It sounds like there is still a backdoor somewhere. Remember that they probably can't access the admincp, but they can still insert data via whatever method they are using to get in. It could be something appended to a plugin or template. I would install the
plugin search mod and search plugins and templates for things like base64 and display:none (which is actually used in some templates)
Make sure you look carefully at Maintenance > Diagnostics > Suspect file versions for unexpected contents.
You should update to 4.2.2 pl1.
Also, if you have wordpress installed - I recently restored a hacked vbulletin and found that their WP install even had things inserted into the files/templates. Make sure to take a close look at WP or any other software packages if you have them.
I'm assuming you already removed the install directory...