What are the permissions on the directory that the .htaccess file was left in? Could be worth asking your provider which processes run as 'nobody'.
On my system, the .htaccess file that was altered had owner & group of my user. Permissions were 644 on the file and 755 for the directory. I need to check with my provider as to which user runs the apache process.
As for the attack itself, the php added to my files varies slightly, but the basics seem to be that it tries to set a cookie, then if it's able to read that cookie back it inserts code into the HTML to load some javascript, and adds a redirect to the page itself. I've not sussed out the rest, as I said, PHP isn't my strong point.
I never got a chance to capture the javascript. By the time I'd got my site sorted, their site was off-line, so I couldn't go and get a copy.