I'd go through the normal cleanup and audit process at this point. You'd want to check all of your logs for any abnormal activity to try and track down how they are editing those files.
A good place to start is by grabbing the time that one of the hacked files was actually edited, and then scanning your webserver logs for that same time. You should be able to track down if it's a web-based exploit with that method.
If you don't see any matches there, then you can do the same thing with your FTP and domain CP logs.
Last edited by Rick; 09/15/2009 1:39 PM.