My suggestion is to stop using the compromised server(s). It might already be running a process that you don't even know. So no matter what you do, he will still have a backdoor to the server unless you remove all those from your server which might be hard to track down. Back up all your data. Scan them for viruses. Ensure all of them are virus free. Create a new server (I'd recommend Linux although windows might be okay). Don't use passwords to login. Check if you can use public-private keys for authentication. (Google "RDP public key authentication")