For us, there are no other options: Flatten the system.
Jesper Johansson at Microsoft Security Management:
There are no guarantees when it comes to cleaning out a compromised system.
None … nada … zilch.
Thus, keeping a good, tested, and up to date backup is essential for getting the data back. Not recovering the complete system, just for recovering the data itself.
To date, we have only had a few one-off situations where the person with the compromised system did not want it rebuilt. In that case, we make it pretty clear, in writing, that there can be no guarantees that the system is clean after we have done our best to remove the offensive content.
Microsoft Small Business Specialists
Co-Author: SBS 2008 Blueprint Book