You have no idea how they got in? You could probably just install a patch for the time being. It was probably just some stupid unicode bug, I used to scan for those all the time and we'd packet people from about 10,000 compromised IIS servers. It wouldn't be hard for them to start an FTP service from their browser with one of these.
