So my plugin is finding and fixing these threats but you just keep getting hacked with more of them.

Look in the Quarantine for the exact time of the last infection that you cleaned, then check you acces_log file to see what scripts or URLs were being accessed at that exact time. Hopefully that will indicate how you are getting re-infected so that you can plug up the security hole.