Well because I thought it would be a one of, so I just reinstalled WordPress. I uploaded the files for 2.3.2 but I’m not sure if it updated correctly. I just reinstalled and imported by databases and it seems that they used that as when I imported, the hacking message was back again. I was using a custom username.
I’ve deleted the post they used and it seems to have fixed the hack. Is there anything I can do to be sure I’m safe?