If you don't have a back up, which although you haven't said it directly it doesn't sound like you do, it might be the best idea to just delete everything that the hacker had access to and start a fresh wordpress install. Obviously, if you have a back up it would be best to restore everything from that back up. It's probably going to be a lot more work to go through a bunch of code that you didn't write and might not understand fully rather than just starting over and being sure you got all the hacked bits out of the system. At least that is what I would do. You never know if the hacker added some way to monitor what you change your new password to or a back door to make it easier to get in and get it all jacked up again easier next time.
ugh, yeah you're right...
i wish i knew softopia could backup stuff :/