Using Web-sniffer.net it looks to me like he may have replaced some of your PHP files. You may only have to upload backup copies of the PHP, not the MySQL database.
As far as blocking him from accessing your site again, look at your VBulletin ADMIN log and your raw server log to see if you can identify the right IP address.
If you don't know how to do this stuff then you'll probably need to pay someone to harden your server.
|