The redirects are being inserted into the database through the ADMINCP. Replacing the scripts won't accomplish anything.
Your best bet is to look at the Admin Log and see which functions the bogus admin accounts accessed. Then go to those tools and look at the most recently changed/added data. This could be notices, templates, plugins -- anything where you can embed HTML code that is executed.
|