Well, FWIW, I did something that might have been "dumb" (wouldn't be the first time in my life.)
I have a cronjob running (I alluded to in an earlier post) that deletes all php code from the writable directories. It's possible that may have interrupted the exploit...