLDownloadToFileA] > [D:\!0\MoonLoader.asi] > {szURL: https://blast.hk/moonloader/data/version-info.json | szFileName: C:\Users\755E~1\AppData\Local\Temp\moonloader-version.json}
[WARNING] > [URLDownloadToFileW] > [C:\Windows\SYSTEM32\urlmon.dll] > {szURL: https://blast.hk/moonloader/data/version-info.json | szFileName: C:\Users\755E~1\AppData\Local\Temp\moonloader-version.json}
[WARNING] > [InternetOpenW] > [C:\Windows\SYSTEM32\urlmon.dll] > {lpszAgent: Mozilla/4.0 (compatible; MSIE 7.0; Windows NT 6.2; WOW64; Trident/7.0; .NET4.0E; .NET4.0C; .NET CLR 3.5.30729; .NET CLR 2.0.50727; .NET CLR 3.0.30729)}
[WARNING] > [InternetOpenA] > [C:\Windows\SYSTEM32\WININET.dll] > {lpszAgent: Mozilla/4.0 (compatible; MSIE 7.0; Windows NT 6.2; WOW64; Trident/7.0; .NET4.0E; .NET4.0C; .NET CLR 3.5.30729; .NET CLR 2.0.50727; .NET CLR 3.0.30729)}
[WARNING] > [InternetConnectW] > [C:\Windows\SYSTEM32\urlmon.dll] > {lpszServerName: blast.hk | lpszUserName: - | lpszPassword: -}
[WARNING] > [HttpOpenRequestW] > [C:\Windows\SYSTEM32\urlmon.dll] > {lpszObjectName: /moonloader/data/version-info.json}
[WARNING] > [InternetCreateUrlA] > [C:\Windows\SYSTEM32\WININET.dll] > {lpUrlComponents->lpszHostName: blast.hk}
[WARNING] > [InternetCreateUrlW] > [C:\Windows\SYSTEM32\WININET.dll] > {lpUrlComponents->lpszHostName: blast.hk}
[WARNING] > [InternetCreateUrlW] > [C:\Windows\SYSTEM32\WININET.dll] > {lpUrlComponents->lpszHostName: blast.hk}
[WARNING] > [WinHttpCreateUrl] > [C:\Windows\SYSTEM32\WINHTTP.DLL] > {lpUrlComponents->lpszHostName: blast.hk}
[WARNING] > [WinHttpCreateUrl] > [C:\Windows\SYSTEM32\WINHTTP.DLL] > {lpUrlComponents->lpszHostName: blast.hk}
[PATCHED] > [ZwQueueApcThread] > [C:\Windows\SYSTEM32\sechost.dll]
[WARNING] > [InternetOpenA] > [D:\!0\SAMPFUNCS.asi] > {lpszAgent: SAMPFUNCS v5.3.3 release #19 (SA-MP 0.3.7)}
[WARNING] > [InternetOpenUrlA] > [D:\!0\SAMPFUNCS.asi] > {lpszUrl: http://service.blasthack.net/sf_sta...EF0C8C5C&x=B9909B053E5CD06910E320FA43440F5E5D | lpszHeaders: -}
[WARNING] > [WinHttpCreateUrl] > [C:\Windows\SYSTEM32\WINHTTP.DLL] > {lpUrlComponents->lpszHostName: service.blasthack.net}
[WARNING] > [WinHttpCreateUrl] > [C:\Windows\SYSTEM32\WINHTTP.DLL] > {lpUrlComponents->lpszHostName: service.blasthack.net}
[PATCHED] > [ZwQueueApcThread] > [C:\Windows\SYSTEM32\sechost.dll]
 

index

Известный
126
82
Скажите пожалуйста есть ли стиллер?



[PATCHED] > [ZwSetInformationFile] > [C:\Windows\SYSTEM32\KERNELBASE.dll] > {FileInformationClass: HIDE}
[PATCHED] > [ZwSetInformationFile] > [C:\Windows\SYSTEM32\KERNELBASE.dll] > {FileInformationClass: HIDE}
[WARNING] > [InternetOpenA] > [D:\!0\crashes.asi] > {lpszAgent: Mozilla/5.0}
[WARNING] > [InternetOpenUrlA] > [D:\!0\crashes.asi] > {lpszUrl: https://raw.githubusercontent.com/Whitetigerswt/gtasa_crashfix/master/LatestVersion.txt | lpszHeaders: -}
[WARNING] > [WinHttpCreateUrl] > [C:\Windows\SYSTEM32\WINHTTP.DLL] > {lpUrlComponents->lpszHostName: raw.githubusercontent.com}
[WARNING] > [WinHttpCreateUrl] > [C:\Windows\SYSTEM32\WINHTTP.DLL] > {lpUrlComponents->lpszHostName: raw.githubusercontent.com}
[PATCHED] > [ZwQueueApcThread] > [C:\Windows\SYSTEM32\sechost.dll]
[PATCHED] > [RtlInitUnicodeStringEx] > [C:\Windows\SYSTEM32\ntdll.dll] > {SourceString: !0AntiStealerByDarkP1xel.ASI}
[WARNING] > [gethostbyname] > [D:\!0\samp.dll] > {name: pc}
[WARNING] > [URLDownloadToFileA] > [D:\!0\MoonLoader.asi] > {szURL: https://blast.hk/moonloader/data/version-info.json | szFileName: C:\Users\755E~1\AppData\Local\Temp\moonloader-version.json}
[WARNING] > [URLDownloadToFileW] > [C:\Windows\SYSTEM32\urlmon.dll] > {szURL: https://blast.hk/moonloader/data/version-info.json | szFileName: C:\Users\755E~1\AppData\Local\Temp\moonloader-version.json}
[WARNING] > [InternetOpenW] > [C:\Windows\SYSTEM32\urlmon.dll] > {lpszAgent: Mozilla/4.0 (compatible; MSIE 7.0; Windows NT 6.2; WOW64; Trident/7.0; .NET4.0E; .NET4.0C; .NET CLR 3.5.30729; .NET CLR 2.0.50727; .NET CLR 3.0.30729)}
[WARNING] > [InternetOpenA] > [C:\Windows\SYSTEM32\WININET.dll] > {lpszAgent: Mozilla/4.0 (compatible; MSIE 7.0; Windows NT 6.2; WOW64; Trident/7.0; .NET4.0E; .NET4.0C; .NET CLR 3.5.30729; .NET CLR 2.0.50727; .NET CLR 3.0.30729)}
[WARNING] > [InternetConnectW] > [C:\Windows\SYSTEM32\urlmon.dll] > {lpszServerName: blast.hk | lpszUserName: - | lpszPassword: -}
[WARNING] > [HttpOpenRequestW] > [C:\Windows\SYSTEM32\urlmon.dll] > {lpszObjectName: /moonloader/data/version-info.json}
[WARNING] > [InternetCreateUrlA] > [C:\Windows\SYSTEM32\WININET.dll] > {lpUrlComponents->lpszHostName: blast.hk}
[WARNING] > [InternetCreateUrlW] > [C:\Windows\SYSTEM32\WININET.dll] > {lpUrlComponents->lpszHostName: blast.hk}
[WARNING] > [InternetCreateUrlW] > [C:\Windows\SYSTEM32\WININET.dll] > {lpUrlComponents->lpszHostName: blast.hk}
[WARNING] > [WinHttpCreateUrl] > [C:\Windows\SYSTEM32\WINHTTP.DLL] > {lpUrlComponents->lpszHostName: blast.hk}
[WARNING] > [WinHttpCreateUrl] > [C:\Windows\SYSTEM32\WINHTTP.DLL] > {lpUrlComponents->lpszHostName: blast.hk}
[PATCHED] > [ZwQueueApcThread] > [C:\Windows\SYSTEM32\sechost.dll]
[WARNING] > [InternetOpenA] > [D:\!0\SAMPFUNCS.asi] > {lpszAgent: SAMPFUNCS v5.3.3 release #19 (SA-MP 0.3.7)}
[WARNING] > [InternetOpenUrlA] > [D:\!0\SAMPFUNCS.asi] > {lpszUrl: http://service.blasthack.net/sf_sta...EF0C8C5C&x=B9909B053E5CD06910E320FA43440F5E5D | lpszHeaders: -}
[WARNING] > [WinHttpCreateUrl] > [C:\Windows\SYSTEM32\WINHTTP.DLL] > {lpUrlComponents->lpszHostName: service.blasthack.net}
[WARNING] > [WinHttpCreateUrl] > [C:\Windows\SYSTEM32\WINHTTP.DLL] > {lpUrlComponents->lpszHostName: service.blasthack.net}
[PATCHED] > [ZwQueueApcThread] > [C:\Windows\SYSTEM32\sechost.dll]
Чисто
 

Ottone Brown

Участник
41
6
Я скачал и установил как я должен зайти в игру чтобы не взломали, как обычно или с помощью какойто команды?
 

Help_Admins

Известный
75
8
Я скачал и установил как я должен зайти в игру чтобы не взломали, как обычно или с помощью какойто команды?
как обычно, потом как выйдешь из игры, посмотри лог стиллера

Есть Стиллер


Дай стиллеру пароль. Тогда будет работа стиллера)))0)

Кстати, админы
Посмотреть вложение 30200
Шо это?Зачем админы
 
Статус
В этой теме нельзя размещать новые ответы.