I'd argue this response was insufficient. I've always been taught that a clean wipe is the response to your box being rooted.<p>At step 3 one should be thinking "I now know nothing about this box, what's installed? What's modified?" You can't know if its been modified or rooted.<p>While I'm certain its possible to replace software in the system piece by piece until you trust it again, but that's much harder than what I would say is your only option:<p>Wipe the disk, put a a new install on it and restore your sites from backups.
Calling the guys who hacked you "script kids" and "idiots" is just childish. You failed to take basic security measures and got fucked over by people who know better than you. The bigger idiot here is the one who was hacked.