All setup files should be deleted just to be safe. (None are useful anyway unless all are there.) But to be sure delete the setup.php as it is the most dangerous.
Unless you have serious server security issues as well, the hacker could not place the setup files back on your server. Besides, if he could do this, he could just replace the zp-config.php file alone, so why would he bother with the setup files