it has something to do with a that it tries to download, thankfully it infects a temporary internet file and it's easy to remove. It's a Win32/MS07-07!expliot the file that is infected is called cursor[1].ani in \Local Settings\Temporary Internet Files\Content.IE5\ENBVINLW\
Also known as Trojan.Anicmoo (Symantec) , Exploit-ANIfile.c (McAfee), Win32/MSA-935423!exploit, TrojanDownloader:Win32/Anicmoo.gen!D (MS OneCare)
Description
Win32/MSA-935423!exploit is a generic detection of animated cursor files that attempt to exploit a vulnerability in the handling of these file formats.
For more information please visit our Vulnerability Encyclopedia: "Microsoft Windows Animated Cursor remote code execution vulnerability":
http://www3.ca.com/securityadvisor/vulninfo/vuln.aspx?id=35196
or Microsoft "Vulnerability in Windows Animated Cursor Handling":
http://www.microsoft.com/technet/security/advisory/935423.mspx