Seriously?
How the heck does this happen to a real company, supposedly with a disaster recovery plan?
Seems like the obvious fix is blow away / reformat the compromised server, reload web application source code (backed up on another box, right?), reload application data (backed up on another box, right?) and away we go....
For a financial company???? <sadness>