downloaded the database to an external device. deleted the database on the hosting server and pointed the domain to a basic html maintenance page. then we ran the db file we downloaded through db scanners, several different ones. the malicious code was lurking in this sliders data in a table. even after removing the plugin. we are still in the process of testing the db files via virtual machines & db readers to be sure we do not miss any bad files. originally the malicious files infected all of my wordpress db’s. cleaned them all, but it came back in one – that is where we tracked it down to this slider.