Currently I’ve just cleared the content and left a comment in it just in case there’s some sort of check they do to see if the file exists.
I see what you mean with the php injection – it’s done that to my files too. I can’t figure out how they’ve managed to do that (files are only writable to owners on server), so by clearing the content it would make their javascript invalid if they tried to run it again in the future.
Edit: I’ve just realised that php files can be edited through Appearance > Editor. This might be how the php files were altered.