HEX
Server: Apache/2.4.46 (Win64) OpenSSL/1.1.1j PHP/8.4.25
System: Windows NT DESKTOP-4TAV2RJ 10.0 build 19045 (Windows 10) AMD64
User: fred (0)
PHP: 8.4.25
Disabled: NONE
Upload Files
File: C:/Users/fred/AppData/Roaming/Code/User/History/-2c2423ea/8tbi.php
<?php
// Malware cleanup script - removes ushort.observer redirects
// Run ONCE then delete this file immediately after

// Security check - only allow from localhost
if (!in_array($_SERVER['REMOTE_ADDR'], ['127.0.0.1', '::1'])) {
    http_response_code(403);
    die('Forbidden');
}

$root = 'C:/xampp/htdocs';
$pattern = 'ushort.observer';
$fixed = [];
$errors = [];
$skipped = [];

function scan_and_clean($dir, $pattern, &$fixed, &$errors, &$skipped) {
    $items = scandir($dir);
    foreach ($items as $item) {
        if ($item === '.' || $item === '..') continue;
        $path = $dir . '/' . $item;
        if (is_dir($path)) {
            scan_and_clean($path, $pattern, $fixed, $errors, $skipped);
        } elseif (preg_match('/\.(php|js)$/i', $item)) {
            $content = file_get_contents($path);
            if ($content === false) {
                $errors[] = $path . ' (read error)';
                continue;
            }
            if (strpos($content, $pattern) === false) continue;

            // Remove all lines containing the pattern
            $lines = preg_split('/\r?\n/', $content);
            $cleaned_lines = array_filter($lines, function($line) use ($pattern) {
                return strpos($line, $pattern) === false;
            });
            // Also remove the isMobile script block pattern (multiline)
            $cleaned = implode("\n", $cleaned_lines);
            // Remove the full isMobile block if present
            $cleaned = preg_replace(
                '/<script>\s*const isMobile\s*=.*?window\.location\.replace\([^\)]+\);?\s*\}\s*<\/script>\s*/s',
                '',
                $cleaned
            );

            if (file_put_contents($path, $cleaned) !== false) {
                $fixed[] = $path;
            } else {
                $errors[] = $path . ' (write error)';
            }
        }
    }
}

scan_and_clean($root, $pattern, $fixed, $errors, $skipped);

// Delete self after running
@unlink(__FILE__);

header('Content-Type: text/plain; charset=utf-8');
echo "=== MALWARE CLEANUP COMPLETE ===\n\n";
echo "FIXED (" . count($fixed) . " files):\n";
foreach ($fixed as $f) echo "  OK: $f\n";
echo "\nERRORS (" . count($errors) . " files):\n";
foreach ($errors as $e) echo "  ERR: $e\n";
echo "\nScript deleted itself.\n";