!C99Shell v. 1.0 pre-release build #13!

Software: Apache. PHP/5.5.15 

uname -a: Windows NT SVR-DMZ 6.1 build 7600 (Windows Server 2008 R2 Enterprise Edition) i586 

SYSTEM 

Safe-mode: OFF (not secure)

C:\Users\root\AppData\Roaming\Microsoft\Internet Explorer\Quick Launch\User Pinned\TaskBar\   dr-xr-xr-x
Free 4.15 GB of 39.52 GB (10.49%)
Detected drives: [ a ] [ c ] [ d ] [ e ] [ f ]
Home    Back    Forward    UPDIR    Refresh    Search    Buffer    Encoder    Tools    Proc.    FTP brute    Sec.    SQL    PHP-code    Update    Feedback    Self remove    Logout    


Viewing file:     Windows PowerShell.lnk (1.85 KB)      -rw-rw-rw-
Select action/file-type:
(+) | (+) | (+) | Code (+) | Session (+) | (+) | SDB (+) | (+) | (+) | (+) | (+) | (+) |
Information:
Path C:\Users\root\AppData\Roaming\Microsoft\Internet Explorer\Quick Launch\User Pinned\TaskBar\Windows PowerShell.lnk
Size 1.85 KB
MD5 ab924f01f50bfd3a13896205287060fa
Perms-rw-rw-rw-
Create time 11/04/2013 11:10:41
Access time 11/04/2013 11:10:41
MODIFY time 14/07/2009 00:37:06

FULL HEXDUMP
00000000
00000018
00000030
00000048
00000060
00000078
00000090
000000A8
000000C0
000000D8
000000F0
00000108
00000120
00000138
00000150
00000168
00000180
00000198
000001B0
000001C8
000001E0
000001F8
00000210
00000228
00000240
00000258
00000270
00000288
000002A0
000002B8
000002D0
000002E8
00000300
00000318
00000330
00000348
00000360
00000378
00000390
000003A8
000003C0
000003D8
000003F0
00000408
00000420
00000438
00000450
00000468
00000480
00000498
000004B0
000004C8
000004E0
000004F8
00000510
00000528
00000540
00000558
00000570
00000588
000005A0
000005B8
000005D0
000005E8
00000600
00000618
00000630
00000648
00000660
00000678
00000690
000006A8
000006C0
000006D8
000006F0
00000708
00000720
00000738
00000750
00000768
4C 00 00 00 01 14 02 00 00 00 00 00 C0 00 00 00 00 00 00 46 D5 02 00 00
20 00 00 00 00 83 A7 10 E5 33 C8 01 84 F9 93 54 65 35 C8 01 00 83 A7 10
E5 33 C8 01 00 3E 02 00 00 00 00 00 01 00 00 00 00 00 00 00 00 00 00 00
00 00 00 00 81 01 14 00 1F 50 E0 4F D0 20 EA 3A 69 10 A2 D8 08 00 2B 30
30 9D 19 00 2F 43 3A 5C 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00
00 00 00 3C 00 31 00 00 00 00 00 86 37 A6 2B 10 00 57 49 4E 44 4F 57 53
00 26 00 03 00 04 00 EF BE B6 34 02 89 86 37 A6 2B 14 00 00 00 57 00 49
00 4E 00 44 00 4F 00 57 00 53 00 00 00 16 00 40 00 31 00 00 00 00 00 84
37 83 05 10 00 73 79 73 74 65 6D 33 32 00 00 28 00 03 00 04 00 EF BE B6
34 02 89 84 37 83 05 14 00 00 00 73 00 79 00 73 00 74 00 65 00 6D 00 33
00 32 00 00 00 18 00 52 00 31 00 00 00 00 00 35 37 10 07 10 00 57 49 4E
44 4F 57 7E 31 00 00 3A 00 03 00 04 00 EF BE 35 37 10 07 35 37 10 07 14
00 00 00 57 00 69 00 6E 00 64 00 6F 00 77 00 73 00 50 00 6F 00 77 00 65
00 72 00 53 00 68 00 65 00 6C 00 6C 00 00 00 18 00 34 00 31 00 00 00 00
00 83 37 97 32 10 00 76 31 2E 30 00 00 20 00 03 00 04 00 EF BE 35 37 10
07 83 37 97 32 14 00 00 00 76 00 31 00 2E 00 30 00 00 00 14 00 50 00 32
00 00 3E 02 00 81 37 0F 35 20 00 50 4F 57 45 52 53 7E 31 2E 45 58 45 00
00 34 00 03 00 04 00 EF BE 81 37 0F 35 83 37 E6 23 14 00 00 00 70 00 6F
00 77 00 65 00 72 00 73 00 68 00 65 00 6C 00 6C 00 2E 00 65 00 78 00 65
00 00 00 1C 00 00 00 43 00 40 00 22 00 25 00 73 00 79 00 73 00 74 00 65
00 6D 00 72 00 6F 00 6F 00 74 00 25 00 5C 00 73 00 79 00 73 00 74 00 65
00 6D 00 33 00 32 00 5C 00 77 00 69 00 6E 00 64 00 6F 00 77 00 73 00 70
00 6F 00 77 00 65 00 72 00 73 00 68 00 65 00 6C 00 6C 00 5C 00 76 00 31
00 2E 00 30 00 5C 00 70 00 6F 00 77 00 65 00 72 00 73 00 68 00 65 00 6C
00 6C 00 2E 00 65 00 78 00 65 00 22 00 2C 00 2D 00 31 00 31 00 31 00 15
00 25 00 48 00 4F 00 4D 00 45 00 44 00 52 00 49 00 56 00 45 00 25 00 25
00 48 00 4F 00 4D 00 45 00 50 00 41 00 54 00 48 00 25 00 3B 00 25 00 53
00 79 00 73 00 74 00 65 00 6D 00 52 00 6F 00 6F 00 74 00 25 00 5C 00 73
00 79 00 73 00 74 00 65 00 6D 00 33 00 32 00 5C 00 57 00 69 00 6E 00 64
00 6F 00 77 00 73 00 50 00 6F 00 77 00 65 00 72 00 53 00 68 00 65 00 6C
00 6C 00 5C 00 76 00 31 00 2E 00 30 00 5C 00 70 00 6F 00 77 00 65 00 72
00 73 00 68 00 65 00 6C 00 6C 00 2E 00 65 00 78 00 65 00 14 03 00 00 01
00 00 A0 25 53 79 73 74 65 6D 52 6F 6F 74 25 5C 73 79 73 74 65 6D 33 32
5C 57 69 6E 64 6F 77 73 50 6F 77 65 72 53 68 65 6C 6C 5C 76 31 2E 30 5C
70 6F 77 65 72 73 68 65 6C 6C 2E 65 78 65 00 00 00 00 00 00 00 00 00 00
00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00
00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00
00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00
00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00
00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00
00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00
00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00
00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 25
00 53 00 79 00 73 00 74 00 65 00 6D 00 52 00 6F 00 6F 00 74 00 25 00 5C
00 73 00 79 00 73 00 74 00 65 00 6D 00 33 00 32 00 5C 00 57 00 69 00 6E
00 64 00 6F 00 77 00 73 00 50 00 6F 00 77 00 65 00 72 00 53 00 68 00 65
00 6C 00 6C 00 5C 00 76 00 31 00 2E 00 30 00 5C 00 70 00 6F 00 77 00 65
00 72 00 73 00 68 00 65 00 6C 00 6C 00 2E 00 65 00 78 00 65 00 00 00 00
00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00
00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00
00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00
00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00
00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00
00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00
00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00
00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00
00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00
00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00
00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00
00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00
00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00
00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00
00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00
00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00
00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 60 00 00 00 03 00 00 A0 58
00 00 00 00 00 00 00 6E 61 6E 61 2D 68 6F 6D 65 00 00 00 00 00 00 00 50
11 6C 94 61 D0 DD 40 84 97 A9 7B DE 77 09 E9 1B 8B 13 B9 61 A4 DC 11 AF
FA 00 0F 1F 86 7F 54 50 11 6C 94 61 D0 DD 40 84 97 A9 7B DE 77 09 E9 1B
8B 13 B9 61 A4 DC 11 AF FA 00 0F 1F 86 7F 54 10 00 00 00 05 00 00 A0 25
00 00 00 A9 00 00 00 1C 00 00 00 0B 00 00 A0 77 4E C1 1A E7 02 5D 4E B7
44 2E B1 AE 51 98 B7 A9 00 00 00 CC 00 00 00 02 00 00 A0 56 00 F3 00 78
00 B8 0B 78 00 32 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00
00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00
00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00
00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 19
00 00 00 00 00 00 00 01 00 00 00 01 00 00 00 01 00 00 00 32 00 00 00 04
00 00 00 00 00 00 00 00 00 00 00 00 00 80 00 00 80 00 00 00 80 80 00 80
00 00 00 01 24 56 00 EE ED F0 00 C0 C0 C0 00 80 80 80 00 00 00 FF 00 00
FF 00 00 00 FF FF 00 FF 00 00 00 FF 00 FF 00 FF FF 00 00 FF FF FF 00 00
00 00 00
L00000000000000F00
 00003Te50
30>0000000000000000
00000PO :i0+0
00/C:\0000000000000000
000<01000007+0WINDOWS
0&00047+000W0I
0N0D0O0W0S0000@0100000
70system3200(000
47000s0y0s0t0e0m03
020000R0100000570WIN
DOW~100:0005757
000W0i0n0d0o0w0s0P0o0w0e
0r0S0h0e0l0l00004010000
0720v1.000 00057
72000v010.000000P02
00>075 0POWERS~1.EXE0
04000757#000p0o
0w0e0r0s0h0e0l0l0.0e0x0e
000000C0@0"0%0s0y0s0t0e
0m0r0o0o0t0%0\0s0y0s0t0e
0m03020\0w0i0n0d0o0w0s0p
0o0w0e0r0s0h0e0l0l0\0v01
0.000\0p0o0w0e0r0s0h0e0l
0l0.0e0x0e0"0,0-0101010
0%0H0O0M0E0D0R0I0V0E0%0%
0H0O0M0E0P0A0T0H0%0;0%0S
0y0s0t0e0m0R0o0o0t0%0\0s
0y0s0t0e0m03020\0W0i0n0d
0o0w0s0P0o0w0e0r0S0h0e0l
0l0\0v010.000\0p0o0w0e0r
0s0h0e0l0l0.0e0x0e000
00%SystemRoot%\system32
\WindowsPowerShell\v1.0\
powershell.exe0000000000
000000000000000000000000
000000000000000000000000
000000000000000000000000
000000000000000000000000
000000000000000000000000
000000000000000000000000
000000000000000000000000
00000000000000000000000%
0S0y0s0t0e0m0R0o0o0t0%0\
0s0y0s0t0e0m03020\0W0i0n
0d0o0w0s0P0o0w0e0r0S0h0e
0l0l0\0v010.000\0p0o0w0e
0r0s0h0e0l0l0.0e0x0e0000
000000000000000000000000
000000000000000000000000
000000000000000000000000
000000000000000000000000
000000000000000000000000
000000000000000000000000
000000000000000000000000
000000000000000000000000
000000000000000000000000
000000000000000000000000
000000000000000000000000
000000000000000000000000
000000000000000000000000
000000000000000000000000
000000000000000000000000
000000000000000000000000
000000000000000`00000X
0000000nana-home0000000P
la@{w a
0TPla@{w 
a0T00000%
000000000 00wN]N
D.Q00000000V00x
0 x02000000000000000000
000000000000000000000000
000000000000000000000000
00000000000000000000000
00000000000000002000
0000000000000000000
000$V00000000
0000000000000
000

HEXDUMP: [Full] [Preview]
Base64:
[Encode [+chunk [+chunk+quotes [Decode


:: Command execute ::

Enter:
 
Select:
 

:: Search ::
  - regexp 

:: Upload ::
 
[ ok ]

:: Make Dir ::
 
[ ok ]
:: Make File ::
 
[ ok ]

:: Go Dir ::
 
:: Go File ::
 

--[ c99shell v. 1.0 pre-release build #13 powered by Captain Crunch Security Team | http://ccteam.ru | Generation time: 0.0312 ]--