DavidR
12
Firstly is there a URL to what the guys as aumha said, with their statement that there are at least 4 rootkits/services protecting the dll (Dynamic Link Library, a file containing a library of instructions, see none the wiser, http://en.wikipedia.org/wiki/Dynamic-link_library, better).
If they can make that statement you would think they would go the extra yard and tell you more rather than leave you hanging, considering the file in question cp1041.nls, isn’t a .dll file.
So run all of the anti-rootkit tools, read the info available at the antirootkit.com link I gave and also post the contents of a hijackthis (HJT) log here and we will see what we can find.
Take things one step at a time and don’t think this is a big job rather a task with several small jobs. At the end of each stage (running one of the anti-rootkits, etc.) report the findings here before moving on to the next step. If there is something you are not sure about stop and ask, rather than bore on regardless.