Thanks ozzy. I'm familiar with those (and also
this) but didn't find (or maybe I missed) what to search for in the access logs.
I have already taken all steps in the guide "Fixing your site after you have been hacked" several times, but continue to get admin users injected in my database.
Any help with searching raw access logs to determine how it's being done would be appreciated.