I wouldn’t break my mind about which files are exactly mandatory to be replaced. Just replace wp-admin
and wp-includes
— if he just had access to your wordpress administration I would make sure to check all of the theme and plugins files which are accessible through the administration panel if he included base64
malware code and look-a-like. There are plugins for novice users (no shame) to check for such things – this post at WPMU.org goes over free themes which isn’t interesting in your case, however they cover what tools you may use in such a scenario.
Here’s the WordPress Codex Files list which gives you a good overview which files do what, what they control, what they’re needed for and so on.
Some links to similar issues (blank/white page):