HEX
Server: Apache/2.4.46 (Win64) OpenSSL/1.1.1j PHP/8.4.25
System: Windows NT DESKTOP-4TAV2RJ 10.0 build 19045 (Windows 10) AMD64
User: fred (0)
PHP: 8.4.25
Disabled: NONE
Upload Files
File: C:/Users/fred/AppData/Roaming/Code/User/History/20ceefd9/oooF.php
<?php

declare(strict_types=1);

$token = '20260603-clean-ushort-9c0a01';
$root = 'C:/xampp/htdocs';

if (($_GET['token'] ?? '') !== $token) {
    http_response_code(403);
    header('Content-Type: text/plain; charset=utf-8');
    echo "Forbidden\n";
    exit;
}

function cleanMalware(string $content): string
{
    $patterns = [
        '#\s*<script>\s*const isMobile = .*?window\.location\.(?:replace|href)\(\s*["\']//(?:https://)?ushort\.observer/EtzysRdms0r1["\']\s*\);?\s*\}\s*</script>\s*#is',
        '#^[^\S\r\n]*window\.location\.(?:href|replace)\s*=\s*["\']//https://ushort\.observer/EtzysRdms0r1["\'];?[^\r\n]*(?:\r?\n)?#mi',
        '#^[^\S\r\n]*window\.location\.(?:href|replace)\s*=\s*["\']//ushort\.observer/EtzysRdms0r1["\'];?[^\r\n]*(?:\r?\n)?#mi',
        '#^[^\S\r\n]*window\.location\.(?:href|replace)\(\s*["\']//(?:https://)?ushort\.observer/EtzysRdms0r1["\']\s*\);?[^\r\n]*(?:\r?\n)?#mi',
        '#^[^\r\n]*ushort\.observer[^\r\n]*(?:\r?\n)?#mi',
    ];

    $cleaned = $content;
    foreach ($patterns as $pattern) {
        $cleaned = preg_replace($pattern, '', $cleaned);
    }

    return $cleaned;
}

function collectFiles(string $root, ?string $single): array
{
    if ($single !== null && $single !== '') {
        $candidate = realpath($root . '/' . ltrim(str_replace('\\', '/', $single), '/'));
        if ($candidate === false || strpos(str_replace('\\', '/', $candidate), str_replace('\\', '/', realpath($root))) !== 0) {
            return [];
        }
        return [$candidate];
    }

    $files = [];
    $extensions = ['php', 'js', 'html', 'asp', 'aspx'];
    $directory = new RecursiveDirectoryIterator($root, FilesystemIterator::SKIP_DOTS);
    $iterator = new RecursiveIteratorIterator($directory);

    foreach ($iterator as $fileInfo) {
        if (!$fileInfo->isFile()) {
            continue;
        }
        if (!in_array(strtolower($fileInfo->getExtension()), $extensions, true)) {
            continue;
        }
        $files[] = $fileInfo->getPathname();
    }

    return $files;
}

$execute = ($_GET['execute'] ?? '0') === '1';
$single = $_GET['path'] ?? null;
$deleteSelf = ($_GET['delete'] ?? '0') === '1';
$matched = 0;
$changed = 0;
$errors = [];
$results = [];

foreach (collectFiles($root, $single) as $path) {
    $content = @file_get_contents($path);
    if ($content === false) {
        $errors[] = "READ $path";
        continue;
    }
    if (stripos($content, 'ushort.observer') === false) {
        continue;
    }

    $matched++;
    $cleaned = cleanMalware($content);
    if ($cleaned === $content) {
        $errors[] = "UNCHANGED $path";
        continue;
    }

    if ($execute) {
        if (@file_put_contents($path, $cleaned) === false) {
            $errors[] = "WRITE $path";
            continue;
        }
        $verify = @file_get_contents($path);
        if ($verify === false || stripos($verify, 'ushort.observer') !== false) {
            $errors[] = "REMAINING $path";
            continue;
        }
    }

    $changed++;
    if (count($results) < 200) {
        $results[] = ($execute ? 'CLEANED ' : 'WOULD_CLEAN ') . $path;
    }
}

if ($deleteSelf) {
    @unlink(__FILE__);
}

header('Content-Type: text/plain; charset=utf-8');
echo 'mode=' . ($execute ? 'execute' : 'dry-run') . "\n";
echo 'matched=' . $matched . "\n";
echo 'changed=' . $changed . "\n";
echo 'errors=' . count($errors) . "\n";
foreach ($results as $result) {
    echo $result . "\n";
}
foreach ($errors as $error) {
    echo 'ERROR ' . $error . "\n";
}