Cleaning server from hacker actions is not on our side. It's beyond typical (free) support.
Returning files means that hacker hidden extra file that recovers them. Quite popular.
Please ask hosting support to scan your site deeply, and delete all suspicus. It can be also beyond /public_html/. Yes, they should have Firewall tools for that.
2nd option, would be to zip whole website (all files), download zip to your computer and scan using good Antivirus software and Malwarebytes tool (free is OK). Then after removing all weird files, delete files on server and upload cleaned package. Then run Joomla > install firewall and scan site again, update etc. It should take you about 1-2 hours. But it's free, your time only.
Unfortunately, we live in a time when the number of attacks on websites (private, commercial, medical, goverment) is enormous.