If your site as been hack link is the last thing you need to worry about.
Here the step to take
1.take site offline
2.review all your extension and see if there are on the list here
docs.joomla.org/Security_Checklist_7
no need to run the forum post assistant and security tool at this time
Also can you confirm
that legacy is not on
and that you are not still using J 1.0 extensions
As you know they are no longer supported on jed so we cannot confirm if there any exploit in them
Best rule for safe site.
1. do not use jos_
2.do not use legacy
3.use only native J 1.5 extension
4.Back up your site daily
5.look at vel list daily or ad rss feed to your admin panel
Pierre
Please be kind no PM without asking,Pm without asking will result in fow list
help also on freenode irc #joomla,hosting solution for a great value 20 users only per server.
Pierre.