That seems to show that the CR_XX.tmp directory is related to Chrome, but they could have been a bit more imaginative than setup.exe…anything could be called setup.exe…
Well it shows one cannot take anything for granted and have to investigate when there is an alarm or rather warning to allow such a process with ThreatFire.
Good to have google and some Internet repositories to check against,