It is possible that there is a back-door on your site that is planting those DB injections, but it is more likely that the malicious injections are coming from outside of your site. If there was any malicious code in the files on your site then my plugin should be finding it. If it is only finding malicious injections in your DB then the hack is likely to be a direct DB injection using your DB credentials. First try changing you DB password and update your wp-config.php file to match. If the DB injections continue then I would suggest that you move your site to a move secure host.