Hello,
Recently, my forum got hacked, the hacker used the "C99madShell v. 2.0 madnet edition" and changed my paypal adresses to get the membership donations. He also created some new administrators accounts.
So i just noticed that today by going on the paid subscriptions options on the admincp :
So if you know how can i fix it and how can i do to avoid this again.
EDIT : I just used the Suspect File Versions in Maintenance in the admincp and i found 3 files that the hack seems to has uploaded : 3 php files (which one was a config of the shell) and when i deleted one of the php file, it also deleted another file : "mine.tar.gz" which is without doubts the file that the hacker has uploaded on my ftp to run the shell script.
Cordially