If you have a backup of the database the radical solution would be to delete the contents of the server and upgrade / update to the latest version 1.0.8
This way it ensures that there are no-longer files on the server that could be infected.
Preferably use a new database with your backed up DB dump, with a new password.
Next step:
Change all passwords for the manager (including all editors)
Change all passwords for FTP access
Been there, seen it, done it, not once, not twice
After doing this a few times you realise you need a fully working up-to-date copy on your local machine or on a different server as a back-up.