Hello,
I came to know of this exploit and looks like we too had this attack, we did the below:
1.Deleted install folder
2. Deleted suspicious admin user accounts
4. Refer thread -
https://vborg.vbsupport.ru/showthread.php?t=301892 as mentioned there I didn't have any Iframe injection , but there was a line added in the "header" template of one of our custom style that reads as "Kindly delete "install" directory of your forums. Otherwise you will keep getting hacked" and the suspicious lines were removed.
Also we notice that few templates in the custom style has edit history that says "Edited by .." the suspicious admin accounts with time stamp in the past year 2010.
Is there any other precautions that need to be done. Am I currently still exploited? What are the other security measures that I need to do to protect my forums.