If you have a backup of includes/config.inc.php that would probably get you going again, however the exploit would still be there and you might be down again a few minutes later if the troublemaker is persistant. If you do go this route I'd set the config.inc.php file and theme.inc.php file to unwriteable like 644. You wouldn't be able to update the config from the control panel but this would keep it from being tampered with.