C:\rrbackups?

Everytime I run the scans, I get a notification after it's completed that there is 1 item that may be affecting hundreds of objects on my computer and there doesn't seem to be anything to do to fix the issue. It seems as if all the objects are in some place titled C:\RRbackups. Here is part of that portion of the log (because it's large and I don't want to stretch out the page too much) :


Remaining issues:Object Name Threat Name Final Status


C:\RRbackups\SIS\C\0 Rootkit-Hidden Items Hidden


C:\RRbackups\SIS\C Rootkit-Hidden Items Hidden


C:\RRbackups\Documents and Settings\Trisha\Application Data\Microsoft\SystemCertificates\My\CTLs Rootkit-Hidden Items Hidden


C:\RRbackups\Documents and Settings\Trisha\Application Data\Microsoft\SystemCertificates\My\CRLs Rootkit-Hidden Items Hidden


C:\RRbackups\Documents and Settings\Trisha\Application Data\Microsoft\SystemCertificates\My\Certificates Rootkit-Hidden Items Hidden


C:\RRbackups\Documents and Settings\Trisha\Application Data\Microsoft\SystemCertificates\My Rootkit-Hidden Items Hidden


C:\RRbackups\Documents and Settings\Trisha\Application Data\Microsoft\Protect\S-1-5-21-4202826613-1114058476-797053376-500\Preferred Rootkit-Hidden Items Hidden


C:\RRbackups\Documents and Settings\Trisha\Application Data\Microsoft\Protect\S-1-5-21-4202826613-1114058476-797053376-500\ef5e32e7-2869-44bb-9443-0e47adee18ea Rootkit-Hidden Items Hidden


C:\RRbackups\Documents and Settings\Trisha\Application Data\Microsoft\Protect\S-1-5-21-2610168659-4123940765-1932575519-500\Preferred Rootkit-Hidden Items Hidden


C:\RRbackups\Documents and Settings\Trisha\Application Data\Microsoft\Protect\S-1-5-21-2610168659-4123940765-1932575519-500\846cfe33-2251-43ad-9246-483bf0c56dde Rootkit-Hidden Items Hidden


C:\RRbackups\Documents and Settings\Trisha\Application Data\Microsoft\Protect\S-1-5-21-2565432985-3520619055-3017979378-1008\Preferred Rootkit-Hidden Items Hidden


C:\RRbackups\Documents and Settings\Trisha\Application Data\Microsoft\Protect\S-1-5-21-2565432985-3520619055-3017979378-1008\d93f2e29-71c8-4a06-b26f-5b36a579ed1c Rootkit-Hidden Items Hidden


C:\RRbackups\Documents and Settings\Trisha\Application Data\Microsoft\Protect\S-1-5-21-2565432985-3520619055-3017979378-1008\c3044657-3d8f-442d-a639-af1030890558 Rootkit-Hidden Items Hidden


C:\RRbackups\Documents and Settings\Trisha\Application Data\Microsoft\Protect\S-1-5-21-2565432985-3520619055-3017979378-1008\adcd9669-a675-4883-ae54-b5a1eec8cfe8 Rootkit-Hidden Items Hidden


C:\RRbackups\Documents and Settings\Trisha\Application Data\Microsoft\Protect\S-1-5-21-2565432985-3520619055-3017979378-1008\8028be75-65ca-4a1d-8b32-5a3b6782fbc7 Rootkit-Hidden Items Hidden


C:\RRbackups\Documents and Settings\Trisha\Application Data\Microsoft\Protect\S-1-5-21-2565432985-3520619055-3017979378-1008\7034b79f-0944-455f-9349-618746c3da11 Rootkit-Hidden Items Hidden


C:\RRbackups\Documents and Settings\Trisha\Application Data\Microsoft\Protect\S-1-5-21-2565432985-3520619055-3017979378-1008\67c6b429-0c00-4782-a4b2-1090df3dffb1 Rootkit-Hidden Items Hidden


C:\RRbackups\Documents and Settings\Trisha\Application Data\Microsoft\Protect\S-1-5-21-2565432985-3520619055-3017979378-1008\679a2bdc-4251-4e05-996b-ebcae58c65c2 Rootkit-Hidden Items Hidden


C:\RRbackups\Documents and Settings\Trisha\Application Data\Microsoft\Protect\S-1-5-21-2565432985-3520619055-3017979378-1008\63ebb177-d45d-4cfd-85fc-22b5384994b0 Rootkit-Hidden Items Hidden


C:\RRbackups\Documents and Settings\Trisha\Application Data\Microsoft\Protect\S-1-5-21-2565432985-3520619055-3017979378-1008\42f9df0e-fe55-4947-8e83-7c8986934612 Rootkit-Hidden Items Hidden


C:\RRbackups\Documents and Settings\Trisha\Application Data\Microsoft\Protect\S-1-5-21-1339109310-2534669650-537350892-500\Preferred Rootkit-Hidden Items Hidden


C:\RRbackups\Documents and Settings\Trisha\Application Data\Microsoft\Protect\S-1-5-21-1339109310-2534669650-537350892-500\d7a3ba97-751f-4add-a182-bd401d3b9660 Rootkit-Hidden Items Hidden


C:\RRbackups\Documents and Settings\Trisha\Application Data\Microsoft\Protect\S-1-5-21-4202826613-1114058476-797053376-500 Rootkit-Hidden Items Hidden


C:\RRbackups\Documents and Settings\Trisha\Application Data\Microsoft\Protect\S-1-5-21-2610168659-4123940765-1932575519-500 Rootkit-Hidden Items Hidden


C:\RRbackups\Documents and Settings\Trisha\Application Data\Microsoft\Protect\S-1-5-21-2565432985-3520619055-3017979378-1008 Rootkit-Hidden Items Hidden


C:\RRbackups\Documents and Settings\Trisha\Application Data\Microsoft\Protect\S-1-5-21-1339109310-2534669650-537350892-500 Rootkit-Hidden Items Hidden


C:\RRbackups\Documents and Settings\Trisha\Application Data\Microsoft\Protect\CREDHIST Rootkit-Hidden Items Hidden


C:\RRbackups\Documents and Settings\Trisha\Application Data\Microsoft\Crypto\RSA\S-1-5-21-2565432985-3520619055-3017979378-1008\cb9806374345b8842b48b4e820940706_2ac079c8-4aa9-4ca9-819f-8784099f114c Rootkit-Hidden Items Hidden


C:\RRbackups\Documents and Settings\Trisha\Application Data\Microsoft\Crypto\RSA\S-1-5-21-2565432985-3520619055-3017979378-1008\8f71098770f72c7a67cd8f1151619865_2ac079c8-4aa9-4ca9-819f-8784099f114c Rootkit-Hidden Items Hidden


C:\RRbackups\Documents and Settings\Trisha\Application Data\Microsoft\Crypto\RSA\S-1-5-21-2565432985-3520619055-3017979378-1008\743d3f200dd5ca60391a68d5b3bdb4b4_2ac079c8-4aa9-4ca9-819f-8784099f114c Rootkit-Hidden Items Hidden


C:\RRbackups\Documents and Settings\Trisha\Application Data\Microsoft\Crypto\RSA\S-1-5-21-2565432985-3520619055-3017979378-1008\6b29ae44e85efac3c72ff4d1865d73f1_2ac079c8-4aa9-4ca9-819f-8784099f114c Rootkit-Hidden Items Hidden


C:\RRbackups\Documents and Settings\Trisha\Application Data\Microsoft\Crypto\RSA\S-1-5-21-2565432985-3520619055-3017979378-1008 Rootkit-Hidden Items Hidden


C:\RRbackups\Documents and Settings\Trisha\Application Data\Microsoft\Crypto\RSA Rootkit-Hidden Items Hidden


C:\RRbackups\Documents and Settings\Trisha\Application Data\Microsoft\SystemCertificates Rootkit-Hidden Items Hidden


C:\RRbackups\Documents and Settings\Trisha\Application Data\Microsoft\Protect Rootkit-Hidden Items Hidden


C:\RRbackups\Documents and Settings\Trisha\Application Data\Microsoft\Crypto Rootkit-Hidden Items Hidden


C:\RRbackups\Documents and Settings\Trisha\Application Data\Lenovo\Client Security Solution Rootkit-Hidden Items Hidden


C:\RRbackups\Documents and Settings\Trisha\Application Data\Microsoft Rootkit-Hidden Items Hidden


C:\RRbackups\Documents and Settings\Trisha\Application Data\Lenovo Rootkit-Hidden Items Hidden


C:\RRbackups\Documents and Settings\Trisha\Application Data Rootkit-Hidden Items Hidden


C:\RRbackups\Documents and Settings\NetworkService\Application Data\Microsoft\SystemCertificates\My\CTLs Rootkit-Hidden Items Hidden


C:\RRbackups\Documents and Settings\NetworkService\Application Data\Microsoft\SystemCertificates\My\CRLs Rootkit-Hidden Items Hidden


C:\RRbackups\Documents and Settings\NetworkService\Application Data\Microsoft\SystemCertificates\My\Certificates Rootkit-Hidden Items Hidden


C:\RRbackups\Documents and Settings\NetworkService\Application Data\Microsoft\SystemCertificates\My Rootkit-Hidden Items Hidden


C:\RRbackups\Documents and Settings\NetworkService\Application Data\Microsoft\Protect\S-1-5-20\Preferred Rootkit-Hidden Items Hidden


C:\RRbackups\Documents and Settings\NetworkService\Application Data\Microsoft\Protect\S-1-5-20\e645de08-14c6-48e6-a9d0-a20b3fc48ce7 Rootkit-Hidden Items Hidden


C:\RRbackups\Documents and Settings\NetworkService\Application Data\Microsoft\Protect\S-1-5-20\e5b0dd94-3cb0-44cb-8a87-6ca35447504a Rootkit-Hidden Items Hidden


C:\RRbackups\Documents and Settings\NetworkService\Application Data\Microsoft\Protect\S-1-5-20\aa5fb6cd-96b3-40c3-b4b3-8937ee62d49a Rootkit-Hidden Items Hidden


C:\RRbackups\Documents and Settings\NetworkService\Application Data\Microsoft\Protect\S-1-5-20\7b4cdd48-db69-4798-9c17-a59ebae25f06 Rootkit-Hidden Items Hidden


C:\RRbackups\Documents and Settings\NetworkService\Application Data\Microsoft\Protect\S-1-5-20\64078d62-8e54-4091-88c6-518f90589476 Rootkit-Hidden Items Hidden


C:\RRbackups\Documents and Settings\NetworkService\Application Data\Microsoft\Protect\S-1-5-20\04aec46f-27fc-48ee-9df2-189819474441 Rootkit-Hidden Items Hidden


C:\RRbackups\Documents and Settings\NetworkService\Application Data\Microsoft\Protect\S-1-5-20\01487047-2dfa-417a-b442-dfe1eb175000 Rootkit-Hidden Items Hidden


C:\RRbackups\Documents and Settings\NetworkService\Application Data\Microsoft\Protect\S-1-5-20 Rootkit-Hidden Items Hidden


C:\RRbackups\Documents and Settings\NetworkService\Application Data\Microsoft\Protect\CREDHIST Rootkit-Hidden Items Hidden


C:\RRbackups\Documents and Settings\NetworkService\Application Data\Microsoft\Crypto\RSA\S-1-5-20\94498385663a229a93d423c6d144ae0b_2ac079c8-4aa9-4ca9-819f-8784099f114c Rootkit-Hidden Items Hidden


C:\RRbackups\Documents and Settings\NetworkService\Application Data\Microsoft\Crypto\RSA\S-1-5-20 Rootkit-Hidden Items Hidden


C:\RRbackups\Documents and Settings\NetworkService\Application Data\Microsoft\Crypto\RSA Rootkit-Hidden Items Hidden


C:\RRbackups\Documents and Settings\NetworkService\Application Data\Microsoft\SystemCertificates Rootkit-Hidden Items Hidden


C:\RRbackups\Documents and Settings\NetworkService\Application Data\Microsoft\Protect Rootkit-Hidden Items Hidden


C:\RRbackups\Documents and Settings\NetworkService\Application Data\Microsoft\Crypto Rootkit-Hidden Items Hidden


C:\RRbackups\Documents and Settings\NetworkService\Application Data\Microsoft Rootkit-Hidden Items Hidden


C:\RRbackups\Documents and Settings\NetworkService\Application Data Rootkit-Hidden Items Hidden


C:\RRbackups\Documents and Settings\LocalService\Application Data\Microsoft\SystemCertificates\My\CTLs Rootkit-Hidden Items Hidden


C:\RRbackups\Documents and Settings\LocalService\Application Data\Microsoft\SystemCertificates\My\CRLs Rootkit-Hidden Items Hidden


C:\RRbackups\Documents and Settings\LocalService\Application Data\Microsoft\SystemCertificates\My\Certificates Rootkit-Hidden Items Hidden


C:\RRbackups\Documents and Settings\LocalService\Application Data\Microsoft\SystemCertificates\My Rootkit-Hidden Items Hidden


C:\RRbackups\Documents and Settings\LocalService\Application Data\Microsoft\SystemCertificates Rootkit-Hidden Items Hidden


C:\RRbackups\Documents and Settings\LocalService\Application Data\Microsoft Rootkit-Hidden Items Hidden


C:\RRbackups\Documents and Settings\LocalService\Application Data Rootkit-Hidden Items Hidden


C:\RRbackups\Documents and Settings\Default User\Application Data\Microsoft\SystemCertificates\My\CTLs Rootkit-Hidden Items Hidden


C:\RRbackups\Documents and Settings\Default User\Application Data\Microsoft\SystemCertificates\My\CRLs Rootkit-Hidden Items Hidden


C:\RRbackups\Documents and Settings\Default User\Application Data\Microsoft\SystemCertificates\My\Certificates Rootkit-Hidden Items Hidden


C:\RRbackups\Documents and Settings\Default User\Application Data\Microsoft\SystemCertificates\My Rootkit-Hidden Items Hidden


C:\RRbackups\Documents and Settings\Default User\Application Data\Microsoft\Protect\S-1-5-21-4202826613-1114058476-797053376-500\Preferred Rootkit-Hidden Items Hidden


C:\RRbackups\Documents and Settings\Default User\Application Data\Microsoft\Protect\S-1-5-21-4202826613-1114058476-797053376-500\ef5e32e7-2869-44bb-9443-0e47adee18ea Rootkit-Hidden Items Hidden


C:\RRbackups\Documents and Settings\Default User\Application Data\Microsoft\Protect\S-1-5-21-2610168659-4123940765-1932575519-500\Preferred Rootkit-Hidden Items Hidden


C:\RRbackups\Documents and Settings\Default User\Application Data\Microsoft\Protect\S-1-5-21-2610168659-4123940765-1932575519-500\846cfe33-2251-43ad-9246-483bf0c56dde Rootkit-Hidden Items Hidden


C:\RRbackups\Documents and Settings\Default User\Application Data\Microsoft\Protect\S-1-5-21-1339109310-2534669650-537350892-500\Preferred Rootkit-Hidden Items Hidden


C:\RRbackups\Documents and Settings\Default User\Application Data\Microsoft\Protect\S-1-5-21-1339109310-2534669650-537350892-500\d7a3ba97-751f-4add-a182-bd401d3b9660 Rootkit-Hidden Items Hidden


C:\RRbackups\Documents and Settings\Default User\Application Data\Microsoft\Protect\S-1-5-21-4202826613-1114058476-797053376-500 Rootkit-Hidden Items Hidden


C:\RRbackups\Documents and Settings\Default User\Application Data\Microsoft\Protect\S-1-5-21-2610168659-4123940765-1932575519-500 Rootkit-Hidden Items Hidden


C:\RRbackups\Documents and Settings\Default User\Application Data\Microsoft\Protect\S-1-5-21-1339109310-2534669650-537350892-500 Rootkit-Hidden Items Hidden


C:\RRbackups\Documents and Settings\Default User\Application Data\Microsoft\Protect\CREDHIST Rootkit-Hidden Items Hidden


C:\RRbackups\Documents and Settings\Default User\Application Data\Microsoft\Crypto\RSA Rootkit-Hidden Items Hidden


C:\RRbackups\Documents and Settings\Default User\Application Data\Microsoft\SystemCertificates Rootkit-Hidden Items Hidden


C:\RRbackups\Documents and Settings\Default User\Application Data\Microsoft\Protect Rootkit-Hidden Items Hidden


C:\RRbackups\Documents and Settings\Default User\Application Data\Microsoft\Crypto Rootkit-Hidden Items Hidden


C:\RRbackups\Documents and Settings\Default User\Application Data\Lenovo\Client Security Solution Rootkit-Hidden Items Hidden


C:\RRbackups\Documents and Settings\Default User\Application Data\Microsoft Rootkit-Hidden Items Hidden


C:\RRbackups\Documents and Settings\Default User\Application Data\Lenovo Rootkit-Hidden Items Hidden


C:\RRbackups\Documents and Settings\Default User\Application Data Rootkit-Hidden Items Hidden


C:\RRbackups\Documents and Settings\All Users\Application Data\Microsoft\Crypto\RSA\S-1-5-18\d42cc0c3858a58db2db37658219e6400_2ac079c8-4aa9-4ca9-819f-8784099f114c Rootkit-Hidden Items Hidden


C:\RRbackups\Documents and Settings\All Users\Application Data\Microsoft\Crypto\RSA\S-1-5-18\b973ec0ff915c48a18fe09064ce3a22d_2ac079c8-4aa9-4ca9-819f-8784099f114c Rootkit-Hidden Items Hidden


C:\RRbackups\Documents and Settings\All Users\Application Data\Microsoft\Crypto\RSA\S-1-5-18\a81bb17e1f5dc49a730b06b63f6d28e9_2ac079c8-4aa9-4ca9-819f-8784099f114c Rootkit-Hidden Items Hidden


C:\RRbackups\Documents and Settings\All Users\Application Data\Microsoft\Crypto\RSA\S-1-5-18\8f71098770f72c7a67cd8f1151619865_2ac079c8-4aa9-4ca9-819f-8784099f114c Rootkit-Hidden Items Hidden


C:\RRbackups\Documents and Settings\All Users\Application Data\Microsoft\Crypto\RSA\S-1-5-18\6d14e4b1d8ca773bab785d1be032546e_2ac079c8-4aa9-4ca9-819f-8784099f114c Rootkit-Hidden Items Hidden


C:\RRbackups\Documents and Settings\All Users\Application Data\Microsoft\Crypto\RSA\S-1-5-18\42e7e898003fbdeb9585806ee1664b51_2ac079c8-4aa9-4ca9-819f-8784099f114c Rootkit-Hidden Items Hidden


C:\RRbackups\Documents and Settings\All Users\Application Data\Microsoft\Crypto\RSA\S-1-5-18 Rootkit-Hidden Items Hidden


C:\RRbackups\Documents and Settings\All Users\Application Data\Microsoft\Crypto\RSA Rootkit-Hidden Items Hidden


C:\RRbackups\Documents and Settings\All Users\Application Data\Microsoft\Crypto Rootkit-Hidden Items Hidden


C:\RRbackups\Documents and Settings\All Users\Application Data\Microsoft Rootkit-Hidden Items Hidden


C:\RRbackups\Documents and Settings\All Users\Application Data Rootkit-Hidden Items Hidden


C:\RRbackups\Documents and Settings\Administrator\Application Data\Microsoft\Crypto Rootkit-Hidden Items Hidden


C:\RRbackups\Documents and Settings\Administrator\Application Data\Microsoft Rootkit-Hidden Items Hidden


C:\RRbackups\Documents and Settings\Administrator\Application Data\Lenovo Rootkit-Hidden Items Hidden


C:\RRbackups\Documents and Settings\Administrator\Application Data Rootkit-Hidden Items Hidden


C:\RRbackups\Documents and Settings\Trisha Rootkit-Hidden Items Hidden


C:\RRbackups\Documents and Settings\NetworkService Rootkit-Hidden Items Hidden


C:\RRbackups\Documents and Settings\LocalService Rootkit-Hidden Items Hidden


C:\RRbackups\Documents and Settings\Default User Rootkit-Hidden Items Hidden


C:\RRbackups\Documents and Settings\All Users Rootkit-Hidden Items Hidden


C:\RRbackups\Documents and Settings\Administrator Rootkit-Hidden Items Hidden


C:\RRbackups\common\usersids.dat Rootkit-Hidden Items Hidden


C:\RRbackups\common\tvtns.bin Rootkit-Hidden Items Hidden


C:\RRbackups\common\tvtcmn.dat Rootkit-Hidden Items Hidden


C:\RRbackups\common\system.dat Rootkit-Hidden Items Hidden


C:\RRbackups\common\settings.dat Rootkit-Hidden Items Hidden


C:\RRbackups\common\secpolicy.dat Rootkit-Hidden Items Hidden


C:\RRbackups\common\seccache.dat Rootkit-Hidden Items Hidden


C:\RRbackups\common\SAM Rootkit-Hidden Items Hidden


C:\RRbackups\common\rr.log Rootkit-Hidden Items Hidden


C:\RRbackups\common\restore.log Rootkit-Hidden Items Hidden


C:\RRbackups\common\regcerts.dat Rootkit-Hidden Items Hidden


C:\RRbackups\common\mnd.dat Rootkit-Hidden Items Hidden


C:\RRbackups\common\hints.dat Rootkit-Hidden Items Hidden


C:\RRbackups\common\css.dat Rootkit-Hidden Items Hidden


C:\RRbackups\common\bt5.dat Rootkit-Hidden Items Hidden


C:\RRbackups\common\bt4.dat Rootkit-Hidden Items Hidden


C:\RRbackups\common\bt3.dat Rootkit-Hidden Items Hidden


C:\RRbackups\common\bt2.dat Rootkit-Hidden Items Hidden


C:\RRbackups\common\bt1.dat Rootkit-Hidden Items Hidden


C:\RRbackups\common\bt0.dat Rootkit-Hidden Items Hidden


C:\RRbackups\common\backups.dat Rootkit-Hidden Items Hidden


C:\RRbackups\C\5\TOCFile Rootkit-Hidden Items Hidden


C:\RRbackups\C\5\Info Rootkit-Hidden Items Hidden


C:\RRbackups\C\5\HashFile Rootkit-Hidden Items Hidden


C:\RRbackups\C\5\EFSFile Rootkit-Hidden Items Hidden


C:\RRbackups\C\5\dats Rootkit-Hidden Items Hidden


C:\RRbackups\C\5\Data9 Rootkit-Hidden Items Hidden


C:\RRbackups\C\5\Data8 Rootkit-Hidden Items Hidden


C:\RRbackups\C\5\Data7 Rootkit-Hidden Items Hidden


C:\RRbackups\C\5\Data6 Rootkit-Hidden Items Hidden


C:\RRbackups\C\5\Data5 Rootkit-Hidden Items Hidden


C:\RRbackups\C\5\Data4 Rootkit-Hidden Items Hidden


C:\RRbackups\C\5\Data3 Rootkit-Hidden Items Hidden


C:\RRbackups\C\5\Data25 Rootkit-Hidden Items Hidden


C:\RRbackups\C\5\Data24 Rootkit-Hidden Items Hidden


C:\RRbackups\C\5\Data23 Rootkit-Hidden Items Hidden


C:\RRbackups\C\5\Data22 Rootkit-Hidden Items Hidden


C:\RRbackups\C\5\Data21 Rootkit-Hidden Items Hidden


C:\RRbackups\C\5\Data20 Rootkit-Hidden Items Hidden


C:\RRbackups\C\5\Data2 Rootkit-Hidden Items Hidden


C:\RRbackups\C\5\Data19 Rootkit-Hidden Items Hidden


C:\RRbackups\C\5\Data18 Rootkit-Hidden Items Hidden


C:\RRbackups\C\5\Data17 Rootkit-Hidden Items Hidden


C:\RRbackups\C\5\Data16 Rootkit-Hidden Items Hidden


C:\RRbackups\C\5\Data15 Rootkit-Hidden Items Hidden


C:\RRbackups\C\5\Data14 Rootkit-Hidden Items Hidden


C:\RRbackups\C\5\Data13 Rootkit-Hidden Items Hidden


C:\RRbackups\C\5\Data12 Rootkit-Hidden Items Hidden


C:\RRbackups\C\5\Data11 Rootkit-Hidden Items Hidden


C:\RRbackups\C\5\Data10 Rootkit-Hidden Items Hidden


C:\RRbackups\C\5\Data1 Rootkit-Hidden Items Hidden


C:\RRbackups\C\5\Data0 Rootkit-Hidden Items Hidden


C:\RRbackups\C\4\TOCFile Rootkit-Hidden Items Hidden


C:\RRbackups\C\4\Info Rootkit-Hidden Items Hidden


C:\RRbackups\C\4\HashFile Rootkit-Hidden Items Hidden


C:\RRbackups\C\4\EFSFile Rootkit-Hidden Items Hidden


C:\RRbackups\C\4\dats Rootkit-Hidden Items Hidden


C:\RRbackups\C\4\Data9 Rootkit-Hidden Items Hidden


C:\RRbackups\C\4\Data8 Rootkit-Hidden Items Hidden


C:\RRbackups\C\4\Data7 Rootkit-Hidden Items Hidden


C:\RRbackups\C\4\Data6 Rootkit-Hidden Items Hidden


C:\RRbackups\C\4\Data5 Rootkit-Hidden Items Hidden


C:\RRbackups\C\4\Data4 Rootkit-Hidden Items Hidden


C:\RRbackups\C\4\Data3 Rootkit-Hidden Items Hidden


C:\RRbackups\C\4\Data2 Rootkit-Hidden Items Hidden


C:\RRbackups\C\4\Data1 Rootkit-Hidden Items Hidden


C:\RRbackups\C\4\Data0 Rootkit-Hidden Items Hidden


C:\RRbackups\C\3\TOCFile Rootkit-Hidden Items Hidden


C:\RRbackups\C\3\Info Rootkit-Hidden Items Hidden


C:\RRbackups\C\3\HashFile Rootkit-Hidden Items Hidden


C:\RRbackups\C\3\EFSFile Rootkit-Hidden Items Hidden


C:\RRbackups\C\3\dats Rootkit-Hidden Items Hidden


C:\RRbackups\C\3\Data9 Rootkit-Hidden Items Hidden


C:\RRbackups\C\3\Data8 Rootkit-Hidden Items Hidden


C:\RRbackups\C\3\Data7 Rootkit-Hidden Items Hidden


C:\RRbackups\C\3\Data6 Rootkit-Hidden Items Hidden


C:\RRbackups\C\3\Data5 Rootkit-Hidden Items Hidden


C:\RRbackups\C\3\Data4 Rootkit-Hidden Items Hidden


C:\RRbackups\C\3\Data3 Rootkit-Hidden Items Hidden


C:\RRbackups\C\3\Data2 Rootkit-Hidden Items Hidden


C:\RRbackups\C\3\Data10 Rootkit-Hidden Items Hidden


C:\RRbackups\C\3\Data1 Rootkit-Hidden Items Hidden


C:\RRbackups\C\3\Data0 Rootkit-Hidden Items Hidden


C:\RRbackups\C\2\TOCFile Rootkit-Hidden Items Hidden


C:\RRbackups\C\2\Info Rootkit-Hidden Items Hidden


C:\RRbackups\C\2\HashFile Rootkit-Hidden Items Hidden


C:\RRbackups\C\2\EFSFile Rootkit-Hidden Items Hidden


C:\RRbackups\C\2\dats Rootkit-Hidden Items Hidden


C:\RRbackups\C\2\Data9 Rootkit-Hidden Items Hidden


C:\RRbackups\C\2\Data8 Rootkit-Hidden Items Hidden


C:\RRbackups\C\2\Data7 Rootkit-Hidden Items Hidden


C:\RRbackups\C\2\Data6 Rootkit-Hidden Items Hidden


C:\RRbackups\C\2\Data5 Rootkit-Hidden Items Hidden


C:\RRbackups\C\2\Data4 Rootkit-Hidden Items Hidden


C:\RRbackups\C\2\Data3 Rootkit-Hidden Items Hidden


C:\RRbackups\C\2\Data2 Rootkit-Hidden Items Hidden


C:\RRbackups\C\2\Data16 Rootkit-Hidden Items Hidden


C:\RRbackups\C\2\Data15 Rootkit-Hidden Items Hidden


C:\RRbackups\C\2\Data14 Rootkit-Hidden Items Hidden


C:\RRbackups\C\2\Data13 Rootkit-Hidden Items Hidden


C:\RRbackups\C\2\Data12 Rootkit-Hidden Items Hidden


C:\RRbackups\C\2\Data11 Rootkit-Hidden Items Hidden


C:\RRbackups\C\2\Data10 Rootkit-Hidden Items Hidden


C:\RRbackups\C\2\Data1 Rootkit-Hidden Items Hidden


C:\RRbackups\C\2\Data0 Rootkit-Hidden Items Hidden


C:\RRbackups\C\1\TOCFile Rootkit-Hidden Items Hidden


C:\RRbackups\C\1\Info Rootkit-Hidden Items Hidden


C:\RRbackups\C\1\HashFile Rootkit-Hidden Items Hidden


C:\RRbackups\C\1\EFSFile Rootkit-Hidden Items Hidden


C:\RRbackups\C\1\dats Rootkit-Hidden Items Hidden


C:\RRbackups\C\1\Data99 Rootkit-Hidden Items Hidden


C:\RRbackups\C\1\Data98 Rootkit-Hidden Items Hidden


C:\RRbackups\C\1\Data97 Rootkit-Hidden Items Hidden


C:\RRbackups\C\1\Data96 Rootkit-Hidden Items Hidden


C:\RRbackups\C\1\Data95 Rootkit-Hidden Items Hidden


C:\RRbackups\C\1\Data94 Rootkit-Hidden Items Hidden


C:\RRbackups\C\1\Data93 Rootkit-Hidden Items Hidden


C:\RRbackups\C\1\Data92 Rootkit-Hidden Items Hidden


C:\RRbackups\C\1\Data91 Rootkit-Hidden Items Hidden


C:\RRbackups\C\1\Data90 Rootkit-Hidden Items Hidden


C:\RRbackups\C\1\Data9 Rootkit-Hidden Items Hidden


C:\RRbackups\C\1\Data89 Rootkit-Hidden Items Hidden


C:\RRbackups\C\1\Data88 Rootkit-Hidden Items Hidden


C:\RRbackups\C\1\Data87 Rootkit-Hidden Items Hidden


C:\RRbackups\C\1\Data86 Rootkit-Hidden Items Hidden


C:\RRbackups\C\1\Data85 Rootkit-Hidden Items Hidden


C:\RRbackups\C\1\Data84 Rootkit-Hidden Items Hidden


C:\RRbackups\C\1\Data83 Rootkit-Hidden Items Hidden


C:\RRbackups\C\1\Data82 Rootkit-Hidden Items Hidden


C:\RRbackups\C\1\Data81 Rootkit-Hidden Items Hidden


C:\RRbackups\C\1\Data80 Rootkit-Hidden Items Hidden


C:\RRbackups\C\1\Data8 Rootkit-Hidden Items Hidden


C:\RRbackups\C\1\Data79 Rootkit-Hidden Items Hidden


C:\RRbackups\C\1\Data78 Rootkit-Hidden Items Hidden


C:\RRbackups\C\1\Data77 Rootkit-Hidden Items Hidden


C:\RRbackups\C\1\Data76 Rootkit-Hidden Items Hidden


C:\RRbackups\C\1\Data75 Rootkit-Hidden Items Hidden


C:\RRbackups\C\1\Data74 Rootkit-Hidden Items Hidden


C:\RRbackups\C\1\Data73 Rootkit-Hidden Items Hidden


C:\RRbackups\C\1\Data72 Rootkit-Hidden Items Hidden


C:\RRbackups\C\1\Data71 Rootkit-Hidden Items Hidden


C:\RRbackups\C\1\Data70 Rootkit-Hidden Items Hidden


C:\RRbackups\C\1\Data7 Rootkit-Hidden Items Hidden


C:\RRbackups\C\1\Data69 Rootkit-Hidden Items Hidden


C:\RRbackups\C\1\Data68 Rootkit-Hidden Items Hidden


C:\RRbackups\C\1\Data67 Rootkit-Hidden Items Hidden


C:\RRbackups\C\1\Data66 Rootkit-Hidden Items Hidden


C:\RRbackups\C\1\Data65 Rootkit-Hidden Items Hidden


C:\RRbackups\C\1\Data64 Rootkit-Hidden Items Hidden


C:\RRbackups\C\1\Data63 Rootkit-Hidden Items Hidden


C:\RRbackups\C\1\Data62 Rootkit-Hidden Items Hidden


C:\RRbackups\C\1\Data61 Rootkit-Hidden Items Hidden


C:\RRbackups\C\1\Data60 Rootkit-Hidden Items Hidden


C:\RRbackups\C\1\Data6 Rootkit-Hidden Items Hidden


C:\RRbackups\C\1\Data59 Rootkit-Hidden Items Hidden


C:\RRbackups\C\1\Data58 Rootkit-Hidden Items Hidden


C:\RRbackups\C\1\Data57 Rootkit-Hidden Items Hidden


C:\RRbackups\C\1\Data56 Rootkit-Hidden Items Hidden


C:\RRbackups\C\1\Data55 Rootkit-Hidden Items Hidden


C:\RRbackups\C\1\Data54 Rootkit-Hidden Items Hidden


C:\RRbackups\C\1\Data53 Rootkit-Hidden Items Hidden


C:\RRbackups\C\1\Data52 Rootkit-Hidden Items Hidden


C:\RRbackups\C\1\Data51 Rootkit-Hidden Items Hidden


C:\RRbackups\C\1\Data50 Rootkit-Hidden Items Hidden


C:\RRbackups\C\1\Data5 Rootkit-Hidden Items Hidden


C:\RRbackups\C\1\Data49 Rootkit-Hidden Items Hidden


C:\RRbackups\C\1\Data48 Rootkit-Hidden Items Hidden


C:\RRbackups\C\1\Data47 Rootkit-Hidden Items Hidden


C:\RRbackups\C\1\Data46 Rootkit-Hidden Items Hidden


C:\RRbackups\C\1\Data45 Rootkit-Hidden Items Hidden


C:\RRbackups\C\1\Data44 Rootkit-Hidden Items Hidden


C:\RRbackups\C\1\Data43 Rootkit-Hidden Items Hidden


C:\RRbackups\C\1\Data42 Rootkit-Hidden Items Hidden


C:\RRbackups\C\1\Data41 Rootkit-Hidden Items Hidden


C:\RRbackups\C\1\Data40 Rootkit-Hidden Items Hidden


C:\RRbackups\C\1\Data4 Rootkit-Hidden Items Hidden


C:\RRbackups\C\1\Data39 Rootkit-Hidden Items Hidden


C:\RRbackups\C\1\Data38 Rootkit-Hidden Items Hidden


C:\RRbackups\C\1\Data37 Rootkit-Hidden Items Hidden


C:\RRbackups\C\1\Data36 Rootkit-Hidden Items Hidden


C:\RRbackups\C\1\Data35 Rootkit-Hidden Items Hidden


C:\RRbackups\C\1\Data34 Rootkit-Hidden Items Hidden


C:\RRbackups\C\1\Data33 Rootkit-Hidden Items Hidden


C:\RRbackups\C\1\Data32 Rootkit-Hidden Items Hidden


C:\RRbackups\C\1\Data31 Rootkit-Hidden Items Hidden


My question is whether this is something I should worry about. My computer seems to be working fine at the moment and I've seen it mentioned that sometimes RRbackups on ThinkPad computers can be normal and the virus program is mistakenly considering it a threat because it's hidden.


Any help?

Comments

  • I have the same issue and have been trying to get an answer from Tech Support for weeks.

  • Interesting. And your computer is working fine in the meantime as well? I'm getting the impression it's a normal thing on this type of computer and the only reason the antivirus program thinks of it as a potential threat is because the computer has the files hidden.

  • rootkit
    rootkit ✭✭✭
    edited March 2009

    I think it's a false positive. Those files are encrypted.


    Let's wait for a virus researcher.

  • Lenovo Notepads?

  • Lenovo Notepads?


    I think so, yeah. I'm somewhat of a technophobe when it comes to knowing stuff about the computer, but it says Lenova on my computer. It also says IBM ThinkPad.

  • I think so, yeah. I'm somewhat of a technophobe when it comes to knowing stuff about the computer, but it says Lenova on my computer. It also says IBM ThinkPad.


    What is the status of these? It has been nearly two weeks since a Virus Researcher <img class=" /> was supposed to rule on this and post a reply????????

  • The Rescue and Recovery system is usually found preinstalled on some laptops. The application hides the backed up files in a rootkit hidden location on the drive (C:\RRbackups). BitDefender will detect these files because they are hidden from the user using a rootkit method (rootkits can be and are commonly used to hide malicious applications).


    What steps to take if you are facing this issue?


    1. If BitDefender detects the hidden location then add the folder to the Exclusions list (in Advanced View > Antivirus):


    post-21888-1238416806_thumb.jpg


    2. If BitDefender renamed the backed up files (adding .bd.ren in an attempt to render the potentially harmful rootkit harmless) and you want to restore the original names in order to recover the files use this tool (password to extract is bitdefender):


    post-21888-1238417415_thumb.jpg


    - extract the content of the package to a location on your computer


    - run (double click) RestoreFiles.bat


    - wait for the process to be completed and the "Press any key to continue..." prompt


    - press any key


    POTENTIAL ISSUES


    You may run into one of these issues; If you do please reply in this topic for better tracking and resolution.


    1. Unable to add the C:\RRbackups folder to the exceptions list; (BitDefender won't allow adding the C:\RRbackups folder - or other rootkit protected folder)


    2. Rootkit protected folders excluded from scanning are still being scanned;


    Feedback appreciated!

  • ronchicago
    edited March 2009
    The Rescue and Recovery system is usually found preinstalled on some laptops. The application hides the backed up files in a rootkit hidden location on the drive (C:\RRbackups). BitDefender will detect these files because they are hidden from the user using a rootkit method (rootkits can be and are commonly used to hide malicious applications).


    What steps to take if you are facing this issue?


    1. If BitDefender detects the hidden location then add the folder to the Exclusions list (in Advanced View > Antivirus):


    post-21888-1238416806_thumb.jpg


    2. If BitDefender renamed the backed up files (adding .bd.ren in an attempt to render the potentially harmful rootkit harmless) and you want to restore the original names in order to recover the files use this tool (password to extract is bitdefender):


    post-21888-1238417415_thumb.jpg


    - extract the content of the package to a location on your computer


    - run (double click) RestoreFiles.bat


    - wait for the process to be completed and the "Press any key to continue..." prompt


    - press any key


    POTENTIAL ISSUES


    You may run into one of these issues; If you do please reply in this topic for better tracking and resolution.


    1. Unable to add the C:\RRbackups folder to the exceptions list; (BitDefender won't allow adding the C:\RRbackups folder - or other rootkit protected folder)


    2. Rootkit protected folders excluded from scanning are still being scanned;


    Feedback appreciated!


    I cannot do it - I tried


    1. use browse - click on RRbackups and then "Add" - nothing appears


    2. use browse - click square on RRbackups - "access denied"


    3. manually enter c:\RRbackups into exclude path - and then "Add" - nothing happens (like #1)

  • I cannot do it - I tried


    1. use browse - click on RRbackups and then "Add" - nothing appears


    2. use browse - click square on RRbackups - "access denied"


    3. manually enter c:\RRbackups into exclude path - and then "Add" - nothing happens (like #1)


    ??????????????????????????????????????????????????????????????????????????????????

  • Anyone from BitDefender looking at the forum? trish and I have been waiting for weeks.

  • I couldn't add the C:\RRbackups to the exclusions list.


    Is there any other way to add it other than the one mentioned?



  • name='ronchicago' date='Apr 6 2009, 01:40 PM' post='54618']


    Anyone from BitDefender looking at the forum? trish and I have been waiting for weeks.





    HELLO?? Is anyone from Bitdefender paying attention to this thread?


    I too have this problem, related to the "Rescue and Recovery" application provided by Lenovo (formerly IBM) for use on its ThinkPad laptops and other personal computers.


    After multiple installs and reinstalls of the Windows OS (in my case, Vista Home Premium) and updates of all key Lenovo drivers and applications, I have determined the following:


    (1) Lenovo appears to be using "rootkit" techniques to create hidden directories and files related to certain of its Windows utility applications.


    (2) Multiple scans of my boot (C:\) drive using Bitdefender Internet Security 2009 (either Full or Deep Scan) disclose "hidden" and "password-protected" files and folders related to Lenovo's "Rescue and Recovery" application.


    (3) The primary "hidden" folder is identified as "C:\RRbackups."


    (4) The primary folders identified with "password-protected" files are "C:\SWTOOLS\apps\rnr" and "C:\SWTOOLS\apps\rnr42en." 9803 items are identified as being password-protected and, thus, not scannable.


    (5) One file is identified as being "overcompressed," and, hence, not scannable. It is not clear whether or not this file is related to the Lenovo Rescue and Recovery application.


    (6) The Bitdefender scan identifies 384 files as "Rootkit-Hidden Items." An option is given to "Unhide" these items. If selected, Bitdefender indicates that 28 of the 384 hidden files cannot be rennamed (and, hence, unhidden). Bitdefender further indicates that a reboot of the computer will allow the other 356 hidden files to be unhidden. However, after reboot, a Full or Deep Scan with Bitdefender still identifies the same 384 files as "Rootkit-Hidden Items." I have repeated this process multiple times with the same result.


    (7) As mentioned by the other forum member above, there does not appear to be a way to exclude the rootkit-hidden folder C:\RRbackups from AV scanning. Bitdefender's "Exclusions" function does not allow this hidden directory to be added, either by browsing or by manual entry.


    I have now run scans of my C:\ drive with several other notable AV/malware programs, including Norton/Symantec, Kapersky and Malwarebytes. None of these programs flags the hidden or password-protected files and folders which were identified by Bitdefender. I don't know whether to consider this fact as good news or bad news. Is Bitdefender mistakenly classifying these items as "false positives?" Or should Bitdefender be commended for the quality of its scan engine, notwithstanding the fact that the offending item cannot be excluded from future scans?


    I am a longtime loyal and confident customer of Bitdefender. This issue, and the customers who have brought it to the attention of Bitdefender Tech Support, deserve an intelligent and thoughtful response to this issue.


    Thank you.


    Mark Shneour


    PS -- I have attached the log file from my latest Bitdefender scan.

    /applications/core/interface/file/attachment.php?id=5066" data-fileid="5066" rel="">1240086530_1_02.xml

  • Rootkit hidden folders cannot be excluded from scanning. We are aware of this situation however it is unlikely that a fix will be implemented in the BitDefender 2009 products. The next generation of BitDefender desktop products (scheduled for release in August - September 2009) will not have this issue.


    If your C:\RRbackups files have been renamed please refer to step 2 of my previous post /index.php?/topic/12511-crrbackups/#comment-53982" rel=""><{POST_SNAPBACK}> for a tool that will restore them to their initial name.

  • Rootkit hidden folders cannot be excluded from scanning. We are aware of this situation however it is unlikely that a fix will be implemented in the BitDefender 2009 products. The next generation of BitDefender desktop products (scheduled for release in August - September 2009) will not have this issue.


    If your C:\RRbackups files have been renamed please refer to step 2 of my previous post /index.php?/topic/12511-crrbackups/#comment-53982" rel=""><{POST_SNAPBACK}> for a tool that will restore them to their initial name.


    I am using BitDefender AntiVirus 2009 with a Lenovo T61, and have the same problem as others in this thread. I had used BitDefender to rename the false positives. I tried using the .bat file in your post to "unrename" these false positives (and successfully obtained the message ".../Done/Press any key to continue...), but running BitDefender on a subsequent scan shows that the .bat file had no effect, and the files in RRbackups identified as false positives still end in *bd.ren.


    Properties of these files prevented my renaming them manually.


    Your advice would be appreciated.

  • I am using BitDefender AntiVirus 2009 with a Lenovo T61, and have the same problem as others in this thread. I had used BitDefender to rename the false positives. I tried using the .bat file in your post to "unrename" these false positives (and successfully obtained the message ".../Done/Press any key to continue...), but running BitDefender on a subsequent scan shows that the .bat file had no effect, and the files in RRbackups identified as false positives still end in *bd.ren.


    Properties of these files prevented my renaming them manually.


    Your advice would be appreciated.


    I have now determined that the .bat file did indeed work to un-rename the affected files, because Bitdefender now (falsely) reports that some 560 files are infected in RRBackups. However, the danger is that one asks BitDefender to unhide these files, and once those steps are invoked, BitDefender will again rename them. So nothing more to do until the next release of BitDefender becomes available.

  • Mark's reply was spot on for me. I have a Lenovo x61 and I can verify all that he reported. Great work Mark!

  • I am using BitDefender AntiVirus 2010 with a Lenovo T61, and have the same problem as others in this thread. A few posts ago Corneliu noted that you cannot add a hidden folder to the Exclusions list but that would be fixed in AV 2009. I don't know about AV 2009, but it is NOT fixed in AV 2010; I cannot add C:\RRbackups as an exclusion.


    Any suggestions other than making the folder visible, or uninstalling R&R?

  • Hello Lee-K,


    Unfortunately this issue persist on our 2010 product as well and we are currently working on a fix.


    The RRUbackups folder is actually a hidden folder which is part of the IBM Rescue & Recovery Utility (RRU) and is created by the BIOS. The contents of this folder are encrypted and/or hidden from the operating system in order to be protected. They cannot be accessed or modified by anything other than the IBM Rescue & Recovery Utility (RRU). The contents are not infected.


    Until this issue is solved, please ignore the RRUbackups references in the scan report.


    Thank you .

  • hello.


    just want to let you know, I get this problem as well, all my files in private folder have been renamed to .bd.ren. all of those files are my important personal files (i.e my important documents, notes etc).


    up to this date, no solution I found to help me recover these files.


    if anyone have resolved this issues, please tell us.


    at the mean time, I want to express my dissappointment to BitDefender because creating this loss to me (I used other antivirus software before, but none gave me problems like this).


    now, not only I can't get my files, I even cannot use my Private Folder software as well, as it required me to delete the old private folder first - which was unable to access because of this mess.


    maybe someone said "that's why you need to back up your files". but please think again, if i did back up my private files, i still need to locked it, and the same problem will happened again.


    :(

  • Definitely I'm not using BitDefender anymore :( (no offense to the team)


    for your information, this is my second time I encounter problems with BitDefender.


    The first one is whenever I plugged in my external hard drive, BitDefender gave me a warning that my D the drive (my external hard drive is F:\) has been infected with trojan.mebroot, and when I scanned it, nothing detected. i try to reformat my D drive the same problem still occured.


    But when I plugged it to different laptop/pc using different antivirus, nothing happened.