Please ensure you change all your administrator accounts for your community, hosting, FTP, etc... immediately.
The best recommendation afterwards would be to contact your hosting provider to see how they did this. Unless you uploaded the exploited file through an untrusted source, they likely gained access through your hosting panel, FTP, etc...