You should *always* notify your web host, especially if you are in a shared hosting environment. Do not delete any files from your server until your host has had a chance to examine them. Or better still, ZIP them up and send them to your host with a trouble/support ticket.
Often, it’s not YOUR site through which the hacker gained access. On a shared server, you are only as secure as the most lax person using the space so …. it could have been anyone’s account on that server that allowed the hacker access. But as always, to be safe, change ALL your account passwords.
And YES, TransPersonal‘s recommendation to change the default database prefix is excellent advice and one more way to lock down your WP installation. ??
Good luck.