Here is the info they sent me
Your site was not reported directly. We received a report regarding aol phishing emails coming from the server your account is on. After investigating, we found a page named '.copyright.php' on your account that was being used to spam. We also found a php shell script with the title information '!C99Shell v. 1.0 pre-release build #13!'. This was used to gain complete access to your account. The hackers might have used an exploit in your board to put this script on your server. Once the script was uploaded, they had complete control.
In the previous email they told me these files were uploaded on May 27th....which means there is an exploit still in the board! and this could happen all over again even though I changed the passwords to everything.