DonatShell
Server IP : 180.180.241.3  /  Your IP : 216.73.216.127
Web Server : Microsoft-IIS/7.5
System : Windows NT NETWORK-NHRC 6.1 build 7601 (Windows Server 2008 R2 Standard Edition Service Pack 1) i586
User : IUSR ( 0)
PHP Version : 5.3.28
Disable Function : NONE
MySQL : ON  |  cURL : ON  |  WGET : OFF  |  Perl : OFF  |  Python : OFF  |  Sudo : OFF  |  Pkexec : OFF
Directory :  C:/Windows/System32/

Upload File :
current_dir [ Writeable ] document_root [ Writeable ]

 

Command :


[ HOME SHELL ]     

Current File : C:/Windows/System32/userinit.exe
MZ@	!L!This program cannot be run in DOS mode.

$2݀\\\Ɏ\؎\ώ\]\ߎ\Ȏ\͎\Rich\PEL8L	P+`=@Tp,]8G@pR.textINP `.data`T@.rsrcpZ@@.reloc,b@BnLHLRL{1L{&L(LLLntdll.dllAPI-MS-Win-Core-LocalRegistry-L1-1-0.dllAPI-MS-Win-Core-ProcessThreads-L1-1-0.dllUSER32.dllUSERENV.dllmsvcrt.dllKERNEL32.dllwhAw]wTw%
w>!ww2wwOwuMwHwQ3w]7wwM w@w8wgww_ww>w}Pwbww|wwI0j@ouoo7o6oooZoλoQooowo'o(oao'>oo+o'o/w1#w8ww`wwAw=ww
w\9w4w5w[wGwwwWAwcvwTw='w@wwFwGdw̼wTwFww|www=www<w3wwewc3wdw;wwUQM39SV5HWSEPW։EuFXuX}sRhLESjҐShellReadyEventjPPh NLuT_^[3U`3ʼnEESVW3WWjWx}}}$jRXt&htlE;thdPp;tjо<V8hE+SEJWV5\EWhWSCw$1h,`;G1EjWuuWuu5uuj8P4x.lPWEPhWW<;thVPVTEPhWhh$09}_^[t	utM33UserInitMprLogonScriptUserInitLogonScriptUserInitLogonServerImmDisableIMEimm32.dll;
`<ÐSoftware\Microsoft\Windows\CurrentVersion\Policies\SystemuF	1EtAEPVjh`=`81P5d}t^j
X뾐U
`3ʼnESVW}h"3WYYth"WYYphPDžh<t9ufEf3fPPEVV3j CVV#VPE#PDžDD;M9u	 =T9t׋M_^3[%SystemRoot%\Explorer.EXEU`V3uuuuuuu܉u9u:3@^VV4V#3_%%U,EeSXVpW}+x@+ًUyEuMRRS}-jWV{-jY}EE\E$]h-}-}-uu@-E-}tE0_^[=uԐ%pWEPh@PHtuu؋T3@;ES;f90yPh(Ӎ<VǍ|Wj@|EUVWPuWu9
h(Wu+
3}EPWu0EPunuuuuE;tuh\u9}t	u9} 9} 9} 9} } 3@[_\\PATH95`u2h#l;h#Pp`;WӍDPj@|;WW@Pt9uu	;tf93f	j<_WPVP
ElPPPDžT@`dDž\`;t9uTWopenUQQS3VW9]u5u֍WÍ\Sj@|tyuSVcWSVuSV3E9]uEShh SuuuSV}E;tV9]E_^[u뛐\HideLegacyLogonScriptsUVuW3;7 3_@^]U4`3ʼnEEd@0
;(SV5WhP֋=3PSPDžDž@ׅh0P3PSPDžDž@ׅ1hP֍P3SPDžDž@;_^[M3	\Registry\Machine\System\CurrentControlSet\Control\GraphicsDrivers\InvalidDisplay\Registry\Machine\System\CurrentControlSet\Control\GraphicsDrivers\NewDisplay\Registry\Machine\System\CurrentControlSet\Control\GraphicsDrivers\DetectDisplay%h`QRPhRZYU `3ʼnEESV5$WPW3Sh hօPWShdhօj^PPPShc v(hM_^3[9u뼉CLSID\{16d12736-7a9e-4765-bec6-f301d679caaa}U`3ʼnESW33]}fjEEXMQPSSSESEP`d@0
;uVht!ShH;^M_3[ÐRasAutodialNewLogonUserUU3t"w|EMhj]WߐUSVW؋33t?9EtftfAACCNMGut3fMK_^[]IIOzߐSoftware\Microsoft\Windows NT\CurrentVersion\Winlogonexplorer.exeexplorerUV5xWjju֋t.S?Pj@|؅t!WSuօO;[_^]3UUS3Vt7;w3]|3W}1M_|UEV+jK_^[]W3ؐV3ʅt$f9tFFJut^

+ʉøWshell32.dllShellExecuteExWUVuVf>"h
^]UESV5$WEEPWjhH"u֋ u&EPEPEPjuEuu(EPWjhuօD
E_^[UWW,Mt_SV5Pu؍\Sj@|t6uSVh(%SV=E0SV1VW\V3@^[_];hPW%UEV3t%ftf"Kuf t	PP^]SEE_MASK_NOZONECHECKSf?,t>Ef8 t>SuSuSPtE}f9y9]3fGG@@븐UH
`3ʼnESV5$WPh3Sh&WօJ9d@0
;3GWSSSS(VuWSSWh"V~NjM_^3[Ðsystem\currentcontrolset\control\safeboot\optionU ES3VW@Vj@]uE]]|};D9]tuhW;ÉEEP39]hShH"P$uIEPWEPSuuu u#}Ef9\Gu(9]u'9]u"EPhShh$f9uW_^[u9]5h(u]YYu#h"WYYth"WYYuEf99]]}느h(h%\Ð1\NETLOGONshellVjh%\^ÐUu]U\`3ʼnEhX>	M33@)ÐUV395`tWEPjVh)h$u6EPEPEPVh)uuE 
u(5`d^ÐTSAppCompatSystem\CurrentControlSet\Control\Terminal Serverf9Qf?,GG鐐dh`5d`h`h`h``ÐhO3Ð%hLQd5D$l$l$+SVW`1E3PeuEEEEdÐ3ÐU`eeSWN@;VEPu3u3d33EPE3E3;t`t5`։5`^_[þO@搐UVu3;usu
tу^]ø`QRPhRZY+jXh-3ۉ]]EPEEdp`jVW3F`;`5`h-h,<YY2`;uh,h,3YY`uSW=dT0u< M<"mPYjFՐv*5-*FFUFiFMZf9<8PEu|HPxtvf39j`*P
`
`YY
d
dP=d33룐hhYYÐUeSV5$WEPWjhH"h֋ u(EPEPEPjh.uEu(EPWjhH"hօu(EPEPEPjh.uEu(EPWjhhօEPWjhhօu(EPEPEPjh.uEu(E_^[ÐRunLogonScriptSyncU`3ʼnEd@0Wdh/jKP3|RVdPV`P\PWjjWWdPV^u\(`uGM3_ÐSoftware\Microsoft\Windows\CurrentVersion\Explorer\SessionInfo\%dUM3t>w6|0SVW}EPuqVW3|;w_^[]øWûzUjtP!t@\f&jX]ËE]ÐjhH13Mt:t5!EMZf9u!Q<|s
E8PEE%FFMd
Y__^[]QÃ'É9f|F"3fLFDPFPVmS}3ɅX=2F,EPEPEPjuEuu(f8ȋWf9,uAAf9,tII3f9;tf9f:AABBf9u_;3f
EPEPEPjh.uEu(.VDVTSV3ST@f;WjYj@G}YEPEPShSfSS|4}5h4WօjEPjSEPuE1E3u(EPEPShSSSh3WօEPEPEPS3VuE u5MEff;uf;tfPf;Quf;u3;u"jEPjSVuuSSSj[|u(_^[HotkeyKeyboard Layout\ToggleSoftware\Microsoft\Windows\CurrentVersion\Runoncectfmon.exe /n9ud3fw33fCCjPX=#9u95`u2h#l;h#Pp`;WӍDPj@|;\WW@PA9uu;tf93t	3fCChj<_WVPE0PDž@$(Dž 6`;tLW9s3Cd@0
;o9c=dSPhHVSPhGVVPPV`VV\jPrunas3}uhW'3fEPWEPSuuu uE(9]$3A9MuEv
f9\GMEWEP8rNDhXGuYYuESuuuSVE]f;tf.PPf;u3Sduu;uSuuuSVgVX}tSEPhWh;h$u+EPEPEPWh;uE u(}59}5xWWh`;։E;Pj@|E;uPh`;օEPh@WWuW`Eg;_0VӃ~f>\u
f~\u;thV4`YYE9}'EPVu8`	MEPVu50`փjhuփWjuփEPjuEփE܉EčEPu}@`YYhWWu<`uluE0h(Ӎt6Pj@|E;t4M1VP|,h(Vu|E}!}"}uuuD`Y
34;VӍ\GSj@|eSW4t;VSWaEPWuuuWuEh\uW}t}t)
Ez\repl\import\scriptsUSERDNSDOMAINAllow-LogonScript-NetbiosDisabledSOFTWARE\Policies\Microsoft\Windows\SystemWuVWt
9}tVtFf9>hPhBd3PjPjPP(SSSSSh=59yhPhAdSjSjPhXGB_%SystemRoot%\System32\RunDll32.exe %SystemRoot%\System32\rover.dll,RunMonitorPPPShCDž (9mPhShCWօuUPPPShCDž u	f9u(@W3GWWWSSpCVWWWWSVSjSSSP3PPPPjƅ:u;u<h C
YSS\98uj8E@=<9tXVPׅu,VP;}P8P(8u.d@0hBƅhP

tWVPPׅuPVPe;KSjSSSPuhBMY38jDPSSSXA
u
8SjPS3Sh,3hQ9t_CPSd;t4hj@|;t!PhV	QEPSd;tVhj@|;t!PhV;t;thBh@SVSSx
V
9
9x
ts_remoteprograms.chm::/html/d69deee5-8457-4327-92b0-f0c6c8c826ef.htmUSERINIT: Failed to start ctfmon.exe in TS Single App mode ! 
USERINIT: Failed to set working directory %ws for SessionId %u
USERINIT: Logging off session since WinStationGetInitialApplication failed! 
AppSetupAlternateShellsystem\currentcontrolset\control\safebootUseAlternateShell9}t3FhTEl;h<ESp;tStVjVuuVuEj^tP|PpPWhEu|t u/9pu'9|thDj2EPWjWWWEPu(proquota.exeEnableProfileQuotaTermsrvCheckNewIniFilestsappcmp.dllMQjWu}~t=u2jjVtEVEcuSb;u
3FShL.j@Yohd
Yjjjd< Fu39MMFuE	MPQ	YYËeEܣ`=`uP=duE`3@ËeEÁ39h+Y3@Ëe3E1f3@]Å)У`s.cmd.batctfmon.exevmappletMessageHelpWndClassH`GLQU `3ʼnEhjP2PDžt3@8Eu	Eu3M3AÐU<`3ʼnEVPh3VhIh$PPPPPPPPVPPDž,u895dthdPhud3Fd(t3h#lt"h|IVptjQVtM33@^RegenerateUserEnvironmentVolatile EnvironmentUVhj@|u3.uVhuuu`u	V=w^]UQQSEPj3ShJh]$t2@VuEPVEPSh@Gu u}uE3fLFu(^[Software\Microsoft\Windows\CurrentVersion\RunU4`3ʼnEVPh,Pjj3VJt
EtFM3^LÐVhpKjjHtVDVT^ShellDesktopSwitchEventUEHt#Rt]%ljj5du3@EPu
djul]U0j0EjP8EEdEEPE0EإKpUE@VtQ39utJWuuuVuVVVVhV5dVxuuuV`Vt_uuuu`^]%UM3tvW|@ES3Vt&UW++Ѝ7t
t@Nu_uHz^[]U`3ʼnEEVPh3VhNhWPPPVVDžuAEuWPHO;FPW3Ʌ(_3M3^CLSID\{ADB880A6-D8FF-11CF-9377-00AA003B7A11}\InprocServer32U`3ʼnE
dS]VW}uW9
duOP5tP֣d
du!hO֋ȉ
dud3%dujQpdtuuSWЋM_^3[hhctrl.ocx`QRPhR<ZY`QRPhR$ZY%`$`QRPhSZY%$` `ݐ% `(`ː%(`D`QRPh$SZY<`@`0`ڸ8`Ӹ4`̐UE8csmu+xu%@= t=!t="t=@u3]%UMMZf9t3]ËA<8PEu3ҹf9H‹]ÐUEH<ASVq3WDv}H;r	X;r
B(;r3_^[]Ðjh QeVbYt=E+PVYYt+@$ЃE E3=ËeE3IÐP
Q%Uuuuuhh`]ËU(a
aaa5a=aa
aaa%a-aaEaEaEa(aa``	```jhPRh	@PÐ`(a%%t%X% pS``SS``SS``SS``SS` `SS`0`Tdwmapi.dllCRYPT32.dlllogoncli.dllnetutils.dllWINSTA.dllWLDAP32.dlls(T<TLT`TxTTIX.CryptProtectDataDsGetDcNameWNetApiBufferFreeWinStationFreeMemorySWinStationQueryInformationWWinStationGetInitialApplicationUUVU$VU4@VUPtVtU|VhUVXUKERNEL32.dllmsvcrt.dllUSERENV.dllUSER32.dllAPI-MS-Win-Core-ProcessThreads-L1-1-0.dllAPI-MS-Win-Core-LocalRegistry-L1-1-0.dllntdll.dllWWWWWWWWXX"X6XJX^XnXXXXXXXXXYY,Y@YPYbYzYYYYYYYYYYYYZZ$Z6ZJZdZrZZZZZZZ[[0[N[`[v[[[[[[[\$\<\N\f\|\\\\\\\\]]0]>]T]f]v]]]]]]] DbgPrintRtlInitUnicodeStringZNtOpenKeyNtCloseRegCreateKeyExWRegDeleteTreeW%RegSetValueExWRegQueryValueExWRegOpenKeyExWRegCloseKeyRegQueryInfoKeyW$SetThreadPriorityGetCurrentThreadCreateThread
GetCurrentProcessCreateProcessWOpenProcessToken1CharNextW>GetKeyboardLayout~GetSystemMetricsExitWindowsExMessageBoxWLoadStringWLoadRemoteFontsDefWindowProcWMRegisterClassExWDestroyWindownCreateWindowExWSystemParametersInfoW_ismbbleadj_XcptFilterb_exit_cexitexit_wcsicmpmemsetmemmove_vsnwprintf_initterm_acmdln_amsg_exit__setusermatherr__p__fmode__set_app_type7?terminate@@YAXXZY_except_handler4_common'_controlfp__getmainargs__p__commodewGetSystemTimeAsFileTimeTerminateProcessUnhandledExceptionFilterGetCurrentProcessIdGetTickCountQueryPerformanceCounterGetModuleHandleASetUnhandledExceptionFilter`GetStartupInfoAInterlockedExchange;LoadLibraryARegOpenKeyExARegQueryValueExAExpandEnvironmentStringsA<LoadLibraryExAInterlockedCompareExchangeDelayLoadFailureHookHeapSetInformationISetCurrentDirectoryW]FormatMessageWGetFileAttributesExWnGetSystemDirectoryWnSetLastErrorExpandEnvironmentStringsWGetUserDefaultLangIDUSetEventsOpenEventWSleepWaitForSingleObjectRCloseHandleGetLastErrorSSetEnvironmentVariableWSearchPathWGetCurrentThreadId`CompareFileTime>LoadLibraryWBGetProcAddressaFreeLibraryGetEnvironmentVariableWCLocalAllocGLocalFreeGetVersionExWJlstrlenW8L%$^$R8L5~
 ^ R~RSDSRo&=CrX&userinit.pdb+}O0OvOSOOOOOOOON@DTempPageFileSystem\CurrentControlSet\Control\Session Manager\Memory Management4G(GlG(@Xp			vspMUI<?xml version="1.0" encoding="UTF-8" standalone="yes"?>
<!-- Copyright (c) Microsoft Corporation -->
<assembly xmlns="urn:schemas-microsoft-com:asm.v1" manifestVersion="1.0">

<description>Userinit Logon Application</description>

<trustInfo xmlns="urn:schemas-microsoft-com:asm.v3">
    <security>
        <requestedPrivileges>
            <requestedExecutionLevel
                level="asInvoker"
                uiAccess="false"
            />
        </requestedPrivileges>
    </security>
</trustInfo>
</assembly>

4VS_VERSION_INFOjDjD?StringFileInfo040904B0LCompanyNameMicrosoft Corporation^FileDescriptionUserinit Logon Applicationr)FileVersion6.1.7601.17514 (win7sp1_rtm.101119-1850)2	InternalNameuserinit.LegalCopyright Microsoft Corporation. All rights reserved.B
OriginalFilenameUSERINIT.EXEj%ProductNameMicrosoft Windows Operating SystemBProductVersion6.1.7601.17514DVarFileInfo$Translation	O.6$GGcL.Eqm.MUIMUIen-US11112 2)2G2n2v22222222223=3Q3X3y3333333415;5A5O5U5555555z66=7T7_77777g8w8~88888889$9Z9`9i9w9999999::::::
;;0;o;;%<V<\<k<<=y?~?????? 0.0H00,1I1U123
444I4T4~44444455E5|56#68666k777788*8>8[8`8s8888888;9K9x99999999w:|:::::::::::::";I;U;];e;q;;;;;;;<$<.<><K<Y<^<c<w<<<<<<<<<<<= =(=,===H=N===========>>&>=>R>^>|>>>>>>/?O?t???0000\1`11112d2y2222222223#393V3g33334444555"5'555E555	6R666667:7E7f7o7778858@8V8f8o888888 9A9^99999:.:f::::::;;;:<U<r<<<<<====>+>J>m>?!???[????@c000
1 1S1l1111)4/4>4E4R4444456"6p6v66666667777'8_8y8888899%919:9@9K9R9h999:.:<:W:`:::L;V;c;j;;;;;<*<0<r<y<<<<<8=[=f====a>l>>>>>>>>>>>?#?1?;?O?T?^?r?w???????????P`0$0004181C1^1c1}11111111111111111111222*2/252@2G2P2T2_2j2u22`(0000 0$0(0004080<0@0D0444

Anon7 - 2022
AnonSec Team