Work in this order. The instinct is to delete the bad files and carry on, which is exactly how sites get reinfected within days.
1. Take a copy before you change anything
Even a compromised site is evidence. Take a full backup now, and keep it separate from your clean backups. Without it you cannot work out how they got in.
2. Change every password
cPanel, FTP, all database users, the site's own administrator accounts, and any account that shares that password elsewhere. Do this before cleaning, or you will clean a site the attacker can still walk back into.
3. Find out how they got in
Nearly always one of: an out-of-date plugin, theme or extension; a weak or reused password; or a password stolen from an infected computer. The access logs and the modification dates on the changed files will usually tell you when it started, which points at what changed around then.
4. Clean, or restore
Restoring a known-good backup from before the compromise is usually faster and safer than trying to pick out changed files, provided you then close whatever hole let them in. If you restore without fixing the cause, you will be back here shortly.
5. Update everything, then re-check
Bring the core software, plugins, themes and extensions fully up to date. Then look again for anything left behind, particularly unexpected administrator accounts, scheduled tasks and files in upload folders.
Tell us
Open a ticket. We can see things you cannot – what was being served, when it started, and whether anything is still running – and if the site is sending spam we need to know before it affects mail delivery for everybody.