What is the first thing you do if your website was hacked?
What would you do as first thing if your website was hacked? Taking the site from net? or rollback a backup? not realy or? Did you made any experiences in this way?
The first thing I would do is to take it off the net at least till I understand what exactly is the damage. Assessing what has been compromised in a timely manner is most crucial.
Take the site offline.
This is crucial. If the intruder is still in your system and you start poking around, they might notice that you have detected their presence and try to cover their tracks (i.e. delete things).
Take it off-line and restore the entire machine, not just the web pages, from your backups. Then, before putting it back on-line, fix the hole they used to get in.