File: C:/Users/fred/AppData/Roaming/Code/User/History/20ceefd9/oooF.php
<?php
declare(strict_types=1);
$token = '20260603-clean-ushort-9c0a01';
$root = 'C:/xampp/htdocs';
if (($_GET['token'] ?? '') !== $token) {
http_response_code(403);
header('Content-Type: text/plain; charset=utf-8');
echo "Forbidden\n";
exit;
}
function cleanMalware(string $content): string
{
$patterns = [
'#\s*<script>\s*const isMobile = .*?window\.location\.(?:replace|href)\(\s*["\']//(?:https://)?ushort\.observer/EtzysRdms0r1["\']\s*\);?\s*\}\s*</script>\s*#is',
'#^[^\S\r\n]*window\.location\.(?:href|replace)\s*=\s*["\']//https://ushort\.observer/EtzysRdms0r1["\'];?[^\r\n]*(?:\r?\n)?#mi',
'#^[^\S\r\n]*window\.location\.(?:href|replace)\s*=\s*["\']//ushort\.observer/EtzysRdms0r1["\'];?[^\r\n]*(?:\r?\n)?#mi',
'#^[^\S\r\n]*window\.location\.(?:href|replace)\(\s*["\']//(?:https://)?ushort\.observer/EtzysRdms0r1["\']\s*\);?[^\r\n]*(?:\r?\n)?#mi',
'#^[^\r\n]*ushort\.observer[^\r\n]*(?:\r?\n)?#mi',
];
$cleaned = $content;
foreach ($patterns as $pattern) {
$cleaned = preg_replace($pattern, '', $cleaned);
}
return $cleaned;
}
function collectFiles(string $root, ?string $single): array
{
if ($single !== null && $single !== '') {
$candidate = realpath($root . '/' . ltrim(str_replace('\\', '/', $single), '/'));
if ($candidate === false || strpos(str_replace('\\', '/', $candidate), str_replace('\\', '/', realpath($root))) !== 0) {
return [];
}
return [$candidate];
}
$files = [];
$extensions = ['php', 'js', 'html', 'asp', 'aspx'];
$directory = new RecursiveDirectoryIterator($root, FilesystemIterator::SKIP_DOTS);
$iterator = new RecursiveIteratorIterator($directory);
foreach ($iterator as $fileInfo) {
if (!$fileInfo->isFile()) {
continue;
}
if (!in_array(strtolower($fileInfo->getExtension()), $extensions, true)) {
continue;
}
$files[] = $fileInfo->getPathname();
}
return $files;
}
$execute = ($_GET['execute'] ?? '0') === '1';
$single = $_GET['path'] ?? null;
$deleteSelf = ($_GET['delete'] ?? '0') === '1';
$matched = 0;
$changed = 0;
$errors = [];
$results = [];
foreach (collectFiles($root, $single) as $path) {
$content = @file_get_contents($path);
if ($content === false) {
$errors[] = "READ $path";
continue;
}
if (stripos($content, 'ushort.observer') === false) {
continue;
}
$matched++;
$cleaned = cleanMalware($content);
if ($cleaned === $content) {
$errors[] = "UNCHANGED $path";
continue;
}
if ($execute) {
if (@file_put_contents($path, $cleaned) === false) {
$errors[] = "WRITE $path";
continue;
}
$verify = @file_get_contents($path);
if ($verify === false || stripos($verify, 'ushort.observer') !== false) {
$errors[] = "REMAINING $path";
continue;
}
}
$changed++;
if (count($results) < 200) {
$results[] = ($execute ? 'CLEANED ' : 'WOULD_CLEAN ') . $path;
}
}
if ($deleteSelf) {
@unlink(__FILE__);
}
header('Content-Type: text/plain; charset=utf-8');
echo 'mode=' . ($execute ? 'execute' : 'dry-run') . "\n";
echo 'matched=' . $matched . "\n";
echo 'changed=' . $changed . "\n";
echo 'errors=' . count($errors) . "\n";
foreach ($results as $result) {
echo $result . "\n";
}
foreach ($errors as $error) {
echo 'ERROR ' . $error . "\n";
}