@dwardoric @xanderio @veer66 If the user's first "bash" in his PATH is a rogue one, you really can't do much for him: he is already doomed.
If he did this himself, he probably deserves it. If his administrator did this… well his administrator is already in position of changing /bin/bash with a not trustworthy one.