So we managed to track down the source of the php injections that have been happening on our server, and if you have any problems with that like we do you might want to send them the information that has affected your website.
Our IT expert:
www.he.net , Hurricane Electric, is the internet provider that co-locates the server of the source of the hack. they said to send over any information we have about whats going on to support@he.net who will look in to this as well as forward the information to the customer who owns the server.
I suggest anyone who has this problem to do the same.
Apparently it is comming out of Freemont CA