Also check to see what is in CRON, to see if any php scripts are there. But if the box was pwnt, it’s pretty easy to hide stuff from the web admin user/s. That being said, this was done with an exploit, and if that wasn’t patched, then… yeah. 😉
There’s probably some code running somewhere in php that’s just re-"installing" this to the public pages. The first part of the battle would be to figure out what exploit script is being used via php, and find out where it does everything by default. The php script for the root access probably has a name and credits in it.