So far so good - usually by this time I have already been hacked. I searched for the perp's IP on Google and found it in several discussions about hacking into community sites - apparently it is a problem all over the web. I assumed that the IP was spoofed but maybe not - that would explain why he was deleteing log files and changing "last login from" files.
In case anyone else suspects they have been hacked - what happens is the hackers place inline frames on your site using encryped code. These frames are invisible and sometimes you may not even realize that you have been hacked - especially on subsequent events.
The worst thing about all of this is that your members think they are getting viruses from visiting your site and traffic (and ad revenue) drops due to the redirects and members avoiding the site.
For me, the easiest way to check if I had been hacked was to click on "Show Hidden Elements" under the Miscellaneous tab on the Webmaster toolbar for Firefox.
Maybe you should try that on your site every once in a while as this issue is rampant on the web right now
