Bruce
I think I have good news but I won't be over joyed until you confirm that all is OK.
I re-ran catchme.exe that showed the C:\WINDOWS\TEMP\TMP0000008C22B43A646E2CBA31
I wonder if I had some file open at that time.
Here is the log from catchme
catchme 0.2 W2K/XP/Vista - userland rootkit detector by Gmer, 17 October 2006
http://www.gmer.net
scanning hidden processes ...
scanning hidden services ...
scanning hidden autostart entries ...
scanning hidden files ...
scan completed successfully
hidden processes: 0
hidden services: 0
hidden files: 0
I'm running hijackThis now. I'll post results when completed.