As far as I remember, you need to add your site and then verify that it is your site (a small html file is generated and you need to upload it to your site). I have had a few sites infected, all of them wordpress sites and the code was injected into the theme .php files (nomrally two files) and on some the htaccess file was changed too.
|