1. Restore is not enough - they got in somehow. Make sure everything is fully up to date. Make sure no mulled plugins, or little known plugins. Make sure no other sites are hosting with it on same shared hosting. If one of those things stands out as a possible cause then great, if not then you’re gonna get hacked again. In this case best to delete and add WP files from new. Keep only database, then put things back one by one.
2. Change all your passwords.
3. Install and configure wordfence (assuming it is WordPress you’re using).
4. Do a scrape of site:yourdomain.com from google, then extract all the spam pages and submit them to google.
I’ve done exactly this several times before and got the issue fully sorted.