I do not think the virus has got into his webpage because of some code he added thought the
ACP/CMS, so I recommend you to get the logs form your server from 2 weeks ago you detected the virus was active in your website. I think that should be engough time.
Please, get that logs as faster as you can, as the servers only storage that logs for 1-2 months. The most secure way is to contact your hosting support staff.
What do we can make with those logs?
With the logs we can seek the webpages the people has been got into, and surely the one(s) with the strings the hacker used to get into it and inyect the code that makes your webpage give that virus to the users.
Please, try to get them and send them to whoever you want at the Staff.
Also, make a backup of the actual files and the database and storage them out of any webserver. They could being required by the Staff when we get the vulnerability the hacker used to inyect those malignant code in order to make the security issue patch.