If you’re unable to clean your site(s) successfully, there are reputable organizations that can clean your sites for you. Sucuri and Wordfence are a couple.
]]>The new user setup could be done via vulnerable plugin allowing remote code injection.
It is worth to scan WordPress files (file system) to verify there is no malware infection in PHP files and well try to investigate website access logs for suspicious HTTP requests.
You can install audit log plugin and wait for next reinfection. Hopefully, this plugin will catch reinfection source.
]]>1 – please take a care to update all your plugins since there is a big chance the code injection going via one of the installed plugins
2 – reset all passwords you are using to manage this website (cPanel, WordPress admin and FTP passwords)
]]>