I saw exactly the same behavior in another invison community.
I believe the actions you took are not enough, You'll almost get hacked again.
As a temp. action, the webmaster added a rule to the htaccess file to prevent the hacker from writing to the index.php files.
Although we didn't find out the root cause, but this action stopped the hacker from messing around.
I also belive there's back door, maybe from another software installed on the sever.
May I ask you some questions? Do you have WordPress installed on the same website? Do you mind sharing a list of apps or plugins you have for your invision community?