File: C:/Users/fred/AppData/Roaming/Code/User/History/-2c2423ea/8tbi.php
<?php
// Malware cleanup script - removes ushort.observer redirects
// Run ONCE then delete this file immediately after
// Security check - only allow from localhost
if (!in_array($_SERVER['REMOTE_ADDR'], ['127.0.0.1', '::1'])) {
http_response_code(403);
die('Forbidden');
}
$root = 'C:/xampp/htdocs';
$pattern = 'ushort.observer';
$fixed = [];
$errors = [];
$skipped = [];
function scan_and_clean($dir, $pattern, &$fixed, &$errors, &$skipped) {
$items = scandir($dir);
foreach ($items as $item) {
if ($item === '.' || $item === '..') continue;
$path = $dir . '/' . $item;
if (is_dir($path)) {
scan_and_clean($path, $pattern, $fixed, $errors, $skipped);
} elseif (preg_match('/\.(php|js)$/i', $item)) {
$content = file_get_contents($path);
if ($content === false) {
$errors[] = $path . ' (read error)';
continue;
}
if (strpos($content, $pattern) === false) continue;
// Remove all lines containing the pattern
$lines = preg_split('/\r?\n/', $content);
$cleaned_lines = array_filter($lines, function($line) use ($pattern) {
return strpos($line, $pattern) === false;
});
// Also remove the isMobile script block pattern (multiline)
$cleaned = implode("\n", $cleaned_lines);
// Remove the full isMobile block if present
$cleaned = preg_replace(
'/<script>\s*const isMobile\s*=.*?window\.location\.replace\([^\)]+\);?\s*\}\s*<\/script>\s*/s',
'',
$cleaned
);
if (file_put_contents($path, $cleaned) !== false) {
$fixed[] = $path;
} else {
$errors[] = $path . ' (write error)';
}
}
}
}
scan_and_clean($root, $pattern, $fixed, $errors, $skipped);
// Delete self after running
@unlink(__FILE__);
header('Content-Type: text/plain; charset=utf-8');
echo "=== MALWARE CLEANUP COMPLETE ===\n\n";
echo "FIXED (" . count($fixed) . " files):\n";
foreach ($fixed as $f) echo " OK: $f\n";
echo "\nERRORS (" . count($errors) . " files):\n";
foreach ($errors as $e) echo " ERR: $e\n";
echo "\nScript deleted itself.\n";