It's a bogus alert. The short version:
They are looking for the existence of a piece of code that was compromised at one point in time, and simply flagging us as infected if they see the file exists. Trouble is - the problem was patched two versions ago (I applied both updates), and there's no way for them to know what version we are running.
I feel like a broken record, but I'll say it again - there is no such thing as effective client-side antivirus that accurately warns against problematic web sites. They simply don't have access to the details of code on our server necessary to say one way or the other.
The best way to protect yourself from malicious code on web sites, is by running the latest versions of Chrome, Firefox or Safari. All of them in their default configuration give accurate warnings of sites that are problematic - even here. The two times we were infected, all these browsers reported it accurately - and equally important, they recognized in short order once we'd fixed things.