Thanks to all for your help in this and especially to Rick for the excellent support and for rescuing my forum!
From what you all mentioned earlier in the post and from what I have subsequently found out - here is my theory of what has happened here...
I still did have all of the old version 6 cgi files on the server and for some reason many were set to 777. I think the intruder used those old files to acquire my account's Cpanel password and changed my files through Cpanel. I had changed the password after a previous incident but because the old files were still on the server he could get the new password.
This guy was even editing and deleting log files to cover his tracks - very persistant!
Last night I removed the old files and today I changed the Cpanel password (after multiple attacks this morning) - so I am hoping my "theory" is correct and that this is over.
We shall see what happens tomorrow I guess.