Hi guys!
Here is a how-to that may be helpful to prevent of being infected and help you to find and remove malware code if the site is already hacked.
Let's go!
Many of the recent web-pages malicious code injections we are facing — are the result of a virus on PCs that have FTP access to websites. It's likely that your computer/webmaster's pc is infected by malware that steals FTP access info and sends it to remote zombie computers which then inject the victim website's pages with JavaScript or hidden iframes pointing to malicious websites.
In order to fix the issue, you should look through this instruction: