I use Avira Internet Security 2012 which is what identified it and blocked it, first by notifying me that a program was trying to open a TCP connection which I denied, then it wanted to open a Microsoft application which I also denied. MWB found it, quarantined and removed it. This scenario repeated each time I visited the site while I was there, so it didn't come from anywhere else, each time I had already ran a scan prior that morning. I also deleted all restore points to prevent Win7 from seeing it as an OS file and restoring it on the next restart, then created a new restore point after it was gone for sure.