Heur.Suspicious@136634132 false / positiv ?

i run win7 64bit using premium comodo fw + av

ich habe returing setup.exe files in my temp folder

log :

Heur.Suspicious@136634132 C:\Windows\Temp\oiko.tmp\setup.exe

and a file fwtsqmfile00

if i delete oder put in safe mode

i will soon geht an other *tmp folder with the exact same file !

full system scan doesnt delete it.

i also tried 3.party software like

Malwarebytes’ Anti-Malware or Spybot - Search & Destroy

nothing helped or even show a warning.

the only thing that happens till now - is that my firefox 3.6 keep opening up sites that a rated as not secure , so i can stop it before its to late.

Hello kandesbuzler,

The file you have reported is not a False Positive. We recommend you to remove the file using Comodo Internet Security. If the problem persists you can ask for help from a Comodo GeekBuddy , they will be happy to help you solve your problem.

Best regards,
FlorinG

I still cant fix this

the setup exe will be deleted but the site popups still exists like

http://68.169.96.72/c.php?re=1&r=eNo1lLnOs0ASRR8I6YNuuhsI_sAY8ArGgNmSEVsbMBizG8TDjyeYqFR1ryo4wSk3yCFENihCDsBNd3bAuP_7t3F_vxX-f_wyDgDIcwCJPNqSOv8EHh4DW85jz10iz8jjQh5S3_gEi5ynUFvCo_7Uy91X38tj6lnVhkCa8jHHi0IWRVigXBpxMeQx_d8BC9F_iEhggkEWZ2IUcUiKCZRiPhMEPiVphsWNJxvYMuPjutroNOXzwZZ0HYbbuSjdsYo9UDY7pyC7XGN2w97gmiIJP2M-Yckf509Maz10V6fHvC1BKIzM-8MaVPBYiT3OIlWkRDBM-bhjDSYeO95hza97PksVOX_dESfOMCjYULOoWa6voa_JuPPla_UyA98V47Ari_UWMkiHQG_h8j7bASSovtDjTZLWZM_kvIVe1Mws7KfjYXkXzeBETR9PUVN7oSN9BbzH2cvwPJmcYuzGNxS-wa3oHOZpNq-BU9vKqLS9ChDpy_ndyQebuY_9jTnbb8Ntk1cHAcSpOxq86y57OqH6NNgRXGsvkQoSTuFNESl-jtMK7-FRXK_dPY-bkv0-dGVSc3wvLKVeRveRaVS-RJw--srZ2z9EKornMMyTm3d5MJ0e9-C5HhdtVCLVuRUSGVNzP9OZlM3F9z9f30J1hVZYDbq2n9mR6O4tGJaPdNXKS3sQ5vree5wer4EjRYZf9O9v4nBLSaXMZJi3yWSM4NvBy7sOwiuLDsQg-P7hzOVb3UJryRTm3IpVe-5G6rajL3wsVQbFnW-8RGdgkCxG8HJj6tZVMmRB8fg8J_x4v7jh5dNzp2rVopwZf_xBKgRcN7abXiVk1woN9ECzIrdoYyUdyt2NvDW7rvyDI2qWM3y8QK-KZyQJU_MJAxkjU2ZnIKsFx622DMRuPhg1f_1BZkUOyazYDscyPkXrfulozRs3xDUiuzPRazWty7Q2_ddM6fDgG4NV433vxqd2NvMw8fOzldePHX0G4iM0S0teiK16z2nR9TCGtuSGZntNTcXzmLd-ksrWiRdDY5cOdJrnCKK9hkil9xMqx6w9nR6BmvqpEZjmN2Xo85KpB_PTj30FrEtbFTiAzomQ_D33qlmfnPJAT3u2n3OX3OizUanCrvJpEBWKo_cyEcRTLayaSzZ-ZMruhOnh8dfGIc1XTugOs_GdUbw3C68HajvJ6Fyt945l1OzQG8y5sVm28I5ZrSUE62bhNT5oYbM4YCTI1qk2Pa1M5fhz4ImZrWdpQkvfur8r5rqybnsomBdi0ZFPv7hw7RpenPD2lMQBn28GOydXbRaQzz2Y49QO4siyuyyXH_1BMVmjGzHPIV_cmcAzqqWbj-zsd2JLDserd-8wr1wOWb1ezOcY1MyuW67ZT059lghOHtFi9LiEDS3RYvmY4JA6UzK9aOpPB273M6aE_yAn_knwT8A_T0FA_oD4BwH-A2Djtg1uKZ_y11rr40P6SevHGEBp2AAQeEHYACbo1-I2fgv9fE5qd00g-FkVlzHk_m0RIRSkJJZ4jOOIZABhEBOSAMRLWADZFsWYCIQIKEMSBhQRAAkPIvT7y2FBFP8L1oXqZg&u=081aafe6d5bb81dfa706fb346ee6cd5f&cid=8bdc66a21f00065c68ac9a3e231bdafd&rc=0&pa=&ref1=&ref2=