I have removed the code from my webpages. Also the 3.1.1 site had the same code.
Avira detected it as follows:
The file ‘C:\Users\xxxx\AppData\LocalLow\Sun\Java\Deployment\cache\6.0\12\3cc664c-253c7238’
contained a virus or unwanted program ‘JAVA/Exdoer.BC.1’ [virus]
Action(s) taken:
I scanned the code offline –> no alerts. I removed the code from both index.php & wp-blog-header.php and set the permissions on 444 instead of on 644.
I think one of the plugins on one of the sites was not OK. Hard to track down what exactly the entry was for this code injuction….