You can skip steps 1 through 3. Backup all data that you know for certain is still safe, wipe the disk entirely, and do a clean reinstall. If the box was rooted, there is no way to determine the extent of the intrusion, and therefore any attempts to replace solely the compromised aspects of the system would be irrelevant. --
Will rsync operate without cp, ls, etc? Chris