Hi Donovansrb10,
The EOT there is marking the end of the gif data source file, separating it from the PHP backdoor code part.
That is why I run webbug detector extension in GoogleChrome to be aware to webbugs on a page, but normally webbugs are not infected via rfi,
Inside the code we find -> $lol is $_GET['lol']; <- (is equals = pol), lots of this particular RFI can be found via RFI logs,
polonus