You could hire someone (such as myself) to run through and change passwords and check access on the server (would probably take a bit as it'd include the install of PHPMyAdmin if it's not already installed on the server).
You'll definatley want to check which hosts have access to the MySQL server, and then change the passwords to all usernames (and likely purge the connect info for those addresses you don't know of).
You'll want to manage who has access to the forums, and who is an admin (and which you wish to purge)
You'll also want to be sure you change any passwords they may have had access to, even your own (or other admin's).
There won't be "trojans" in the db, however there may exist scripts that allow access to the db (such as the one which come with the mysql maintenance software like Navicat or SQLYog as they allow users to connect to servers which don't allow outside connections to connect).
So long as the old admin's dont have access, they cannot manage anything (assuming that any stored password data in the database is changed through whichever scripts they use).