DonatShell
Server IP : 180.180.241.3  /  Your IP : 216.73.216.252
Web Server : Microsoft-IIS/7.5
System : Windows NT NETWORK-NHRC 6.1 build 7601 (Windows Server 2008 R2 Standard Edition Service Pack 1) i586
User : IUSR ( 0)
PHP Version : 5.3.28
Disable Function : NONE
MySQL : ON  |  cURL : ON  |  WGET : OFF  |  Perl : OFF  |  Python : OFF  |  Sudo : OFF  |  Pkexec : OFF
Directory :  /Windows/System32/

Upload File :
current_dir [ Writeable ] document_root [ Writeable ]

 

Command :


[ HOME SHELL ]     

Current File : /Windows/System32//werdiagcontroller.dll
MZ@	!L!This program cannot be run in DOS mode.

$RichPELw]!	^K1p@llf<@e@.text]^ `.datapb@.rsrc@d@@.relocvj@Blkkkkkkkknk^kHk<k.kkjjjjj"lijjj,j@jiTj^jhjxjjjiiii~i`iLi0i"iihhhhhhnhPh:hhHjh>lPl`lnlllw]./#CircularSizeFlagsLevelGuidStopping FDR
Failed cleaning up Autoverifier settings
Stopping Autoverifier
FDR will be enabled
ProcessStartupSettingsUpdate failed 
Verifier.dll loaded. Enabling Autoverifier.
r s\KernelObjects\SystemErrorPortReadyAutoverifier enabled flag is not present 
AutoverifierEnabledAutoverifier settings key is not present
Software\Microsoft\Windows\Windows Error Reporting\Plugins\AutoverifierFailed getting current user registry path
NtAlpcSendWaitReceivePort failed with status 0x%xCAutoVerifierSettingsEngine::DisableHKCULookupForIFEO Service returned failure status 0x%xNtAlpcConnectPort timed out, failing the call with 0x%xNtAlpcConnectPort failed with status 0x%xRtlAllocateAndInitializeSid failed 0x%x
WaitForWerSvc timed out, failing the call with 0x%
xWaitForWerSvc failed 0x%x
SignalStartWerSvc failed 0x%x
PluginsNtGetRegStringValue failed 0x%x
ErrorPortFailed opening registry key 0x%x
\Registry\Machine\Software\Microsoft\Windows\Windows Error ReportingFailed writing key value
Failed opening registry key
Verifier switched to light mode
WaitingThreadFailed switching to normal heap mode
WaitingThreadFailed obtaining VerifierForceNormalHeap function address
VerifierForceNormalHeapWaitingThreadFailed obtaining verifier.dll handleverifier.dllWaitingThreadThread failed to wait for the specified time; Disabling autoverifier
Failed deleting autovefier enabled flag
Failed deleting registry key
Failed creating timer thread
Failed reading key value
AutoVerifierTimeDurationFailed writing registry value
AutoVerifierCountFailed getting process name
Handle to registry key is null
Software\Microsoft\Windows NT\CurrentVersion\Image File Execution OptionsDFԓ@+f9vKtdgInvalid paramsInvalid params
Arithmetic overflowOOMInternal provider enabled for Level %u
Flags %lu
GetTraceEnableFlags failed
GetTraceEnableLevel failed 
GetTraceLoggerHandle failed 
Tracing disabled for internal provider
Provider not registered. RegisterTraceGuids failed with %d
Failed enabling trace provider 0x%x
Invalid argument: GUID structure cannot be null
CFDRShim::UpdateGUIDSettingsInvalid arguments: pointer to settings structure cannot be null
Failed reading string value from registry
PluginsNtSetRegStringValue failed with 0x%x
UtilRemoveAppCompatLayerFromList failed with 0x%x
FDRPluginsNtGetRegStringValue failed with 0x%x
Software\Microsoft\Windows NT\CurrentVersion\AppCompatFlags\LayersAppPathSoftware\Microsoft\Windows\Windows Error Reporting\Plugins\FDR\CurrentSessionFailed deleting session key
Failed opening session registry key
Invalid arguments; pointer to string buffer cannot be null
Failed writing process ID to registry
ProcIDGet current process ID failed
Failed reading log file path value from registry
LogPathFailed reading FDR settings value from registry
SessionSettingsInternal log message
Internal provider failed to log messageMemory allocation for event failed.
Failed determining string length
Internal provider: FDR did not start yet; Message lost
Failed enabling internal trace provider Error 0x%x
StartTrace failed for the internal provider, %d
Failed copying string buffer
Unable to allocate %d bytes for properties structure.
FDR Tracing SessionInvalid arguments: Log path cannot be null
Invalid args: The pair string cannot be null
Invalid args
Failed copying string
Failed getting string length
Invalid format: expected '='.
Failed obtaining string length
Invalid arguments: Buffer or separator character cannot be null
Failed copying characters to pair buffer
Out of resources allocating memory for string buffer
Failed making a copy of the original settings string
Failed obtaining the length of the input string
Invalid arguments: String buffer cannot be null
Failed extracting next pair from the current token
Failed extracting next token from settings string
Log file size was not specified; Logging will not be enabled
Failed updating settings; Parsing continues...
Error parsing current pair; Ignoring pair and continuing parsing
Invalid argument: settins string cannot be NULL
Session settings and/or FDR layer were not deleted successfuly
CFDRShim::CleanupSessionSettingsFailed deleting file
Failed appending process ID to log file name
%s_%dFailed reading session settings, cannot delete log file
FDR startedFailed to enable logging
Failed parsing settings string
Failed reading the session settings of updating the process ID
Unexpected event response or failed waiting for event


Flushing done, done signal sent

Failed setting event
Failed creating event
Failed concatenating strings
%s-%dFDR_FLUSH_MESSAGEStartFDR failed 0x%x
Failed creating FDR thread
AppRecorder enabled flag is not present 
AppRecorderEnabledAppRecorder settings key is not present
Software\Microsoft\Windows\Windows Error Reporting\Plugins\AppRecorderFailed to update App Recorder run count
Failed to update application appcompat layers
Failed to delete appcompat layers
AppRecorderFailed to get application appcompat layers
Failed to open App Recorder layer key
Failed to get current process name
Failed to delete App Recorder key
AppRecorderCountFailed to create UAR process
Failed to create UAR process command line
%s /start /output %s /gui 0 /recordpid %d /stopevent %s /sc 0 /noarc 1 /waitonpid 1Failed to create UAR executable image path
\psr.exeFailed to get system folder path
Failed to register the log file with WER
Failed to create apprecorder temp file
Failed to create temp file name
.AppRecorderData.xmlFailed to get temp file name
WERFailed to get temp folder path
Failed creating apprecorder event name string
%d-AppRecorderEnabledLocal\{DF2B7FCA-C5B0-4638-A4AD-59F7F76CE540}Failed creating AppRecorder thread
ADVAPI32.dllFailed closing registry key 0x%x
Invalid parameters
Failed extracting registry value %S
Out of resources allocating memory for key information structure
Failed writing to value %S
Failed deleting key
Invalid arguments: handle and value name cannot be null
Failed deleting specified value
Failed opening registry key0x%x
Arithmetic operation failed.
Failed concatenating strings: 0x%x
%s\%sInsufficient resources
SizeTAdd Failed wi.
Failed obtaining string length: 0x%x
Failed copying string 0x%x
Invalid size returned
NtQueryInformationProcess failed
Failed with integer overflow
Failed determining string buffer length
Registry value %S is not of type string
RSDS_MM5^adWerDiagController.pdbU4Lp3ʼnEEMV3FW9uP39=puBp#p9=ptD9=ph+Ypn
ȸ#;uh+Y5p9=ph+Y=p%k39}uX95pu/hx+Ypwȸ#;u:hlV+Y-9=pu%h\A+YV*}u pM_3^̋UV3F}ujVj9uu=ruuVu5r^]}̋U,EeSXVpW}+x@+ًUyEu}5 RS*}tEjWV*u+jY}EE E$]t7MQj-W*u"p*~t=uSjjVr*t	E}u	E3}t-uu'*u(*t=uEuuS)}tE0_^[̋UQQs
sss5s=sfsf
sfsfsf%sf-ssEsEsEssrLp sr	rEPph$E(h	j(̋U
$ (;u
M3t=N@uO@]̡Lpt=N@uhLpLpYУPp;
LpűU}u3@]̋U$Lp3ʼnEVWTfEDfE3fE܍}ޫjfjEPEPEnEEEEEEEEh;u~ƋM_3^,̋U,VjFXjHfEXfEEE܍EP3hEPE0Eu؉uuu;|&MEPVuE.u^̋Vt
P&3^̋USVW3fE}fE3P]]#;uh;EPSuh
+#;uhEPhu'#;u
hxY&Y3@9EuE9]t	EPQ'9]tEPSEPE_^[̋ULp3ʼnES3VW3LPf@BfXPSShT\X`]]]]]E%*@P#;uVhTPhpX#-#;uVhH+;}Vh(;}Vh;uSVhT P`PSSSSSSSjjEP;}VhVPLPSSSS`(hSP P\PDž(,408<DžL
;}Vh|;uSVhDHVdSPJ$~fdVffSPDž|$fLPSHPPSdPh\fH;|,t$9}h#3
Vhn#YY9TtTP'9`t``9\t\\9XtX4M_^3[̋USVW3fE}fE3PM]#;uh<EPSuh1'#;uhPShu$#;u
h4|"Y
M[39]t	EPu#9]tEPSEP_^[̋UVWu3fE}f3fE}f3W}h!Yh`EPEPEPWW;}h,!OhEPEPWEPu;}hujU;}hhp!3Y_^̋U$S3VW3fE]܍}્}f3fEPM]]#;u
hJEPSuh%EP#;uWh Y9]uh Y<Ef9uhPJ'#;u
hEPuSu%#;u
hPEPhu!#;t?EvHPhu"#;uhsEPh\u!#;uh@S9]vVjhigSuuEMQPhuh:SSSSSujp#;u
h Y;}w3EP/##;uhYM#;uhY39]t	EP 9]t	EP _^[̋USVW؋33t!9EtftfAACCNMGuuIIOz3fMt9_^[]̋U}wErw	M3E]̋UE~%
|@]̋UES3VW]]];9]u;|M;uPf@@f;u+EMEPf@@f;u+E9]5;-EPjuEPEjYRPdu@0Spd;uhuSP6ǃf9t}9]tEGGf? t9]tf9tj XfFF]uuW`u#EGf;tf u;}tvf9_uf;tfFFGGEf9u3f3,h(Y;tPd@0Sp\hhWY_^[̋UVuuW6d@0jp\&3^]3h PQ(, $̋UEtH!u!uhupuuu
h|1YLSRPp؄uh\5u5upu
h<YPPh[3]̋UQQVW(P3VV0pEPjhVh?@Eup;tPhYY3_^̋UQSW3ۋ]9vNVw~u;$F P6vjp3ɅNtPh%EYYC;r^E_%@[̋3v 9u@JűU Lp3ʼnEVWjYu}}u!Mfufu3ɀ|
uArk|jYuM_3^/̋UQQW3}fE}f_uh0PYWuEPuEPh
̋UQS]MuhhYWV5W}hPWYYuMSu`WhDWYYuulYC:h8WYYuulYChWYYuulYM_3^[̋USVW3fE}3fEP]]]]EPSuh(#;u
hPEPhu #;9]EPEPSuh[#;tEPuu #;uWh`YgEPhXSu;}Wh$YGE;t!f9tPuuA#;uWhuu3%hA;Y}9]tuu9]t	EP,9]t	EPP9]t	EPB9]t	EP
_^[̋UeVW3fE}fEPEPjuh(1#;uhEP#;uh|Y3}t	EPv_^̋USW3fE}3۫]f9]9]VEPEPSuh(#;uhPxuhu#;uhYuhu#;uh:d@ ;uhY@+Phtu#;uhL|Y3^9]t	EPvhTYW_[̋UU3tvW|EMhj]̋UU3Wtv|%}vU3f
uEMj_]̋UM3tvW|9SVW}EPuqVW3X|;wu
z3fw_^[]̋UEW}tUwW}t'_]̋UQuuuhYEPhu}hًESVD6d@0WWjpd؅uh|pWjSf3C,{3fCCECC0EDPuC4PS5u5upthTDYh<9Ytd@0Sjp\_^[3̋UW3 M8x9}uh YWtVEPVup;ljE}hYFEPVh J;ljE|ڋEMDStHzEd@0VWpdV;u
h gYmWSE33AK(C,{}xuClC@CpxWcDK0MAQPS<E}
hp YlSh  VptPh< YYE@?v6hjjjptVh YYVEetd@0Sjp\[E^_̋UQV39u9u9uSWEPSu;}h!j=uxYY;uh!o+uFt]9utXEPGSGW}hx!@EuWuu}h`!NVuuu|3hP!WY_[h !oYW^̋UVu}u
h"MQhPE}h"Yd@0S]W=dLQjpM׉E6CSP]E}
h"uux+]YY6E3PC9Ed@0pu:\ud&@0jp׋MuuP\&}E;sAd
+ÉEDPA0jp׉tBMQMAQPE}h`!PvSd@0Qjp׋MuhP"YE&KQuSPE}
h$"Ye}_[tud@0jp\Eh!qWY^̋U<Lp3ʼnESVuW3ۉMj3Y}]uĉ]܉]ԉ];uhL$YW9td@0=dhSp׉E;uhP"Yd@0hSp׉E;uhP"YW9M؍EPj;V2;9]]]3}૫9]tud@0Sp\]܋M؍EPj,EP;9]tKMhuhuu}h$M؍EPEPuu}h#
Y9]mjYuMu9E;u&h#
Y@h`#h(#
YM؉A39]tud@0Sp\9]tud@0Sp\ud@05\Sp9]tud@0Sp֋NjM_^3[̋U0S3VW3uЍ}ԫ3fE}꫋fuuufEPEPn;ƉE}h8%YE9ud@0hVpd};uhP"iYEdp uh,%hW;ƉE}h$xWEPVVEPuEE؍EPEuE@uu|EP#;uh$Y}9u}
h$Yu=\9utud@0Vp׉u9utud@0Vp׉u9utud@0Vp׋E_^[̋UQQSVW3}}EPEP;}h%4EP;}h%!u;}
h%
Yjht%3ۋ5\9}tud@0Wp։}9}tud@0Wp_^[̋U<Lp3ʼnESV3;}Vh&S
YY6dp d@0WhSpd;uhP"
Vh&h&hW:;}h&	WSSS(;uh&|5,@w=uN3Ʌ#Pօu0uhp&hL&N	3h&@	@Y_td@0jp\M^3[̋UVW33u}EPEPVhQVVVVVjup#;uh'Y3_^̋V3ʅtf9tFFJuuW^t|+ʉÃ'̋UW3t;UvW|
E'_]̋USVW3fE}fE3P]]#;uh;EPSuh'n#;uh|'EPhT'u7	#;u
h('Y3@9EuE9]t	EP9]tEPSEPE_^[̋U,Lp3ʼnESVW3ff33fPDž@#;u
hAPSh'l#;u
h|'Pt)W+#;u
h('P

#;u
hP)hPS$u
h()PSh
#;u
h)}PP
#;u
h(TWfGGf;u+jh(P`uR9tDPYt3DPYuf|uu!3 O9t?SK;r3fP'+t
|?HWP	T?RLHQP3f9uP#;uHh(9PP#;u(hd(HPW#;u
h8(Y9tP9tP9tP9tPSPM_^3[̋UUVuhVE|OUM+SjV[t/+uWu+tftf@@IOu_uHHz3f[^]̋U
Lp3ʼnESVW3j@|VPx33H,WVhfffffPNWjVV(u
@O}hYdp h,WP0؃;}h+YPVVV(;u
h&PWu
h+lPVh+Pu
h+DPht+hP;}
hP+VhjVjh@Pu
h$+P4jjPw;}
h*WPu
h*h*WP;}
h*PPPPPh)WP؃;}h);PxPVVVVVVPPDžxD u
h) Y69t49t439t;}4M_^3[q̋USW33]}]gtQVEPEPShXSSSSSjp#;uh,cY39]t	u4^_[̋D$L$ȋL$u	D$S؋D$d$؋D$[%%%%%t%L%H%D%@%<%8%pQRPheZYคpppppp̋UME;r	M3E]̋UVuuh-Y
.WP#;uWh,YY&3_^]̋USW3fE}3f]9]9]}VuEPd@0jSpd;uhH-.YXEPjVjEPuظ#;t~u	F3uh-YYd@0Vjp\^h-Y
_[̋UQQW3fE}f39}tP9}tKVuEPjEPjWEPu#;uuh-NYY3^h-9Y
_̋UQQW3fE}f39}tk9}tf9}tauEPEHf@@f;u+VDPuEjWPu#;uuh-YY3^h-Y
_̋UVuuh-pY
,WP#;u
h-GY&3_^]̋UQQW3}fE}f_tD}t>VuEPEPu#;u
h.Y3^h-Y
̋UVuu
"d6@0jp\t&^]̋U,SW3fE}3f3]]]9]E;V9]5EPVu;} Wh.YYtEPVu;}Vh.YYCEPuu}h.YEPju~EjYMQRPp|mdu@0VSpd;uh.RYuuh.VWy;}Vhh.YYlW
hH.LuEPEE؍EE܍EPh?uEE@]]#;uVh$.YY3;td@0WSp\^h-|Y
_[̋ULp3ʼnEW}3hPfP[}VjhPj+j}h0/f9vh/q3fBBHHf\tf/tf:t;wHHPuWG}Ph.mYY3^h-XY
M3_̋UW3fE}f3}}}9}o9}fSVuEPd@0VWp=d׋؅uhH-YEPVSjEPu#;uuh-Y{tuh/MQChP}ht/YEPju |eEPEjYRP|Ndu@0jp׋MuhP"0KQuP}
h`!w3hT/Yd@0Sjp\^[h-Y
_,vpff,fBfXfpffffGetTraceEnableFlagsGetTraceEnableLevelGetTraceLoggerHandleARegisterTraceGuidsWEnableTraceTraceEventStartTraceWdgjXg0llkkkkkkkknk^kHk<k.kkjjjjj"lijjj,j@jiTj^jhjxjjjiiii~i`iLi0i"iihhhhhhnhPh:hhHjh>lPl`lnlll DbgPrintfLdrDisableThreadCalloutsForDllNtTerminateProcessRtlUnhandledExceptionFilterRtlNtStatusToDosError>EtwEventWriteNoRegistrationNtClose-NtWaitForSingleObjectWNtOpenEventRtlInitUnicodeStringPRtlFreeUnicodeStringERtlFormatCurrentUserKeyPathNRtlFreeSidNtAlpcSendWaitReceivePortNtAlpcConnectPortcRtlAllocateAndInitializeSidmemsettLdrGetProcedureAddressRtlInitAnsiStringnLdrGetDllHandleNtDelayExecutionRtlCreateUserThreadM_vsnwprintfKRtlFreeHeapR_wcsnicmpeRtlAllocateHeapRRtlGUIDFromStringY_wtoiP_wcsicmp{memcpywcschrNtDeleteFileRtlDosPathNameToNtPathName_U}memmovemisspacentdll.dllDelayLoadFailureHookDGetProcAddressGetLastErrorcFreeLibraryInterlockedCompareExchange>LoadLibraryExASCloseHandle\SetEventWaitForSingleObjectCreateEventWGetModuleFileNameWCreateProcessWKGetProcessIdGetCurrentProcesspGetSystemDirectoryW
WerRegisterFileCreateFileWDeleteFileWGetTempFileNameWGetTempPathWuOpenEventWKERNEL32.dllNtQueryValueKeyNtSetValueKeyNtDeleteKeyNtDeleteValueKey\NtOpenKeyNtQueryInformationProcessDv]llll[YSmmWerDiagController.dllStartAppRecorderStartFDRPD8,rN@DPD8\\	]]]']1]0	H`4VS_VERSION_INFO__?:StringFileInfo040904B0LCompanyNameMicrosoft Corporation\FileDescriptionWER Diagnostic Controller0FileVersion6.1.7601.24521 (win7sp1_ldr_escrow.190909-1704)TInternalNameWER Diagnostic Controller.LegalCopyright Microsoft Corporation. All rights reserved.TOriginalFilenameWERDiagController.dllj%ProductNameMicrosoft Windows Operating SystemBProductVersion6.1.7601.24521DVarFileInfo$Translation	$2(20,01090E0O0U0]0h0s0000000000	1101h1}1111122222222223
333 3(30353:3?3E3O3Y3e3j33334
4E4445.5K5V5v5555555(636P6666677/7H7`7|777888889,9F9999999::I:R:]:g:w::::::::&;8;J;[;i;~;;;;;<<2<N<`<e<p<z<<<<i>t>>$?I?T?[????@0000 010<0D0J0P0Y0k0000001,1~122(2L2c2l22222223$3;3I3|333334444475D5[5e5z55555556B7H7O7t7777778
8878h888889Z9h9u9999999:N:[::::: ;@;_;;;;<Y<<<<<=4=W=n==>J>k>>>>>?????P$0%020A0h0t0000=1U1s11111,2=2R2W2p22222233@3x333J4Z4i4y444444C5S5k5{55555566@6~666617^7~7778889*9F9_9z9999999999:=:G:S:n:::::::::(;1;M;g;;;;;<\<h<t<<<<<<<<<<<<=
===(=2=~===>>#>F>l>>>>>??_??????`T
0S0`0t000=1p1111222O2a222222M3X3r333Y4r444444X5|5555p(0000$0T0\0d0l00000000

Anon7 - 2022
AnonSec Team