Work in this order. Cleaning while the site is still being re-infected wastes the effort.
1. CONTAIN
Open a ticket so we can check the account server-side. Change the cPanel password, all application admin passwords, database passwords and FTP passwords. Delete FTP accounts and admin users you do not recognise.
2. TAKE A COPY
Back up the current infected state before changing anything. You may need it to identify the entry point later, or to recover content you have nowhere else.
3. IDENTIFY
Run ImunifyAV. Run an application-level scanner. Sort files by Last Modified in File Manager and review anything changed around the time the problem started. Check the error and raw access logs for the request that first uploaded a file.
4. CLEAN
The most reliable route is to restore a backup from before the infection, then immediately update everything.
Without a clean backup: replace all core files with fresh official copies, replace every plugin and theme with fresh downloads, remove anything you cannot account for, and inspect uploads folders for PHP files.
5. CLOSE THE ENTRY POINT
Update everything, remove nulled software, enable 2FA, fix permissions. Skipping this guarantees reinfection.
6. RECOVER REPUTATION
Request a review in Google Search Console once clean.