grep -ril '$.* = .*$.* = Array.*$.* = $.*.$.*$.* =
$.*.$.*0.*.$.*.$.*.$.*.$.*.$.*.$.*.$.*0.*.$.*.$.*.$.*.$.*.$.*0.*.$.*.$.*.$.*.$.*.$.*0.*.$.*.$.*.$.*.$.*.$.*0.*.$.*.$.*0.*.$.*.$.*.$.*.$.*.$.*.$.*.$.*.$.*.$.*.$.*$.*
= $.*$.* = $.*.$.*.$.*0.*.$.*0.*.$.*$.* =
$.*.$.*.$.*.$.*.$.*.$.*.$.*.$.*.$.*0.*.$.*$.* =
$.*.$.*.$.*.$.*.$.*.$.*.$.*$.* = $.*.$.*0.*.$.*.$.*.$.*.$.*$.* =
$.*0.*.$.*.$.*.$.*0.*.$.*.$.*.$.*.$.*.$.*.$.*.$.*$.* =
$.*.$.*.$.*.$.*.$.*.$.*0.*$.* = $.*.$.*0.*.$.*.$.*foreach
.*$.*$_COOKIE.* $_POST.* as $.* => $.*function .*$.* $.* $.*return
$.*$.*$.* . $.* .*$.* / $.*$.* + .* 0.* $.*function .*$.* $.*return
@$.*$.*0.* $.*function .*$.* $.*$.* = $.*$.* % .*if .*!$.*
.*eval.*$.*$.*exit.*$.* = .*$.* $.*$.* $.*$.* $.* ^ .*$.* $.* $.*$.*'
--include=*.{php,phtml}* /home/efath0/public_html/ >>
/home/efath0/infected.files.list.txt
grep -ril '$.* = .*$.* = Array.*$.* = $.*.$.*$.* = $.*$.* =
$.*.$.*.$.*.$.*.$.*.$.*.$.*.$.*.$.*.$.*.$.*.$.*.$.*.$.*.$.*.$.*.$.*.$.*.$.*.$.*.$.*.$.*.$.*.$.*.$.*.$.*.$.*.$.*.$.*.$.*.$.*.$.*.$.*.$.*.$.*.$.*$.*
= $.*.$.*.$.*.$.*.$.*$.* = $.*.$.*.$.*.$.*.$.*.$.*.$.*.$.*.$.*.$.*$.* =
$.*.$.*.$.*.$.*.$.*.$.*.$.*$.* = $.*.$.*.$.*.$.*.$.*.$.*$.* =
$.*.$.*.$.*.$.*.$.*.$.*.$.*.$.*.$.*.$.*.$.*$.* =
$.*.$.*.$.*.$.*.$.*.$.*$.* = $.*.$.*.$.*.$.*foreach .*$.*$_COOKIE.*
$_POST.* as $.* => $.*function .*$.* $.* $.*return $.*$.*$.* . $.* .*$.*
/ $.*$.* + .* .* $.*function .*$.* $.*return @$.*$.* $.*function .*$.*
$.*$.* = $.*$.* % .*if .*$.* .*eval.*$.*$.*exit.*$.* = .*$.* $.*$.*
$.*$.* $.* ^ .*$.* $.* $.*$' --include=*.{php,phtml}*
/home/efath0/public_html/ >> /home/efath0/infected.files.list.txt
grep -ril '<?php
for.*ord.*$.*$.*$.*++.*if.*$.*$.*$.*$.*$.*else.*$.*chr.*$.*$.*$.*+.*$.*$.*++$.*eval.*$.*
.*?>' --include=*.{php,phtml}* /home/efath0/public_html/ >>
/home/efath0/infected.files.list.txt
grep -ril ' eval(base64_decode($.*)).* ?>' --include=*.{php,phtml}*
/home/efath0/public_html/ >> /home/efath0/infected.files.list.txt
grep -ril 'if.* .*_POST.*_upl.* == .*Upload.* .* .*
if.*@copy.*_FILES.*file.*tmp_name.* .*_FILES.*file.*name.* .* echo .*;
.* else .* echo .*; .* .*' --include=*.{php,phtml}*
/home/efath0/public_html/ >> /home/efath0/infected.files.list.txt
grep -ril 'echo.*eval(urldecode($.*));' --include=*.{php,phtml}*
/home/efath0/public_html/ >> /home/efath0/infected.files.list.txt
grep -ril '@system(.*killall -9 .*.basename(.*/usr/bin/host.*));'
--include=*.{php,phtml}* /home/efath0/public_html/ >>
/home/efath0/infected.files.list.txt
grep -ril 'if($.*=@fsockopen($.*$this->.*[.*(.*)].*$.*$.*$.*(.*)))'
--include=*.{php,phtml}* /home/efath0/public_html/ >>
/home/efath0/infected.files.list.txt
grep -ril
'<.*php.*create_function.*(.*x.*\.*x.*\.*x.*\.*x.*\.*x.*\.*x.*\.*x.*\.*x.*\.*x.*\.*x.*\.*x.*\.*x.*\.*x.*\.*x.*\.*x.*\.*x.*\.*x.*\.*x.*\.*x.*\.*x.*\.*x.*\.*x.*\.*x.*\.*x.*\.*x.*\.*x.*\.*x.*\.*x.*\.*x.*\.*x.*\.*x.*\.*x.*\.*x.*\.*x.*\.*x.*\.*x.*\.*x.*\.*x.*\.*x.*\.*x.*\.*x.*\.*x.*\.*x.*\.*x.*\.*x.*\.*x.*\.*x.*\.*x.*\.*x.*\.*x.*\.*x.*\.*x.*\.*x.*\.*x.*\.*x.*\.*x.*\.*x.*\.*x.*\.*x.*\.*x.*\.*x.*\.*x.*\.*x.*\.*x.*\.*x.*\.*x.*\.*x.*\.*x.*\.*x.*\.*x.*\.*x.*\.*x.*\.*x.*\.*x.*\.*x.*\.*x.*\.*x.*\.*x.*\.*x.*\.*x.*\.*).*?>'
--include=*.{php,phtml}* /home/efath0 >>
/home/efath0/infected.files.list.txt
grep -ril
'GLOBALS.*Array.*global.*GLOBALS.*NULL.*NULL.*NULL.*function.*return.*function.*global.*Array.*elseif.*eval.*exit'
--include=*.{php,phtml}* /home/efath0/public_html/ >>
/home/efath0/infected.files.list.txt
grep -ril
'(.*/.*/.*/.*/.*/.*/.*/.*/.*/.*/.*/.*/.*/.*/.*/.*/.*/.*/.*/.*/.*/.*/.*/.*/.*/.*/.*/.*/.*/.*/.*/.*/.*/.*/.*/.*/.*/.*/.*/.*/.*/.*/.*/.*/.*/.*/.*/.*/.*/.*/.*/.*/.*/.*/.*/.*/.*/.*/.*/.*/.*/.*/.*/.*/.*/.*/.*/.*/.*/.*/.*)'
--include=*.{php,phtml}* /home/efath0/public_html/ >>
/home/efath0/infected.files.list.txt
grep -ril 'eval.*str_rot13.*gzinflate.*str_rot13.*base64_decode'
--include=*.{php,phtml}* /home/efath0/public_html/ >>
/home/efath0/infected.files.list.txt
grep -ril '<?php.*if.*isset.*REQUEST.*REQUEST.*exit;}?>'
--include=*.{php,phtml}* /home/efath0/public_html/ >>
/home/efath0/infected.files.list.txt
grep -ril 'if.*isset.*GLOBALS.*GLOBALS.*&&.*GLOBALS.*GLOBALS'
--include=*.{php,phtml}* /home/efath0/public_html/ >>
/home/efath0/infected.files.list.txt
grep -ril 'function.*return.*str_repeat.*ceil.*strlen.*strlen'
--include=*.{php,phtml}* /home/efath0/public_html/ >>
/home/efath0/infected.files.list.txt
grep -ril 'MailTo.*base64_decode.*POST.*mailto' --include=*.{php,phtml}*
/home/efath0/public_html/ >> /home/efath0/infected.files.list.txt
grep -ril 'eval.*gzinflate.*base64_decode' --include=*.{php,phtml}*
/home/efath0/public_html/ >> /home/efath0/infected.files.list.txt
grep -ril
'strtolower.*if.*strstr.*or.*strstr.*if.*function_exists.*or.*strstr.*or.*array_map.*str_split.*function.*GLOBALS.*or.*strstr.*return.*chr.*ord.*error_reporting.*explode.*chr.*substr.*if.*function_exists.*function.*for.*sizeof.*substr.*return.*chr.*chr.*explode.*chr.*preg_replace'
--include=*.{php,phtml}* /home/efath0/public_html/ >>
/home/efath0/infected.files.list.txt
grep -ril
'if.*function_exists.*function.*base64_decode.*ord.*ord.*strlen.*preg_match.*base64_decode.*if.*exit.*if.*if.*if.*ord.*for.*else.*for.*else.*if.*return.*eval'
--include=*.{php,phtml}* /home/efath0/public_html/ >>
/home/efath0/infected.files.list.txt
grep -ril 'GLOBALS.*Array.*foreach.*eval.*exit.*php'
--include=*.{php,phtml}* /home/efath0/public_html/ >>
/home/efath0/infected.files.list.txt
grep -ril 'php.*if.*isset.*REQUEST.*assert.*REQUEST.*exit'
--include=*.{php,phtml}* /home/efath0/public_html/ >>
/home/efath0/infected.files.list.txt
grep -ril 'create_function.*base64_decode' --include=*.{php,phtml}*
/home/efath0/public_html/ >> /home/efath0/infected.files.list.txt
grep -ril
'isset.*POST.*isset.*COOKIE.*NULL.*if.*NULL.*md5.*substr.*md5.*strrev.*strlen.*for.*chr.*if.*gzinflate.*if.*isset.*setcookie.*POST.*create_function.*unset'
--include=*.{php,phtml}* /home/efath0/public_html/ >>
/home/efath0/infected.files.list.txt
grep -ril
'isset.*POST.*POST.*isset.*COOKIE.*COOKIE.*NULL.*if.*NULL.*md5.*substr.*md5.*strrev.*strlen.*for.*chr.*if.*gzinflate.*if.*isset.*setcookie.*POST.*create_function.*unset'
--include=*.{php,phtml}* /home/efath0/public_html/ >>
/home/efath0/infected.files.list.txt
grep -ril 'php.*if.*isset.*eval' --include=*.{php,phtml}*
/home/efath0/public_html/ >> /home/efath0/infected.files.list.txt
grep -ril 'GLOBALS.*Array.*GLOBALS.*function.*return.*echo.*eval.*exit'
--include=*.{php,phtml}* /home/efath0/public_html/ >>
/home/efath0/infected.files.list.txt
grep -ril 'function.*for.*strlen.*++.*isset' --include=*.{php,phtml}*
/home/efath0/public_html/ >> /home/efath0/infected.files.list.txt
grep -ril 'new.*JApplication.*array.*UID.*' --include=*.{php,phtml}*
/home/efath0/public_html/ >> /home/efath0/infected.files.list.txt
grep -ril 'strtolower.*strtoupper.*if.*isset.*eval'
--include=*.{php,phtml}* /home/efath0/public_html/ >>
/home/efath0/infected.files.list.txt
grep -ril 'eval.*gzuncompress.*base64_decode' --include=*.{php,phtml}*
/home/efath0/public_html/ >> /home/efath0/infected.files.list.txt
grep -ril
'GLOBALS.*GLOBALS.*if.*empty.*GLOBALS.*eval.*GLOBALS.*GLOBALS.*echo'
--include=*.{php,phtml}* /home/efath0/public_html/ >>
/home/efath0/infected.files.list.txt
grep -ril 'php.*preg_replace.*SERVER.*HTTP.*SERVER.*HTTP.*CURRENT'
--include=*.{php,phtml}* /home/efath0/public_html/ >>
/home/efath0/infected.files.list.txt
grep -ril
'php.*if.*isset.*GLOBALS.*strtolower.*strstr.*strstr.*GLOBALS.*php'
--include=*.{php,phtml}* /home/efath0/public_html/ >>
/home/efath0/infected.files.list.txt
grep -ril 'function.*return.*NULL.*preg_replace'
--include=*.{php,phtml}* /home/efath0/public_html/ >>
/home/efath0/infected.files.list.txt
grep -ril
'explode.*chr.*if.*function_exists.*function.*NULL.*for.*return.*NULL'
--include=*.{php,phtml}* /home/efath0/public_html/ >>
/home/efath0/infected.files.list.txt
grep -ril "function.*for.*strlen.*++" --include=*.{php,phtml}*
/home/efath0/public_html/ >> /home/efath0/infected.files.list.txt
grep -ril 'function.*for.*strlen.*isset' --include=*.{php,phtml}*
/home/efath0/public_html/ >> /home/efath0/infected.files.list.txt
grep -ril
'GLOBALS.*GLOBALS.*global.*function.*for.*function.*global.*return.*if.*Array.*else.*eval.*exit.*php'
--include=*.{php,phtml}* /home/efath0/public_html/ >>
/home/efath0/infected.files.list.txt
grep -ril
'php.*function.*Array.*return.*base64_decode.*error_reporting.*mb_internal_encoding.*mb_regex_encoding.*mb_http_output.*mb_http_input.*mb_language.*mb_strtolower.*mb_substr.*function'
--include=*.{php,phtml}* /home/efath0/public_html/ >>
/home/efath0/infected.files.list.txt
grep -ril 'array.*strrev.*strrev.*eval.*implode.*?>'
--include=*.{php,phtml}* /home/efath0/public_html/ >>
/home/efath0/infected.files.list.txt
grep -ril 'array.*strrev.*implode.*array.*implode.*?>'
--include=*.{php,phtml}* /home/efath0/public_html/ >>
/home/efath0/infected.files.list.txt
grep -ril 'strtoupper.*if.*eval' --include=*.{php,phtml}*
/home/efath0/public_html/ >> /home/efath0/infected.files.list.txt
grep -ril
'<?php.*function_exists.*explode.*chr.*substr.*function_exists.*function
mugvsjx.*NULL.*substr.*?>.*<?php' --include=*.{php,phtml}*
/home/efath0/public_html/ >> /home/efath0/infected.files.list.txt
grep -ril '<?php.*preg_replace.*(.*_REQUEST.*[.*].*).*?>'
--include=*.{php,phtml}* /home/efath0/public_html/ >>
/home/efath0/infected.files.list.txt
grep -ril
'<?php.*return.*chr.*str_split.*GLOBALS.*function_exists.*explode.*substr.*explode.*chr.*?>'
--include=*.{php,phtml}* /home/efath0/public_html/ >>
/home/efath0/infected.files.list.txt
grep -ril
'<?php.*if.*isset.*GLOBALS.*strtolower.*SERVER.*if.*strstr.*strstr.*GLOBALS.*?><?php'
--include=*.{php,phtml}* /home/efath0/public_html/ >>
/home/efath0/infected.files.list.txt
grep -ril
'<?php.*preg_replace.*isset.*GLOBALS.*function.*preg_replace.*explode.*chr.*substr.*function_exists.*function.*substr.*?><?php'
--include=*.{php,phtml}* /home/efath0/public_html/ >>
/home/efath0/infected.files.list.txt
grep -ril
'<?php.*$GLOBALS.*if.*function_exists.*function.*$GLOBALS.*pack.*return.*substr.*?><?php'
--include=*.{php,phtml}* /home/efath0/public_html/ >>
/home/efath0/infected.files.list.txt
grep -ril '<?php.*strtoupper.*if.*isset.*eval.*?>'
--include=*.{php,phtml}* /home/efath0/public_html/ >>
/home/efath0/infected.files.list.txt
grep -ril
'<?php.*$GLOBALS.*isset.*$GLOBALS.*explode.*substr.*function_exists.*function.*?><?php'
--include=*.{php,phtml}* /home/efath0/public_html/ >>
/home/efath0/infected.files.list.txt
grep -ril
'<?php.*strtolower.*$GLOBALS.*strstr.*function_exists.*substr.*explode.*?><?php'
--include=*.{php,phtml}* /home/efath0/public_html/ >>
/home/efath0/infected.files.list.txt
grep -ril
'<?php.*isset.*$GLOBALS.*strtolower.*$_SERVER.*strstr.*function_exists.*function.*?><?php'
--include=*.{php,phtml}* /home/efath0/public_html/ >>
/home/efath0/infected.files.list.txt
grep -ril '<?php.*if.*isset.*globals.*strtolower.*?>'
--include=*.{php,phtml}* /home/efath0/public_html/ >>
/home/efath0/infected.files.list.txt
grep -ril '<?php.*globals.*eval.*?><?php' --include=*.{php,phtml}*
/home/efath0/public_html/ >> /home/efath0/infected.files.list.txt
grep -ril '<?php.*!function_exists.*?><?php' --include=*.{php,phtml}*
/home/efath0/public_html/ >> /home/efath0/infected.files.list.txt
grep -ril 'strstr.*implode.*array_map.*function_exists'
--include=*.{php,phtml}* /home/efath0/public_html/ >>
/home/efath0/infected.files.list.txt
grep -ril 'if.*isset.*${$.*}.*eval.*;}.*?>' --include=*.{php,phtml}*
/home/efath0/public_html/ >> /home/efath0/infected.files.list.txt
grep -ril
'<?php.*strtolower.*[].*[].*[].*[].*[].*[].*strtoupper.*eval.*?>'
--include=*.{php,phtml}* /home/efath0/public_html/ >>
/home/efath0/infected.files.list.txt
grep -ril
'str_split.*strtolower.*implode.*array_map.*strstr.*$GLOBALS.*!function_exists.*substr.*return.*explode.*chr'
--include=*.{php,phtml}* /home/efath0/public_html/ >>
/home/efath0/infected.files.list.txt
grep -ril '<?php.*$GLOBALS.*!function_exists.*?><?php'
--include=*.{php,phtml}* /home/efath0/public_html/ >>
/home/efath0/infected.files.list.txt
grep -ril "eval(base64_decode('.*').*);.*?>" --include=*.{php,phtml}*
/home/efath0/public_html/ >> /home/efath0/infected.files.list.txt
grep -ril 'php.*isset.*strto' --include=*.{php,phtml}*
/home/efath0/public_html/ >> /home/efath0/infected.files.list.txt
grep -ril
'isset.*SERVER.*strpos.*function.*substr.*function.*isset.*md5.*file_exists'
--include=*.{php,phtml}* /home/efath0/public_html/ >>
/home/efath0/infected.files.list.txt
grep -ril
'if.*extension_loaded.*IonCube_loader.*strtolower.*substr.*php_uname().*ioncube_loader_.*substr.*phpversion.*if.*function_exists.*return.*preg_replace.*fopen.*realpath.*extension_dir.*dirname.*if.*strlen.*str_replace.*substr.*str_replace.*substr.*str_repeat.*substr_count.*strlen.*while.*if.*substr.*if.*fread.*filesize.*pack.*substr.*break.*eval.*return.*else.*die.*if.*function_exists.*return.*return'
--include=*.{php,phtml}* /home/efath0/public_html/ >>
/home/efath0/infected.files.list.txt
Comments