Hi Steven Winderlich,

I think this executable was the source of the site warning: http://urlquery.net/report.php?id=7360874
https://www.virustotal.com/en/url/f675cf613a44503c8d49e7c4809a74e293d959389d3bc3150f7d649b78b9c8f6/analysis/
and only https://www.virustotal.com/en/file/0abaee9196ad6e11264b2fa04a601ca338604d25cc1442e42677c43d1b7910ea/analysis/1383768992/

Only Normal detected this as Suspicious_Gen7.CSH. Maybe our good friend Pondus can clear that up at Norman’s.
See: http://f.virscan.org/WEBTOOLOCX.exe.html

polonus