How did you clean your database while upgrading to 3.3.0-19? If the malicious javascript was already in the database, upgrading to the latest release won’t remove it.
What is the value of your files_dir in config.inc.php?
Regards,
Alec Smecher
Public Knowledge Project Team