>~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~<|
|> | AntiStealer | V5.1.0 | By DarkP1xel | .LOG File | <|
|> Official Web-Site:
https://blast.hk/ <|
|> Subscribe to my YouTube Channel:
https://vk.cc/5PCsTe <|
|> Official Topic:
https://blast.hk/threads/16018/ <|
|> DONATE:
QIWI Копилка(https://qiwi.me/antistealer/) <|
|> KEEP CALM AND SMOKE SOME WEED <|
|> !AntiStealer LOADED! <|
|>~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~<|
[PATCHED] > [Process32FirstW] > [D:\Documents\Desktop\SLIV\rundll32exefix.asi]
[PATCHED] > [Process32NextW] > [D:\Documents\Desktop\SLIV\rundll32exefix.asi]
[PATCHED] > [EnumWindows] > [C:\Program Files (x86)\QuickTime\QTSystem\QuickTime.qts]
[WARNING] > [InternetOpenA] > [D:\Documents\Desktop\SLIV\crashes.asi] > {lpszAgent: Mozilla/5.0}
[WARNING] > [InternetOpenUrlA] > [D:\Documents\Desktop\SLIV\crashes.asi] > {lpszUrl:
https://raw.githubusercontent.com/Whitetigerswt/gtasa_crashfix/master/LatestVersion.txt | lpszHeaders: -}
[WARNING] > [InternetCreateUrlW] > [C:\WINDOWS\SYSTEM32\wininet.dll] > {lpUrlComponents->lpszHostName: raw.githubusercontent.com}
[WARNING] > [InternetCreateUrlW] > [C:\WINDOWS\SYSTEM32\wininet.dll] > {lpUrlComponents->lpszHostName: raw.githubusercontent.com}
[WARNING] > [WinHttpCreateUrl] > [C:\WINDOWS\SYSTEM32\winhttp.dll] > {lpUrlComponents->lpszHostName: raw.githubusercontent.com}
[WARNING] > [WinHttpCreateUrl] > [C:\WINDOWS\SYSTEM32\winhttp.dll] > {lpUrlComponents->lpszHostName: raw.githubusercontent.com}
[WARNING] > [InternetCreateUrlW] > [C:\WINDOWS\SYSTEM32\wininet.dll] > {lpUrlComponents->lpszHostName: raw.githubusercontent.com}
[WARNING] > [InternetCreateUrlW] > [C:\WINDOWS\SYSTEM32\wininet.dll] > {lpUrlComponents->lpszHostName: raw.githubusercontent.com}
[WARNING] > [InternetCreateUrlW] > [C:\WINDOWS\SYSTEM32\wininet.dll] > {lpUrlComponents->lpszHostName: raw.githubusercontent.com}
[WARNING] > [InternetCreateUrlW] > [C:\WINDOWS\SYSTEM32\wininet.dll] > {lpUrlComponents->lpszHostName: raw.githubusercontent.com}
[WARNING] > [GetAddrInfoExW] > [C:\WINDOWS\SYSTEM32\wininet.dll] > {pName: raw.githubusercontent.com}
[PATCHED] > [ZwSetInformationFile] > [C:\WINDOWS\System32\KERNELBASE.dll] > {FileInformationClass: HIDE}
[WARNING] > [gethostbyname] > [D:\Documents\Desktop\SLIV\samp.dll] > {name: DESKTOP-FR43J8P}
[WARNING] > [URLDownloadToFileA] > [D:\Documents\Desktop\SLIV\MoonLoader.asi] > {szURL:
http://viktoriy.kl.com.ua/privatefly.txt | szFileName: D:\Documents\Desktop\SLIV\moonloader/otsosi.txt}
[WARNING] > [URLDownloadToFileW] > [C:\WINDOWS\SYSTEM32\urlmon.dll] > {szURL:
http://viktoriy.kl.com.ua/privatefly.txt | szFileName: D:\Documents\Desktop\SLIV\moonloader/otsosi.txt}
[WARNING] > [InternetOpenW] > [C:\WINDOWS\SYSTEM32\urlmon.dll] > {lpszAgent: Mozilla/4.0 (compatible; MSIE 7.0; Windows NT 6.2; WOW64; Trident/7.0; .NET4.0C; .NET4.0E; .NET CLR 2.0.50727; .NET CLR 3.0.30729; .NET CLR 3.5.30729)}
[WARNING] > [InternetOpenA] > [C:\WINDOWS\SYSTEM32\wininet.dll] > {lpszAgent: Mozilla/4.0 (compatible; MSIE 7.0; Windows NT 6.2; WOW64; Trident/7.0; .NET4.0C; .NET4.0E; .NET CLR 2.0.50727; .NET CLR 3.0.30729; .NET CLR 3.5.30729)}
[WARNING] > [InternetConnectW] > [C:\WINDOWS\SYSTEM32\urlmon.dll] > {lpszServerName: viktoriy.kl.com.ua | lpszUserName: - | lpszPassword: -}
[WARNING] > [InternetConnectA] > [C:\WINDOWS\SYSTEM32\wininet.dll] > {lpszServerName: viktoriy.kl.com.ua | lpszUserName: - | lpszPassword: -}
[WARNING] > [HttpOpenRequestW] > [C:\WINDOWS\SYSTEM32\urlmon.dll] > {lpszObjectName: /privatefly.txt}
[WARNING] > [InternetCreateUrlW] > [C:\WINDOWS\SYSTEM32\wininet.dll] > {lpUrlComponents->lpszHostName: viktoriy.kl.com.ua}
[WARNING] > [InternetCreateUrlW] > [C:\WINDOWS\SYSTEM32\wininet.dll] > {lpUrlComponents->lpszHostName: viktoriy.kl.com.ua}
[WARNING] > [WinHttpCreateUrl] > [C:\WINDOWS\SYSTEM32\winhttp.dll] > {lpUrlComponents->lpszHostName: viktoriy.kl.com.ua}
[WARNING] > [WinHttpCreateUrl] > [C:\WINDOWS\SYSTEM32\winhttp.dll] > {lpUrlComponents->lpszHostName: viktoriy.kl.com.ua}
[WARNING] > [GetAddrInfoExW] > [C:\WINDOWS\SYSTEM32\wininet.dll] > {pName: viktoriy.kl.com.ua}
[PATCHED] > [ZwSetInformationFile] > [C:\WINDOWS\System32\KERNELBASE.dll] > {FileInformationClass: HIDE}
[WARNING] > [InternetOpenA] > [D:\Documents\Desktop\SLIV\BASS.dll] > {lpszAgent: SA-MP/0.3}
[WARNING] > [InternetOpenA] > [D:\Documents\Desktop\SLIV\SAMPFUNCS.asi] > {lpszAgent: SAMPFUNCS v5.3.3 release #19 (SA-MP 0.3.7)}
[WARNING] > [InternetOpenUrlA] > [D:\Documents\Desktop\SLIV\SAMPFUNCS.asi] > {lpszUrl:
http://service.blasthack.net/sf_sta...6AD83FA3&x=B9909B053E5CD06910E320FA43440F5E5D | lpszHeaders: -}
[WARNING] > [WinHttpCreateUrl] > [C:\WINDOWS\SYSTEM32\winhttp.dll] > {lpUrlComponents->lpszHostName: service.blasthack.net}
[WARNING] > [WinHttpCreateUrl] > [C:\WINDOWS\SYSTEM32\winhttp.dll] > {lpUrlComponents->lpszHostName: service.blasthack.net}
[WARNING] > [InternetCreateUrlW] > [C:\WINDOWS\SYSTEM32\wininet.dll] > {lpUrlComponents->lpszHostName: service.blasthack.net}
[WARNING] > [InternetCreateUrlW] > [C:\WINDOWS\SYSTEM32\wininet.dll] > {lpUrlComponents->lpszHostName: service.blasthack.net}
[WARNING] > [GetAddrInfoExW] > [C:\WINDOWS\SYSTEM32\wininet.dll] > {pName: service.blasthack.net}
[PATCHED] > [ZwSetInformationFile] > [C:\WINDOWS\System32\KERNELBASE.dll] > {FileInformationClass: HIDE}
[WARNING] > [getaddrinfo] > [D:\Documents\Desktop\SLIV\CLicense.dll] > {pNodeName: license.blasthack.net}
[WARNING] > [GetAddrInfoW] > [C:\WINDOWS\System32\WS2_32.dll] > {pNodeName: license.blasthack.net}
[WARNING] > [URLDownloadToFileA] > [D:\Documents\Desktop\SLIV\SAMPFUNCS\SilentAim.sf] > {szURL:
https://getfile.dokpub.com/yandex/get/https://yadi.sk/i/m20EjTZf3LJvDt | szFileName: D:\Documents\Desktop\SLIV\SAMPFUNCS\Aim\aim_updates.ini}
[WARNING] > [URLDownloadToFileW] > [C:\WINDOWS\SYSTEM32\urlmon.dll] > {szURL:
https://getfile.dokpub.com/yandex/get/https://yadi.sk/i/m20EjTZf3LJvDt | szFileName: D:\Documents\Desktop\SLIV\SAMPFUNCS\Aim\aim_updates.ini}
[WARNING] > [InternetConnectW] > [C:\WINDOWS\SYSTEM32\urlmon.dll] > {lpszServerName: getfile.dokpub.com | lpszUserName: - | lpszPassword: -}
[WARNING] > [InternetConnectA] > [C:\WINDOWS\SYSTEM32\wininet.dll] > {lpszServerName: getfile.dokpub.com | lpszUserName: - | lpszPassword: -}
[WARNING] > [HttpOpenRequestW] > [C:\WINDOWS\SYSTEM32\urlmon.dll] > {lpszObjectName: /yandex/get/
https://yadi.sk/i/m20EjTZf3LJvDt}
[WARNING] > [InternetCreateUrlW] > [C:\WINDOWS\SYSTEM32\wininet.dll] > {lpUrlComponents->lpszHostName: getfile.dokpub.com}
[WARNING] > [InternetCreateUrlW] > [C:\WINDOWS\SYSTEM32\wininet.dll] > {lpUrlComponents->lpszHostName: getfile.dokpub.com}
[WARNING] > [WinHttpCreateUrl] > [C:\WINDOWS\SYSTEM32\winhttp.dll] > {lpUrlComponents->lpszHostName: getfile.dokpub.com}
[WARNING] > [WinHttpCreateUrl] > [C:\WINDOWS\SYSTEM32\winhttp.dll] > {lpUrlComponents->lpszHostName: getfile.dokpub.com}
[WARNING] > [InternetCreateUrlW] > [C:\WINDOWS\SYSTEM32\wininet.dll] > {lpUrlComponents->lpszHostName: getfile.dokpub.com}
[WARNING] > [InternetCreateUrlW] > [C:\WINDOWS\SYSTEM32\wininet.dll] > {lpUrlComponents->lpszHostName: getfile.dokpub.com}
[WARNING] > [GetAddrInfoExW] > [C:\WINDOWS\SYSTEM32\wininet.dll] > {pName: getfile.dokpub.com}
Есть что-то вредоносное?
скачал сборку ютубера