the best would be to use backup as malware can be in any script and any part of the file...so its very hard to remove it even if you have great linux knowledge.
but from the image you sent all before "return{" is part of the malware
Also you could prevent this by using security tools in cwp...info is on the wiki.