Hi @creativeone, thanks for getting in touch.
The plugin doesn’t deactivate or uninstall itself by design for any reason.
We always recommend that you make a full backup of the site before making any further changes. After this, make sure to remove any users with administrative access that you don’t recognize as a priority. That’s just in case somebody has created a new account to retain access to your site. It’s possible that an attack vector outside of WordPress has been used, though.
As a rule, any time I think someone’s site has been compromised I also tell them to update their passwords for their hosting control panel, FTP, WordPress admin users, and database. Make sure to do this.
I will provide our site cleaning instructions for you, just in case the steps can help: https://www.wordfence.com/docs/how-to-clean-a-hacked-wordpress-site-using-wordfence/
Additionally, you might find the WordPress Malware Removal section in our free Learning Center helpful. We provide a site cleaning service should you need further assistance, as do other companies. If you find files that seem suspicious and Wordfence isn’t picking them up, email them to samples @ wordfence . com and we’ll take a look.
Many thanks,
Peter.