Standard practice after a server has been cracked is to wipe the box. Grab any logifles you can, try to figure out what he did, and then blow it away and reinstall the OS. You dont know what he did to the machine, and there isnt any real way to find out.
Consider using something more secure than FTP in the future. SSH/SCP or SFTP are good places to start.
"Good people do not need laws to tell them to act responsibly, while bad people will find a way around the laws."