Things change rapidly in the WordPress world. The content in this post is more than a year old and may no longer represent best practices.
Adria Richards gave a great presentation on what to do if your site has already been hacked. I’m embedding the slides here, but you should read her complete post, because it contains links to other resources mentioned in the presentation.
Slides no longer available on SlideRocket as of July 3, 2017.