The reason likely is you haven't deleted your install directory as that is the most common reason for forums being hacked and if you didn't follow the email and admincp instructions from vbulletin then you were vulnerable and got hacked.
The exploit of this mod in question was fixed in version 4.0.4. If you get base64 results it isn't in the default installation, which you could have easily checked by downloading a fresh copy of the mod searching the file contents for base64. Since it has been added to the plugins for this mod you can safely assume that whoever hacked your site added it there.