hey all
just talked to my host
it had nothing to do with wordpress
I had a copy of this on my server -
http://www.phpfaber.com/i/products/urlinn/ - and they used urlinn_includes/config.php and exploited my server
natnet was on them pretty quickly and had it under control