I found 3 base64 files on each of my sites that were hacked. (3 sites)
All with names similar to aguidaequesabe. All were on GoDaddy as well.
In addition to the code inserted into the header file, I found several “index.php” files around that had the following eval code inserted
function gpc_15674($l15676){i [code moderated] rray_map("gpc_15674",$_SERVER);