grep -ril '$.* = .*$.* = Array.*$.* = $.*.$.*$.* = $.*.$.*0.*.$.*.$.*.$.*.$.*.$.*.$.*.$.*0.*.$.*.$.*.$.*.$.*.$.*0.*.$.*.$.*.$.*.$.*.$.*0.*.$.*.$.*.$.*.$.*.$.*0.*.$.*.$.*0.*.$.*.$.*.$.*.$.*.$.*.$.*.$.*.$.*.$.*.$.*$.* = $.*$.* = $.*.$.*.$.*0.*.$.*0.*.$.*$.* = $.*.$.*.$.*.$.*.$.*.$.*.$.*.$.*.$.*0.*.$.*$.* = $.*.$.*.$.*.$.*.$.*.$.*.$.*$.* = $.*.$.*0.*.$.*.$.*.$.*.$.*$.* = $.*0.*.$.*.$.*.$.*0.*.$.*.$.*.$.*.$.*.$.*.$.*.$.*$.* = $.*.$.*.$.*.$.*.$.*.$.*0.*$.* = $.*.$.*0.*.$.*.$.*foreach .*$.*$_COOKIE.* $_POST.* as $.* => $.*function .*$.* $.* $.*return $.*$.*$.* . $.* .*$.* / $.*$.* + .* 0.* $.*function .*$.* $.*return @$.*$.*0.* $.*function .*$.* $.*$.* = $.*$.* % .*if .*!$.* .*eval.*$.*$.*exit.*$.* = .*$.* $.*$.* $.*$.* $.* ^ .*$.* $.* $.*$.*' --include=*.{php,phtml}* /home/efath0/public_html/ >> /home/efath0/infected.files.list.txt grep -ril '$.* = .*$.* = Array.*$.* = $.*.$.*$.* = $.*$.* = $.*.$.*.$.*.$.*.$.*.$.*.$.*.$.*.$.*.$.*.$.*.$.*.$.*.$.*.$.*.$.*.$.*.$.*.$.*.$.*.$.*.$.*.$.*.$.*.$.*.$.*.$.*.$.*.$.*.$.*.$.*.$.*.$.*.$.*.$.*.$.*$.* = $.*.$.*.$.*.$.*.$.*$.* = $.*.$.*.$.*.$.*.$.*.$.*.$.*.$.*.$.*.$.*$.* = $.*.$.*.$.*.$.*.$.*.$.*.$.*$.* = $.*.$.*.$.*.$.*.$.*.$.*$.* = $.*.$.*.$.*.$.*.$.*.$.*.$.*.$.*.$.*.$.*.$.*$.* = $.*.$.*.$.*.$.*.$.*.$.*$.* = $.*.$.*.$.*.$.*foreach .*$.*$_COOKIE.* $_POST.* as $.* => $.*function .*$.* $.* $.*return $.*$.*$.* . $.* .*$.* / $.*$.* + .* .* $.*function .*$.* $.*return @$.*$.* $.*function .*$.* $.*$.* = $.*$.* % .*if .*$.* .*eval.*$.*$.*exit.*$.* = .*$.* $.*$.* $.*$.* $.* ^ .*$.* $.* $.*$' --include=*.{php,phtml}* /home/efath0/public_html/ >> /home/efath0/infected.files.list.txt grep -ril '' --include=*.{php,phtml}* /home/efath0/public_html/ >> /home/efath0/infected.files.list.txt grep -ril ' eval(base64_decode($.*)).* ?>' --include=*.{php,phtml}* /home/efath0/public_html/ >> /home/efath0/infected.files.list.txt grep -ril 'if.* .*_POST.*_upl.* == .*Upload.* .* .* if.*@copy.*_FILES.*file.*tmp_name.* .*_FILES.*file.*name.* .* echo .*; .* else .* echo .*; .* .*' --include=*.{php,phtml}* /home/efath0/public_html/ >> /home/efath0/infected.files.list.txt grep -ril 'echo.*eval(urldecode($.*));' --include=*.{php,phtml}* /home/efath0/public_html/ >> /home/efath0/infected.files.list.txt grep -ril '@system(.*killall -9 .*.basename(.*/usr/bin/host.*));' --include=*.{php,phtml}* /home/efath0/public_html/ >> /home/efath0/infected.files.list.txt grep -ril 'if($.*=@fsockopen($.*$this->.*[.*(.*)].*$.*$.*$.*(.*)))' --include=*.{php,phtml}* /home/efath0/public_html/ >> /home/efath0/infected.files.list.txt grep -ril '<.*php.*create_function.*(.*x.*\.*x.*\.*x.*\.*x.*\.*x.*\.*x.*\.*x.*\.*x.*\.*x.*\.*x.*\.*x.*\.*x.*\.*x.*\.*x.*\.*x.*\.*x.*\.*x.*\.*x.*\.*x.*\.*x.*\.*x.*\.*x.*\.*x.*\.*x.*\.*x.*\.*x.*\.*x.*\.*x.*\.*x.*\.*x.*\.*x.*\.*x.*\.*x.*\.*x.*\.*x.*\.*x.*\.*x.*\.*x.*\.*x.*\.*x.*\.*x.*\.*x.*\.*x.*\.*x.*\.*x.*\.*x.*\.*x.*\.*x.*\.*x.*\.*x.*\.*x.*\.*x.*\.*x.*\.*x.*\.*x.*\.*x.*\.*x.*\.*x.*\.*x.*\.*x.*\.*x.*\.*x.*\.*x.*\.*x.*\.*x.*\.*x.*\.*x.*\.*x.*\.*x.*\.*x.*\.*x.*\.*x.*\.*x.*\.*x.*\.*x.*\.*x.*\.*x.*\.*x.*\.*x.*\.*x.*\.*).*?>' --include=*.{php,phtml}* /home/efath0 >> /home/efath0/infected.files.list.txt grep -ril 'GLOBALS.*Array.*global.*GLOBALS.*NULL.*NULL.*NULL.*function.*return.*function.*global.*Array.*elseif.*eval.*exit' --include=*.{php,phtml}* /home/efath0/public_html/ >> /home/efath0/infected.files.list.txt grep -ril '(.*/.*/.*/.*/.*/.*/.*/.*/.*/.*/.*/.*/.*/.*/.*/.*/.*/.*/.*/.*/.*/.*/.*/.*/.*/.*/.*/.*/.*/.*/.*/.*/.*/.*/.*/.*/.*/.*/.*/.*/.*/.*/.*/.*/.*/.*/.*/.*/.*/.*/.*/.*/.*/.*/.*/.*/.*/.*/.*/.*/.*/.*/.*/.*/.*/.*/.*/.*/.*/.*/.*)' --include=*.{php,phtml}* /home/efath0/public_html/ >> /home/efath0/infected.files.list.txt grep -ril 'eval.*str_rot13.*gzinflate.*str_rot13.*base64_decode' --include=*.{php,phtml}* /home/efath0/public_html/ >> /home/efath0/infected.files.list.txt grep -ril '' --include=*.{php,phtml}* /home/efath0/public_html/ >> /home/efath0/infected.files.list.txt grep -ril 'if.*isset.*GLOBALS.*GLOBALS.*&&.*GLOBALS.*GLOBALS' --include=*.{php,phtml}* /home/efath0/public_html/ >> /home/efath0/infected.files.list.txt grep -ril 'function.*return.*str_repeat.*ceil.*strlen.*strlen' --include=*.{php,phtml}* /home/efath0/public_html/ >> /home/efath0/infected.files.list.txt grep -ril 'MailTo.*base64_decode.*POST.*mailto' --include=*.{php,phtml}* /home/efath0/public_html/ >> /home/efath0/infected.files.list.txt grep -ril 'eval.*gzinflate.*base64_decode' --include=*.{php,phtml}* /home/efath0/public_html/ >> /home/efath0/infected.files.list.txt grep -ril 'strtolower.*if.*strstr.*or.*strstr.*if.*function_exists.*or.*strstr.*or.*array_map.*str_split.*function.*GLOBALS.*or.*strstr.*return.*chr.*ord.*error_reporting.*explode.*chr.*substr.*if.*function_exists.*function.*for.*sizeof.*substr.*return.*chr.*chr.*explode.*chr.*preg_replace' --include=*.{php,phtml}* /home/efath0/public_html/ >> /home/efath0/infected.files.list.txt grep -ril 'if.*function_exists.*function.*base64_decode.*ord.*ord.*strlen.*preg_match.*base64_decode.*if.*exit.*if.*if.*if.*ord.*for.*else.*for.*else.*if.*return.*eval' --include=*.{php,phtml}* /home/efath0/public_html/ >> /home/efath0/infected.files.list.txt grep -ril 'GLOBALS.*Array.*foreach.*eval.*exit.*php' --include=*.{php,phtml}* /home/efath0/public_html/ >> /home/efath0/infected.files.list.txt grep -ril 'php.*if.*isset.*REQUEST.*assert.*REQUEST.*exit' --include=*.{php,phtml}* /home/efath0/public_html/ >> /home/efath0/infected.files.list.txt grep -ril 'create_function.*base64_decode' --include=*.{php,phtml}* /home/efath0/public_html/ >> /home/efath0/infected.files.list.txt grep -ril 'isset.*POST.*isset.*COOKIE.*NULL.*if.*NULL.*md5.*substr.*md5.*strrev.*strlen.*for.*chr.*if.*gzinflate.*if.*isset.*setcookie.*POST.*create_function.*unset' --include=*.{php,phtml}* /home/efath0/public_html/ >> /home/efath0/infected.files.list.txt grep -ril 'isset.*POST.*POST.*isset.*COOKIE.*COOKIE.*NULL.*if.*NULL.*md5.*substr.*md5.*strrev.*strlen.*for.*chr.*if.*gzinflate.*if.*isset.*setcookie.*POST.*create_function.*unset' --include=*.{php,phtml}* /home/efath0/public_html/ >> /home/efath0/infected.files.list.txt grep -ril 'php.*if.*isset.*eval' --include=*.{php,phtml}* /home/efath0/public_html/ >> /home/efath0/infected.files.list.txt grep -ril 'GLOBALS.*Array.*GLOBALS.*function.*return.*echo.*eval.*exit' --include=*.{php,phtml}* /home/efath0/public_html/ >> /home/efath0/infected.files.list.txt grep -ril 'function.*for.*strlen.*++.*isset' --include=*.{php,phtml}* /home/efath0/public_html/ >> /home/efath0/infected.files.list.txt grep -ril 'new.*JApplication.*array.*UID.*' --include=*.{php,phtml}* /home/efath0/public_html/ >> /home/efath0/infected.files.list.txt grep -ril 'strtolower.*strtoupper.*if.*isset.*eval' --include=*.{php,phtml}* /home/efath0/public_html/ >> /home/efath0/infected.files.list.txt grep -ril 'eval.*gzuncompress.*base64_decode' --include=*.{php,phtml}* /home/efath0/public_html/ >> /home/efath0/infected.files.list.txt grep -ril 'GLOBALS.*GLOBALS.*if.*empty.*GLOBALS.*eval.*GLOBALS.*GLOBALS.*echo' --include=*.{php,phtml}* /home/efath0/public_html/ >> /home/efath0/infected.files.list.txt grep -ril 'php.*preg_replace.*SERVER.*HTTP.*SERVER.*HTTP.*CURRENT' --include=*.{php,phtml}* /home/efath0/public_html/ >> /home/efath0/infected.files.list.txt grep -ril 'php.*if.*isset.*GLOBALS.*strtolower.*strstr.*strstr.*GLOBALS.*php' --include=*.{php,phtml}* /home/efath0/public_html/ >> /home/efath0/infected.files.list.txt grep -ril 'function.*return.*NULL.*preg_replace' --include=*.{php,phtml}* /home/efath0/public_html/ >> /home/efath0/infected.files.list.txt grep -ril 'explode.*chr.*if.*function_exists.*function.*NULL.*for.*return.*NULL' --include=*.{php,phtml}* /home/efath0/public_html/ >> /home/efath0/infected.files.list.txt grep -ril "function.*for.*strlen.*++" --include=*.{php,phtml}* /home/efath0/public_html/ >> /home/efath0/infected.files.list.txt grep -ril 'function.*for.*strlen.*isset' --include=*.{php,phtml}* /home/efath0/public_html/ >> /home/efath0/infected.files.list.txt grep -ril 'GLOBALS.*GLOBALS.*global.*function.*for.*function.*global.*return.*if.*Array.*else.*eval.*exit.*php' --include=*.{php,phtml}* /home/efath0/public_html/ >> /home/efath0/infected.files.list.txt grep -ril 'php.*function.*Array.*return.*base64_decode.*error_reporting.*mb_internal_encoding.*mb_regex_encoding.*mb_http_output.*mb_http_input.*mb_language.*mb_strtolower.*mb_substr.*function' --include=*.{php,phtml}* /home/efath0/public_html/ >> /home/efath0/infected.files.list.txt grep -ril 'array.*strrev.*strrev.*eval.*implode.*?>' --include=*.{php,phtml}* /home/efath0/public_html/ >> /home/efath0/infected.files.list.txt grep -ril 'array.*strrev.*implode.*array.*implode.*?>' --include=*.{php,phtml}* /home/efath0/public_html/ >> /home/efath0/infected.files.list.txt grep -ril 'strtoupper.*if.*eval' --include=*.{php,phtml}* /home/efath0/public_html/ >> /home/efath0/infected.files.list.txt grep -ril '.*> /home/efath0/infected.files.list.txt grep -ril '' --include=*.{php,phtml}* /home/efath0/public_html/ >> /home/efath0/infected.files.list.txt grep -ril '' --include=*.{php,phtml}* /home/efath0/public_html/ >> /home/efath0/infected.files.list.txt grep -ril '> /home/efath0/infected.files.list.txt grep -ril '> /home/efath0/infected.files.list.txt grep -ril '> /home/efath0/infected.files.list.txt grep -ril '' --include=*.{php,phtml}* /home/efath0/public_html/ >> /home/efath0/infected.files.list.txt grep -ril '> /home/efath0/infected.files.list.txt grep -ril '> /home/efath0/infected.files.list.txt grep -ril '> /home/efath0/infected.files.list.txt grep -ril '' --include=*.{php,phtml}* /home/efath0/public_html/ >> /home/efath0/infected.files.list.txt grep -ril '> /home/efath0/infected.files.list.txt grep -ril '> /home/efath0/infected.files.list.txt grep -ril 'strstr.*implode.*array_map.*function_exists' --include=*.{php,phtml}* /home/efath0/public_html/ >> /home/efath0/infected.files.list.txt grep -ril 'if.*isset.*${$.*}.*eval.*;}.*?>' --include=*.{php,phtml}* /home/efath0/public_html/ >> /home/efath0/infected.files.list.txt grep -ril '' --include=*.{php,phtml}* /home/efath0/public_html/ >> /home/efath0/infected.files.list.txt grep -ril 'str_split.*strtolower.*implode.*array_map.*strstr.*$GLOBALS.*!function_exists.*substr.*return.*explode.*chr' --include=*.{php,phtml}* /home/efath0/public_html/ >> /home/efath0/infected.files.list.txt grep -ril '> /home/efath0/infected.files.list.txt grep -ril "eval(base64_decode('.*').*);.*?>" --include=*.{php,phtml}* /home/efath0/public_html/ >> /home/efath0/infected.files.list.txt grep -ril 'php.*isset.*strto' --include=*.{php,phtml}* /home/efath0/public_html/ >> /home/efath0/infected.files.list.txt grep -ril 'isset.*SERVER.*strpos.*function.*substr.*function.*isset.*md5.*file_exists' --include=*.{php,phtml}* /home/efath0/public_html/ >> /home/efath0/infected.files.list.txt grep -ril 'if.*extension_loaded.*IonCube_loader.*strtolower.*substr.*php_uname().*ioncube_loader_.*substr.*phpversion.*if.*function_exists.*return.*preg_replace.*fopen.*realpath.*extension_dir.*dirname.*if.*strlen.*str_replace.*substr.*str_replace.*substr.*str_repeat.*substr_count.*strlen.*while.*if.*substr.*if.*fread.*filesize.*pack.*substr.*break.*eval.*return.*else.*die.*if.*function_exists.*return.*return' --include=*.{php,phtml}* /home/efath0/public_html/ >> /home/efath0/infected.files.list.txt