I wouldnt assume anything, thats not real safe, and may be what has led to this in the first place.
If you were hacked, which given your version, is a possibility, you have more to worry about than disabled plugins and 100 some odd spam comments.
Best case scenario (just wordpress):
they have your WP admin password
Worst case (home directory compromised):
they have your WP admin password
if they can read your files, they have your mysql password, and may have your ftp password, if they're the same.
--------
Looking at your plugins directory, I also see your using wp-db-backup, you might want to take a look at what version youre running of that, since there is directory traversal vulnerability in an older version.