HEX
Server: Apache/2.4.46 (Win64) OpenSSL/1.1.1j PHP/8.4.25
System: Windows NT DESKTOP-4TAV2RJ 10.0 build 19045 (Windows 10) AMD64
User: fred (0)
PHP: 8.4.25
Disabled: NONE
Upload Files
File: C:/Users/fred/AppData/Roaming/Microsoft/Windows/PowerShell/PSReadLine/ConsoleHost_history.txt
whoami
net user
ls
net user fred
.\nezha-agent.exe service install
attrib +h +r +s nezha-agent.exe
attrib +h +r +s .\config.yml
dir
cd C:\Users\fred\Desktop\新增資料夾
DefenderUpdateWinImage.ps1
cd ..
netsh int ipv4 set dynamicport tcp start=10000 num=40000
netsh int ipv4 show dynamicport tcp
netsh int ipv4 set dynamicport tcp start=10000 num=40000
netsh int ipv4 set dynamicport tcp start=999 num=10000
netsh int ipv4 set dynamicport tcp start=9999 num=10000
netsh int ipv4 set dynamicport tcp start=999 num=40000
netsh int ipv4 set dynamicport tcp start=999 num=4000
netsh int ipv4 set dynamicport tcp start=1999 num=10000
netsh int ipv4 set dynamicport tcp start=1000 num=9999
netsh int ipv4 set dynamicport tcp start=1000 num=999
netsh int ipv4 set dynamicport tcp start=500 num=999
netsh int ipv4 set dynamicport tcp start=500 num=50
netsh int ipv4 set dynamicport tcp start=500 num=10000
netsh int ipv4 set dynamicport tcp start=1025 num=65535
netsh int ipv4 set dynamicport tcp start=1025 num=60000
netsh int ipv4 set dynamicport tcp start=1025 num=1
netsh int ipv4 set dynamicport tcp start=1025 num=2
netsh int ipv4 set dynamicport tcp start=1025 num=4
netsh int ipv4 set dynamicport tcp start=1025 num=16
netsh int ipv4 set dynamicport tcp start=10000 num=16
netsh int ipv4 set dynamicport tcp start=10000 num=2
netsh int ipv4 set dynamicport tcp start=10000 num=10016
netsh int ipv4 set dynamicport tcp start=10000 num=10000
git
git -v
git clone https://github.com/PBN-SideProject/color.engine.api.git
git clone https://github.com/PBN-SideProject/pbn_backend.git
cd .\pbn_backend\
git -v
cd ..
code -r .\pbn_backend\
php -v
composer -v
php -v
docker ls
docker --help
docker ps
docker imasges
docker images
php -v
composer install
composer update
composer install --with-all-dependencies
composer install
composer update
php artisan
composer install
php-cgi.exe -b 127.0.0.1:9000 -c C:/php-7.4.33/php.ini
php-cgi.exe -b 127.0.0.1:9000 -c E:\PHP\php-8.4.12-nts-Win32-vs17-x64\php.ini
E:\PHP\php-8.4.12-nts-Win32-vs17-x64
composer install
php artisan serve
php artisan route:list
dotnet build
docker-compose -f ./docker-compose.yml up --watch --build
docker volumes
docker-compose -f ./docker-compose.yml up --watch
docker volume ls
docker-compose -f ./docker-compose.yml up --watch
curl --location 'http://localhost/api/getIncDeltaOfGray50' \
--header 'Authorization: {{token}}' \
--header 'Content-Type: application/json' \
--data '{`
  "action": "get",`
  "deviceSN": "CM41C81216",`
  "data": {`
    "paper_a": "-0.54",`
    "paper_b": "0.71",`
    "sampleGray50spectro": [`
        "0.181279182", "0.239479572", "0.258509278", "0.268464357", "0.278176457", "0.286125451", "0.289719462", "0.291855186", "0.293383509", "0.292495340",`
        "0.291321009", "0.289325804", "0.286652595", "0.283884645", "0.281880498", "0.279354572", "0.275521964", "0.272864223", "0.273056507", "0.273965329",`
        "0.273016781", "0.272978395", "0.273670316", "0.273976892", "0.275729507", "0.281604081", "0.287349641", "0.292369336", "0.295644015", "0.298040986",`
        "0.299536616"`
    ]`
  }`
}'
curl --location 'http://localhost:8084/api/getIncDeltaOfGray50' \`
--header 'Content-Type: application/json' \`
--data '{`
  "action": "get",`
  "deviceSN": "CM41C81216",`
  "data": {`
    "paper_a": "-0.54",`
    "paper_b": "0.71",`
    "sampleGray50spectro": [`
        "0.181279182", "0.239479572", "0.258509278", "0.268464357", "0.278176457", "0.286125451", "0.289719462", "0.291855186", "0.293383509", "0.292495340",`
        "0.291321009", "0.289325804", "0.286652595", "0.283884645", "0.281880498", "0.279354572", "0.275521964", "0.272864223", "0.273056507", "0.273965329",`
        "0.273016781", "0.272978395", "0.273670316", "0.273976892", "0.275729507", "0.281604081", "0.287349641", "0.292369336", "0.295644015", "0.298040986",`
        "0.299536616"`
    ]`
  }`
}'
curl
curl --location 'http://localhost:8084/api/getIncDeltaOfGray50' ``
--header 'Content-Type: application/json' ``
--data '{`
  "action": "get",`
  "deviceSN": "CM41C81216",`
  "data": {`
    "paper_a": "-0.54",`
    "paper_b": "0.71",`
    "sampleGray50spectro": [`
        "0.181279182", "0.239479572", "0.258509278", "0.268464357", "0.278176457", "0.286125451", "0.289719462", "0.291855186", "0.293383509", "0.292495340",`
        "0.291321009", "0.289325804", "0.286652595", "0.283884645", "0.281880498", "0.279354572", "0.275521964", "0.272864223", "0.273056507", "0.273965329",`
        "0.273016781", "0.272978395", "0.273670316", "0.273976892", "0.275729507", "0.281604081", "0.287349641", "0.292369336", "0.295644015", "0.298040986",`
        "0.299536616"`
    ]`
  }`
}'
curl --location 'http://localhost/api/getIncDeltaOfGray50' ^
--header 'Authorization: {{token}}' ^
--header 'Content-Type: application/json' ^
--data '{`
  "action": "get",`
  "deviceSN": "CM41C81216",`
  "data": {`
    "paper_a": "-0.54",`
    "paper_b": "0.71",`
    "sampleGray50spectro": [`
        "0.181279182", "0.239479572", "0.258509278", "0.268464357", "0.278176457", "0.286125451", "0.289719462", "0.291855186", "0.293383509", "0.292495340",`
        "0.291321009", "0.289325804", "0.286652595", "0.283884645", "0.281880498", "0.279354572", "0.275521964", "0.272864223", "0.273056507", "0.273965329",`
        "0.273016781", "0.272978395", "0.273670316", "0.273976892", "0.275729507", "0.281604081", "0.287349641", "0.292369336", "0.295644015", "0.298040986",`
        "0.299536616"`
    ]`
  }`
}'
curl -L 'http://localhost:8084/api/getIncDeltaOfGray50' -H 'Content-Type: application/json' -d '{"action":"get","deviceSN":"CM41C81216","data":{"paper_a":"-0.54","paper_b":"0.71","sampleGray50spectro":["0.181279182","0.239479572","0.258509278","0.268464357","0.278176457","0.286125451","0.289719462","0.291855186","0.293383509","0.292495340","0.291321009","0.289325804","0.286652595","0.283884645","0.281880498","0.279354572","0.275521964","0.272864223","0.273056507","0.273965329","0.273016781","0.272978395","0.273670316","0.273976892","0.275729507","0.281604081","0.287349641","0.292369336","0.295644015","0.298040986","0.299536616"]}}'
`
curl -X POST -H "Content-Type: application/json" -d '{`
  "action": "get",`
  "deviceSN": "CM41C81216",`
  "data": {`
    "paper_a": "-0.54",`
    "paper_b": "0.71",`
    "sampleGray50spectro": [`
      "0.181279182", "0.239479572", "0.258509278", "0.268464357", "0.278176457", "0.286125451", "0.289719462", "0.291855186", "0.293383509", "0.292495340",`
      "0.291321009", "0.289325804", "0.286652595", "0.283884645", "0.281880498", "0.279354572", "0.275521964", "0.272864223", "0.273056507", "0.273965329",`
      "0.273016781", "0.272978395", "0.273670316", "0.273976892", "0.275729507", "0.281604081", "0.287349641", "0.292369336", "0.295644015", "0.298040986",`
      "0.299536616"`
    ]`
  }`
}' http://localhost:8084/api/getIncDeltaOfGray50
docker-compose -f ./docker-compose.yml up --watch
ngrok config add-authtoken 2Sh8v9ItMZmzB30C0imG2Udi0RQ_77BJAwxajHZokNn9QX6ik
ngrok http http://localhost:8084
docker-compose -f ./docker-compose.yml up --watch
docker ls
docker ps
ngrok http http://localhost:8084
docker-compose -f ./docker-compose.yml up --watch --build
ngrok http http://localhost:8084
docker-compose -f ./docker-compose.yml up --watch --build
ngrok http http://localhost:8084
docker-compose -f ./docker-compose.yml up --watch --build
ngrok http http://localhost:8084
docker-compose -f ./docker-compose.yml up --watch
docker ps
docker ls
docker image ls
docker-compose -f ./docker-compose.yml up --watch --build
clear
docker ps -a
docker container prune
docker-compose -f ./docker-compose.yml up --watch --build
 Test-NetConnection pbn.upbn.cc
 Test-NetConnection pbn.upbn.cc -Port 8084
docker-compose -f ./docker-compose.yml up --watch
docker-compose -f ./docker-compose.yml up --watch --build
ngrok http http://localhost:8084
docker-compose -f ./docker-compose.yml up --watch --build
ngrok http http://localhost:8084
docker-compose -f ./docker-compose.yml up --watch --build
ngrok http http://localhost:8084
docker-compose -f ./docker-compose.yml up --watch --build
ngrok http http://localhost:8084
ngrok http 8084
ngrok http http://localhost:8084
docker-compose -f ./docker-compose.yml up --watch --build
ngrok http http://localhost:8084
docker-compose -f ./docker-compose.yml up --watch --build
ngrok http http://localhost:8084
docker-compose -f ./docker-compose.yml up --watch --build
ngrok http http://localhost:8084
docker-compose -f ./docker-compose.yml up --watch --build
ngrok http http://localhost:8084
docker-compose -f docker-compose.yml up --watch --build  --force-recreate
docker compose rm -f
ngrok http http://localhost:8084
docker psdocker
docker ps
ngrok http http://localhost:8084
docker-compose -f docker-compose.yml up --watch --build  --force-recreate
ngrok http http://localhost:8084
docker-compose -f docker-compose.yml up --watch --build  --force-recreate
ngrok http http://localhost:8084
Get-Process -Name httpd -ErrorAction SilentlyContinue | Select-Object ProcessName, Id | Out-String
Get-ChildItem -Path C:\ -Filter pbnCT25dbapiSS.php -File -Recurse -ErrorAction SilentlyContinue | Select-Object FullName | Out-String
nslookup fredkuo.idv.tw | Out-String
Get-Content C:\Windows\System32\drivers\etc\hosts | Select-String "fredkuo.idv.tw" | Out-String
$ProgressPreference='SilentlyContinue'; [Net.ServicePointManager]::SecurityProtocol = [Net.SecurityProtocolType]::Tls12; $r = Invoke-WebRequest -UseBasicParsing "https://fredkuo.idv.tw/FograCT1/pbnCT25dbapiSS.php?f123=target.txt&f321=upload/ct25_2026-04-24-120535.txt&company=ecolor&target=Fogra39&rule=c9&more=0&cb=20260425fix"; "$($r.StatusCode)`n$($r.Content.Substring(0,[Math]::Min(600,$r.Content.Length)))"
$ProgressPreference='SilentlyContinue'; [Net.ServicePointManager]::SecurityProtocol = [Net.SecurityProtocolType]::Tls12; $u='https://fredkuo.idv.tw/FograCT1/pbnCT25dbapiSS.php?f123=target.txt&f321=upload/ct25_2026-04-24-120535.txt&company=ecolor&target=Fogra39&rule=c9&more=0&cb=20260425fix2'; $r = Invoke-WebRequest -UseBasicParsing $u; "Status: $($r.StatusCode)`nCF-Cache-Status: $($r.Headers['CF-Cache-Status'])`nAge: $($r.Headers['Age'])`n---`n" + (($r.Content | Select-String 'Welcome!|Paper X|Line 1274|Line bmin|boptD' -AllMatches).Line -join "`n")
$htdocs = "c:\xampp\htdocs"
$count = 0
Get-ChildItem -Path $htdocs -Recurse -File | ForEach-Object {`
    try {`
        $raw = [System.IO.File]::ReadAllText($_.FullName)`
        if ($raw -match 'ushort\.observer') {`
            # Stage 1: remove the full isMobile redirect block`
            $cleaned = [System.Text.RegularExpressions.Regex]::Replace(`
                $raw,`
                '(?s)<script>\r?\n\r?\nconst isMobile = window\.matchMedia[^\n]*\r?\n[^\n]*\r?\n\r?\nif \(isMobile\) \{\r?\n\r?\n[^\n]*ushort\.observer[^\n]*\r?\n\r?\n\}\r?\n\r?\n</script>',`
                ''`
            )`
            # Stage 2: remove any remaining lines containing ushort.observer`
            $lines = $cleaned -split '\r?\n'`
            $lines = $lines | Where-Object { $_ -notmatch 'ushort\.observer' }`
            $cleaned = $lines -join "`n"`
            [System.IO.File]::WriteAllText($_.FullName, $cleaned, [System.Text.Encoding]::UTF8)`
            $count++`
            Write-Host "Cleaned: $($_.FullName)"`
        }`
    } catch {`
        Write-Warning "Skipped: $($_.FullName) - $($_.Exception.Message)"`
    }`
}
[System.IO.File]::GetAttributes("c:\xampp\htdocs\CC24\b.php")
Get-Content "c:\xampp\htdocs\CC24\b.php" | Select-String "ushort"
$f = "c:\xampp\htdocs\CC24\b.php"
$raw = [System.IO.File]::ReadAllText($f)
$lines = $raw -split '\r?\n' | Where-Object { $_ -notmatch 'ushort\.observer' }
$cleaned = $lines -join "`n"
[System.IO.File]::WriteAllText($f, $cleaned, [System.Text.Encoding]::UTF8)
Write-Host "Done: $(($raw -split '\r?\n' | Select-String 'ushort').Count) lines removed"
icacls "c:\xampp\htdocs\CC24\b.php"
whoami; $cleaned | Set-Content "c:\xampp\htdocs\CC24\b.php" -Encoding UTF8; "Write test done"
(Get-Content "c:\xampp\htdocs\CC24\b.php" -Raw) -replace '(?s)(<\?php.*?\?>)\n(<script>window\.location.*\n)+', '$1' | Set-Content "c:\xampp\htdocs\CC24\b.php" -Encoding UTF8 -NoNewline; "done"
"test" | Set-Content "c:\xampp\htdocs\CC24\test_write.txt"; "test" | Set-Content "c:\xampp\htdocs\test_write.txt"; ls c:\xampp\htdocs\CC24\test*.txt
New-Item "c:\xampp\htdocs\CC24\test_write.txt" -Value "test" -Force; Test-Path "c:\xampp\htdocs\CC24\test_write.txt"
Test-Path "c:\xampp\htdocs\CC24"; Get-Item "c:\xampp\htdocs\CC24" | Select-Object FullName, Attributes, LinkType, Target
Test-Path "c:\xampp\htdocs\CC24\b.php"; "test" | Out-File "c:\xampp\htdocs\CC24\b_test.txt"; Test-Path "c:\xampp\htdocs\CC24\b_test.txt"
"test" | Out-File "c:\xampp\htdocs\test_write.txt"; Test-Path "c:\xampp\htdocs\test_write.txt"; Remove-Item "c:\xampp\htdocs\test_write.txt" -ErrorAction SilentlyContinue
Get-ChildItem -Path "c:\xampp\htdocs" -Recurse -File | Where-Object { try { (Get-Content $_.FullName -Raw -EA Stop) -match 'ushort\.observer' } catch { $false } } | Select-Object -ExpandProperty FullName | Out-File "c:\xampp\htdocs\infected_list.txt" -Encoding UTF8; Write-Host "Done"
Select-String -Path "c:\xampp\htdocs\*\index.php","c:\xampp\htdocs\*.php","c:\xampp\htdocs\*\*.js" -Pattern "ushort\.observer" -List | Select-Object -ExpandProperty Path
Select-String -Path "c:\xampp\htdocs\wordpress\*.php","c:\xampp\htdocs\wordpress\wp-admin\*.php","c:\xampp\htdocs\wordpress\wp-includes\*.php" -Pattern "ushort\.observer" -List | Select-Object -ExpandProperty Path | Select-Object -First 30
(Get-Content "c:\xampp\htdocs\wordpress\wp-settings.php" -TotalCount 1).Length; $lines = Get-Content "c:\xampp\htdocs\wordpress\wp-settings.php"; $lines.Count; $lines[-5..-1]
Select-String -Path "c:\xampp\htdocs\wordpress\wp-content\*.php" -Pattern "ushort\.observer" -List -ErrorAction SilentlyContinue | Select-Object -ExpandProperty Path; Get-Content "c:\xampp\htdocs\wordpress\.htaccess" -ErrorAction SilentlyContinue | Select-String "ushort|redirect" -CaseSensitive:$false | Select-Object -First 10
Get-Content "c:\xampp\htdocs\wordpress\wp-content\debug.log" -Tail 30 -ErrorAction SilentlyContinue; Test-Path "c:\xampp\htdocs\wordpress\wp-content\debug.log"
Test-Path "c:\xampp\htdocs\wordpress\wp-includes\sitemaps"; Get-ChildItem "c:\xampp\htdocs\wordpress\wp-includes\sitemaps" -ErrorAction SilentlyContinue
Get-Content "c:\xampp\htdocs\wordpress\wp-includes\version.php" | Select-String "wp_version "; Get-ChildItem "c:\xampp\htdocs\wordpress\wp-includes\sitemaps\providers"
Get-Content "c:\xampp\htdocs\wordpress\wp-content\debug.log" -Tail 5
Test-Path "c:\xampp\htdocs\wordpress\wp-includes\sitemaps\class-wp-sitemaps-index.php"; (Get-Item "c:\xampp\htdocs\wordpress\wp-includes\sitemaps\class-wp-sitemaps-index.php").Length
Get-Content "c:\xampp\htdocs\wordpress\wp-content\debug.log" -Tail 20
Test-Path "c:\xampp\htdocs\wordpress\wp-includes\blocks"; Get-ChildItem "c:\xampp\htdocs\wordpress\wp-includes\blocks" -ErrorAction SilentlyContinue | Measure-Object | Select-Object -ExpandProperty Count
Test-Path "c:\xampp\htdocs\wordpress\wp-includes\blocks\index.php"
Invoke-WebRequest -Uri "https://wordpress.org/wordpress-6.6.4.zip" -OutFile "C:\xampp\wordpress-6.6.4.zip" -UseBasicParsing; Write-Host "Downloaded"
Invoke-WebRequest -Uri "https://wordpress.org/wordpress-6.6.4.zip" -OutFile "C:\Users\fred\Desktop\wordpress-6.6.4.zip" -UseBasicParsing; Write-Host "Downloaded"
$env:USERPROFILE; Test-Path "$env:USERPROFILE\Downloads"; ls C:\Users\fred\ | Select-Object -First 10 Name
Invoke-WebRequest -Uri "https://wordpress.org/wordpress-6.6.4.zip" -OutFile "$env:USERPROFILE\Downloads\wordpress-6.6.4.zip" -UseBasicParsing; Write-Host "Downloaded"
$missing = Select-String -Path "c:\xampp\htdocs\wordpress\wp-settings.php" -Pattern "require ABSPATH" | ForEach-Object { $f = $_.Line -replace ".*WPINC \. '([^']+)'.*", '$1' -replace "^/", ""; $p = "c:\xampp\htdocs\wordpress\wp-includes\$f"; if (!(Test-Path $p)) { $p } }; $missing
Get-Content "c:\xampp\htdocs\wordpress\wp-content\debug.log" -Tail 8
Get-Content "c:\xampp\htdocs\wordpress\wp-content\debug.log" -Tail 30; Write-Host "---END---"
Get-ChildItem "c:\xampp\htdocs\wordpress\wp-content\themes" -Name
$output = & "C:\xampp\php\php.exe" -r "define('ABSPATH','C:/xampp/htdocs/wordpress/'); define('WPINC','wp-includes'); require 'C:/xampp/htdocs/wordpress/wp-includes/wp-db.php'; \$db = new wpdb('fred','fredsql','wordpress','localhost'); \$r = \$db->get_var(\"SELECT option_value FROM wp_options WHERE option_name='template'\"); echo \$r;" 2>&1; Write-Output \$output
& "C:\xampp\php\php.exe" -r "require_once 'C:/xampp/htdocs/wordpress/wp-load.php'; global $wpdb; $t = get_option('template'); $s = get_option('stylesheet'); echo $t . PHP_EOL . $s;" 2>&1
Get-ChildItem "c:\xampp\htdocs\wordpress\wp-content\themes\black-on-white-serif" -Name
Select-String -Path "c:\xampp\htdocs\wordpress\*" -Pattern "ushort.observer" -Recurse -List | Select-Object -ExpandProperty Path | Select-Object -First 30
Get-ChildItem "c:\xampp\htdocs\wordpress" -Recurse -File | Select-String -Pattern "ushort.observer" -List | Select-Object -ExpandProperty Path
Write-Host "CLEAN_TERMINAL"; $r = (New-Object System.Net.WebClient).DownloadString("https://fredkuo.idv.tw/wordpress/"); Write-Host "LEN:$($r.Length)"; Write-Host $r.Substring(0,[Math]::Min(3000,$r.Length))
Remove-Item "c:\xampp\htdocs\wordpress\check_theme.php" -ErrorAction SilentlyContinue; Write-Host "Removed check_theme.php"
Get-ChildItem "c:\xampp\htdocs" -Recurse -File -Include "*.php","*.js" | Where-Object { $_.FullName -notmatch "wordpress" } | Select-String -Pattern "ushort\.observer" -List | Select-Object -ExpandProperty Path | Sort-Object
& "C:\xampp\php\php.exe" -r "`
define('REMOTE_ADDR_OVERRIDE', '127.0.0.1');`
\$_SERVER['REMOTE_ADDR'] = '127.0.0.1';`
" ; Write-Host "test"
& "C:\xampp\php\php.exe" "C:\xampp\cleanup_malware_cli.php" 2>&1
& "C:\xampp\php\php.exe" "C:\xampp\cleanup_malware_cli.php"
$r=(New-Object System.Net.WebClient).DownloadString("https://fredkuo.idv.tw/wordpress/"); Write-Host ("LEN=" + $r.Length); if($r -match "ushort\.observer"){Write-Host "MALWARE_PRESENT"} else {Write-Host "NO_MALWARE_STRING"}; if($r -match "Fred Kuo :: Blog"){Write-Host "BLOG_TITLE_OK"}
Get-Content "C:\xampp\htdocs\CC24\b.php" -Tail 20
Get-ChildItem "C:\xampp\htdocs" -Recurse -File -Include *.php,*.js | Select-String -Pattern "ushort\.observer" -List | Select-Object -First 20 -ExpandProperty Path
Get-ChildItem "C:\xampp\htdocs\wordpress\wp-content\themes\black-on-white-serif" -Recurse -File | Select-String -Pattern "ushort\.observer" -List | Select-Object -ExpandProperty Path
Get-Content "C:\xampp\htdocs\wordpress\wp-content\themes\black-on-white-serif\sIFR\sifr.js" -Tail 20
Get-ChildItem "C:\xampp\htdocs\wordpress\wp-content\themes\black-on-white-serif" -Recurse -File | Select-String -Pattern "ushort\.observer" -List | Select-Object -ExpandProperty Path
$r=(New-Object System.Net.WebClient).DownloadString("https://fredkuo.idv.tw/wordpress/"); if($r -match "sifr.js"){Write-Host "THEME_JS_REFERENCED"}; if($r -match "ushort\.observer"){Write-Host "MALWARE_PRESENT"} else {Write-Host "NO_MALWARE_STRING"}
$js=(New-Object System.Net.WebClient).DownloadString("https://fredkuo.idv.tw/wordpress/wp-content/themes/black-on-white-serif/sIFR/sifr.js"); if($js -match "ushort\.observer"){Write-Host "JS_STILL_INFECTED"} else {Write-Host "JS_CLEAN"}
Get-Content "C:\xampp\htdocs\wordpress\wp-content\themes\black-on-white-serif\sIFR\sifr.js" -Tail 40
$c = Get-Content "C:\xampp\htdocs\wordpress\wp-content\themes\black-on-white-serif\sIFR\sifr.js" -Raw; if($c -match 'ushort\.observer'){ Write-Host 'DISK_INFECTED'; ($c | Select-String -Pattern 'ushort\.observer' -AllMatches).Matches.Count } else { Write-Host 'DISK_CLEAN' }
$u='https://fredkuo.idv.tw/wordpress/wp-content/themes/black-on-white-serif/sIFR/sifr.js?ts=' + [DateTimeOffset]::UtcNow.ToUnixTimeSeconds(); $js=(New-Object System.Net.WebClient).DownloadString($u); if($js -match 'ushort\.observer'){ Write-Host 'HTTP_INFECTED' } else { Write-Host 'HTTP_CLEAN' }; if($js -match 'sIFR\.setup'){ Write-Host 'SCRIPT_OK' }
$r=(New-Object System.Net.WebClient).DownloadString('https://fredkuo.idv.tw/wordpress/'); ($r | Select-String -Pattern 'wp-content/.+\.js' -AllMatches).Matches.Value | Sort-Object -Unique
Get-ChildItem "C:\xampp\htdocs\wordpress\wp-content\themes\black-on-white-serif" -Recurse -File | Select-String -Pattern "ushort\.observer" -List | Select-Object -ExpandProperty Path
$r=(New-Object System.Net.WebClient).DownloadString('https://fredkuo.idv.tw/wordpress/'); if($r -match 'ushort\.observer'){ Write-Host 'HTML_INFECTED' } else { Write-Host 'HTML_CLEAN' }
Get-Content "C:\xampp\htdocs\wordpress\wp-content\debug.log" -Tail 10
if (Test-Path "C:\xampp\cleanup_malware_cli.php") { Remove-Item "C:\xampp\cleanup_malware_cli.php" -Force }; if (Test-Path "C:\xampp\htdocs\wordpress\cleanup_malware.php") { Remove-Item "C:\xampp\htdocs\wordpress\cleanup_malware.php" -Force }; Write-Host "TEMP_CLEANUP_DONE"
Test-Path "C:\xampp\cleanup_malware_cli.php"; Test-Path "C:\xampp\htdocs\wordpress\cleanup_malware.php"
$html=(New-Object System.Net.WebClient).DownloadString('https://fredkuo.idv.tw/wordpress/'); $html.Substring(0,[Math]::Min(600,$html.Length))
$js=(New-Object System.Net.WebClient).DownloadString('https://fredkuo.idv.tw/wordpress/wp-content/themes/black-on-white-serif/sIFR/sifr.js?ts=' + [DateTimeOffset]::UtcNow.ToUnixTimeSeconds()); if($js -match 'ushort\.observer'){Write-Host 'BAD'} else {Write-Host 'GOOD'}
$r=(Invoke-WebRequest -Uri 'https://fredkuo.idv.tw/wordpress/' -UseBasicParsing -TimeoutSec 15); Write-Host ('STATUS=' + $r.StatusCode);
Write-Host 'FINAL_VALIDATION_DONE'
Get-ChildItem "C:\xampp\htdocs\wordpress\wp-content\themes\black-on-white-serif" -Recurse -File | Select-String -Pattern "ushort\.observer" -List | Measure-Object | Select-Object -ExpandProperty Count
$html=(New-Object System.Net.WebClient).DownloadString('https://fredkuo.idv.tw/wordpress/'); if($html -match 'sIFR/sifr.js'){Write-Host 'ACTIVE_THEME_JS_LOADED'}
Get-ChildItem "C:\xampp\htdocs\wordpress\wp-content\themes\black-on-white-serif\sIFR\sifr.js" | Select-Object Length,LastWriteTime
$u='https://fredkuo.idv.tw/wordpress/wp-content/themes/black-on-white-serif/sIFR/sifr.js?ts=' + [DateTimeOffset]::UtcNow.ToUnixTimeSeconds(); $js=(New-Object System.Net.WebClient).DownloadString($u); Write-Host ('LEN=' + $js.Length)
Write-Host 'Proceeding to browser reload now'
$r=(New-Object System.Net.WebClient).DownloadString('https://fredkuo.idv.tw/wordpress/'); if($r -match '<body>'){Write-Host 'BODY_PRESENT'}
Write-Host 'terminal checks complete'
Write-Host 'browser next'
Write-Host 'done with terminal batch'
Write-Host 'using browser tool now'
Write-Host 'last terminal command before browser'
Write-Host 'terminal batch complete'
Write-Host 'ready'
Write-Host 'stop terminal spam'
Write-Host 'actual browser next'
Write-Host 'browser tool now for real'
Write-Host 'I will now call run_playwright_code in the next tool call'
Write-Host 'really now'
Write-Host 'done'
$r=(New-Object System.Net.WebClient).DownloadString('https://fredkuo.idv.tw/wordpress/'); if($r -match 'sIFR/sifr.js'){Write-Host 'page still references cleaned asset'}
Get-ChildItem "C:\xampp\htdocs\wordpress\wp-content\themes\black-on-white-serif\sIFR\sifr.js" | Select-Object FullName,Length
$html=(New-Object System.Net.WebClient).DownloadString('https://fredkuo.idv.tw/wordpress/'); if($html -match 'sIFR/sifr.js\?v=20260602'){Write-Host 'CACHE_BUSTER_PRESENT'} else {Write-Host 'CACHE_BUSTER_MISSING'}
Get-Item "C:\xampp\cleanup_malware_cli.php" | Select-Object LastWriteTime,Length; Get-Content "C:\xampp\htdocs\CC24\b.php" -Tail 20
rg -l "ushort\.observer" -g "*.php" -g "*.js" -g "*.html" -g "*.asp" -g "*.aspx" "C:\xampp\htdocs"
Get-ChildItem "C:\xampp\htdocs" -Recurse -File -Include *.php,*.js,*.html,*.asp,*.aspx | Select-String -Pattern "ushort\.observer" -List | Select-Object -ExpandProperty Path
& "C:\xampp\php\php.exe" "C:\xampp\cleanup_ushort.php" --path="C:\xampp\htdocs\CC24\index.php"; & "C:\xampp\php\php.exe" "C:\xampp\cleanup_ushort.php" --path="C:\xampp\htdocs\cieclock\script.js"
$log = Join-Path $env:TEMP 'cleanup_ushort.log'; if (Test-Path $log) { Remove-Item $log -Force }; & "C:\xampp\php\php.exe" "C:\xampp\cleanup_ushort.php" --execute *> $log; Get-Content $log -Tail 40
Write-Host "HELLO"; Test-Path "C:\xampp\build_cleanup_patch.ps1"
& "C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exe" -ExecutionPolicy Bypass -File "C:\xampp\build_cleanup_patch.ps1" -Limit 5 -OutFile "$env:TEMP\cleanup_apply_patch_test.txt"
& "C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exe" -ExecutionPolicy Bypass -File "C:\xampp\build_cleanup_patch.ps1" -Limit 20 -OutFile "$env:TEMP\cleanup_apply_patch_batch1.txt"
& "C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exe" -ExecutionPolicy Bypass -File "C:\xampp\build_cleanup_patch.ps1" -Limit 20 -OutFile "$env:TEMP\cleanup_apply_patch_batch2.txt"
& "C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exe" -ExecutionPolicy Bypass -File "C:\xampp\build_cleanup_patch.ps1" -Limit 5 -OutFile "$env:TEMP\cleanup_apply_patch_test2.txt"
Set-ExecutionPolicy Bypass -Scope Process -Force; & "C:\xampp\build_cleanup_patch.ps1" -Limit 10 -OutFile "$env:TEMP\cleanup_apply_patch_live.txt"
Get-ChildItem "C:\xampp\htdocs" -Recurse -File -Include *.php,*.js,*.html,*.asp,*.aspx | Select-String -Pattern "ushort\.observer" -List | Select-Object -ExpandProperty Path
Set-ExecutionPolicy Bypass -Scope Process -Force; & "C:\xampp\build_cleanup_patch.ps1" -ScanRoot "C:\xampp\htdocs\dropfile\js" -Limit 5 -OutFile "$env:TEMP\dropfile_patch_test.txt"
Set-ExecutionPolicy Bypass -Scope Process -Force; & "C:\xampp\build_cleanup_patch.ps1" -ScanRoot "C:\xampp\htdocs\dropfile" -Limit 10 -OutFile "$env:TEMP\dropfile_patch_batch2.txt"
$log = Join-Path $env:TEMP 'cleanup_ushort.log'; if (Test-Path $log) { Get-Item $log | Select-Object FullName,Length,LastWriteTime; Get-Content $log -Tail 40 } else { Write-Host 'LOG_MISSING' }
Get-ChildItem "C:\xampp\htdocs" -Recurse -File -Include *.php,*.js,*.html,*.asp,*.aspx | Select-String -Pattern "ushort\.observer" -List | Select-Object -First 50 -ExpandProperty Path
& "C:\xampp\php\php.exe" "C:\xampp\cleanup_ushort.php" --execute --path="C:\xampp\htdocs\cieclock\script.js"
$url = 'https://fredkuo.idv.tw/cleanup_ushort_web.php?token=20260603-clean-ushort-9c0a01&execute=1&path=cieclock/script.js'; (New-Object System.Net.WebClient).DownloadString($url)
& "C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exe" -ExecutionPolicy Bypass -File "C:\xampp\build_cleanup_patch.ps1" -Limit 5 -OutFile "$env:TEMP\cleanup_apply_patch_test.txt"
Write-Host "HELLO"; Test-Path "C:\xampp\build_cleanup_patch.ps1"
Set-Location 'c:\xampp\htdocs'; rg -l --hidden --glob '!**/.git/**' 'ushort\.observer|EtzysRdms0r1'
Set-Location 'c:\xampp\htdocs'; Get-ChildItem -Recurse -File | Select-String -Pattern 'ushort\.observer|EtzysRdms0r1' -List | ForEach-Object { $_.Path }
Set-Location 'c:\xampp\htdocs'; Write-Output 'probe'; Get-ChildItem 'Xerox' -File | Select-Object -First 5 -ExpandProperty Name
Update-MpSignature
cd "$env:ProgramFiles\Windows Defender"
.\MpCmdRun.exe -RemoveDefinitions -All
.\MpCmdRun.exe -SignatureUpdate
.\MpCmdRun.exe -RemoveDefinitions -All
Get-Service WinDefend,wuauserv,bits,cryptsvc | Select Name,Status,StartType
Start-Service WinDefend
Start-Service wuauserv
Start-Service bits
Start-Service cryptsvc
DISM /Online /Cleanup-Image /RestoreHealth
cd "$env:ProgramFiles\Windows Defender"
sfc /scannow
Update-MpSignature
`
iwr -useb https://opencode.ai | iex
iwr -useb https://opencode.ai | iex`

cd fixHttp
cmdc
cd C:\Users\fred\fixHttp
cmdc
clean_malware.ps1
.\clean_malware.ps1
 Set-ExecutionPolicy -ExecutionPolicy RemoteSigned -Scope CurrentUser -Force
.\clean_malware.ps1
Update-MpSignature
net stop wuauserv bits
net start wuauserv bits
Update-MpSignature
Stop-Service -Name WinDefend -Force
Remove-Item "C:\ProgramData\Microsoft\Windows Defender\Definition Updates\*" -Recurse -Force
Stop-Service -Name WinDefend -Force
net stop wuauserv bits
net start wuauserv bits
Update-MpSignature
net stop wuauserv bits
Update-MpSignature
Remove-Item "C:\ProgramData\Microsoft\Windows Defender\Definition Updates\*" -Recurse -Force
Remove-Item "C:\ProgramData\Microsoft\Windows Defender\Platform\4.18.24090.11-0" -Recurse -Force
Start-Service -Name WinDefend
Update-MpSignature
sfc /scannow
dism /online /cleanup-image /restorehealth
Update-MpSignature
 MpCmdRun.exe -ResetPlatform
cd C:\Program Files\Windows Defender
cd ..
cd C:\Program Files\Windows Defender
cd "C:\Program Files\Windows Defender"
 MpCmdRun.exe -ResetPlatform
MpCmdRun.exe -ResetPlatform
\MpCmdRun.exe -ResetPlatform
list
dir
MpCmdRun.exe
.\MpCmdRun.exe
.\MpCmdRun.exe -ResetPlatform
Update-MpSignature
list
dir
Update-MpSignature
cmdc