Hello,
I've been through this process of recovering from the very hack you are talking about, on multiple websites.
What's probably going on is that you applied the JoomShaper security updates to an infected website, so those injected files are still lying around, and there could be other files, and/or compromised files, and the Joomla database can also no longer be trusted.
When the hackers inject files, they follow up by trying to execute the files, for example .php files. They can also inject code directly into the Joomla database.
The best way to approach this problem is to restore the website from a backup that you know was taken prior to the hacking. Then you apply the security updates. Then you bring the site back online.