I think it would be an extraordinary coincidence for malware to have occurred immediately after a hard-disk crash!
Why complicate the issue? Occam's razor applies here, I think.
It's a server. It's been running reliably for ages until a reason comes to warrant a reboot. Code entered into HKLM/Software/Microsoft/Windows/CurrentVersion/Run is then initiated. Server starts virus payload and runs like a dog.
As indicated by the OP, he is considering a rebuild as an alternative. Therefore, an hour's work with an antimalware tool rather than that is a very cheap alternative, n'est ce pas?