An infection rarely stays in one place
Malicious code may enter through a vulnerable plugin, stolen credentials or an infected file. From there it can create additional files, modify existing code or install mechanisms that restore access later.
Deleting one suspicious file is often not enough. The original cause should be identified, credentials changed, applications updated and a clean backup used where appropriate to reduce the chance of reinfection.