Karen you got a worm
read below you will find your .exe file listed
Here is your removal instructions scroll down to bottom its free....
I would type it myself but it is easy to show you the link.....
http://securityresponse.symantec.com...2.kalm@mm.html
W32.Kalm@mm is a worm that is written in VB. When it runs, it does the following:
It copies itself as:
%windir%\Setup.exe
%system\Setup32.exe
NOTES:
%windir% is a variable. The worm locates the Windows installation folder (by default this is C:\Windows or C:\Winnt) and copies itself to that location.
%system% is a variable. The worm locates the System folder and copies itself to that location. By default this is C:\Windows\System (Windows 95/98/Me), C:\Winnt\System32 (Windows NT/2000), or C:\Windows\System32 (Windows XP).
The worm then creates the file C:\Lymak.exe.bat. This batch file deletes all files and subfolders in:
%Windir%\Cursor\
%Windir%\Temp\
%Windir%\Command\
%Windir%\System\
%Windir%\System32\
%Windir%\Start Menu\Programs\Accessories\System Tools\
The batch file also deletes registry files and some antivirus program files.
The worm modifies C:\Autoexec.bat by adding instructions to format drive C. Symantec antivirus programs detect Autoexec.bat if it is modified by the worm.
The worm attempts to stop these antivirus and firewall program processes:
Aplica32.exe
Cfiadmin.exe
Cfiaudit.exe
Cfinet32.exe
Cfinet.exe
Iamserv.exe
Iamapp.exe
Pcfwallicon.exe
Vshwin32.exe
Vsecomr.exe
Webscanx.exe
Avconsol.exe
Vsstat.exe
Navapw32.exe
Navw32.exe
_Avpm.exe
Avpm.exe
Lockdown2000.exe