the "hacker" injected this in the footer:
<meta http-equiv="Refresh" content="0;url=http://www.gercekvadi.com/hacked.html"><br>
<meta http-equiv="Refresh" content="0;url=http://www.gercekvadi.com/hacked.html"><br>
<meta http-equiv="Refresh" content="0;url=http://www.gercekvadi.com/hacked.html"><br>