had similar issue after updating WordPress 3 days ago have found all index.php files infected with base64_decode, even the two themes supplied with WP where affected. Have had to delete each index.php file in the wordpress core plus all themes. Sites hosted on mediatemple, Also noticed each infected site had a file in the root with list of IP address. file name: 9fec9686a688eb028f2ca1506bc4b9ac
Would welcome any ideas what this exploit is and how best to deal with it.
So far have replaced all instances of index.php plus deleting the above file from the root dir.