1. Issue notice to all members saying board will be done for next Xhrs for routine maintance
  2. Take board offline
  3. If running on your local machine (not a remote host) make backups and format / reinstall everything on your machine. Ensure when reinstalling that you include a Firewall and up-to-date AVP (incase it is more than your forum which has been comprimised). This might still need to be performed if it is your account the person has gained access to - tho it might just be me being overly paranoid
  4. Kill all other admin / mod accounts
  5. Change your admin password
  6. Kill current DB (mySQL?) user and create new one with different name / password (incase it is not forum but mySQL user which has been compromised
  7. Check forum software's website for any upgrades security patches
  8. Ensure server forum is running on is fully patched and upgraded
  9. Bring forum back online
  10. Start some form of logging procedure so you can find out exactly where an attack is coming from next time
  11. Start a routine backup procedure so should the worst happen again you dont lose much
  12. Ensure you keep up to date with all patches / fixes / upgrades
  13. Next time you post here try and include more information (where is frum running, what is it running on, what type of forum software is it, etc