It's shown as \RtrDpeBk.ini & I can't find anything on it. Google brings up something about basketball. AVG rootkit detector dosen't find it nor does their spyware or virus detectors. It looks like Panda can't remove it. Has anyone seen this before? I couldn't nail it down with a reistry scan either. Any help is appreciated.
[Current Loc]
S-1-5-18=\WINDOWS\system32\config\systemprofile\NTUser.Dat
S-1-5-19=\Documents and Settings\LocalService\NTUSER.DAT
S-1-5-19_Classes=\Documents and Settings\LocalService\Local Settings\Application Data\Microsoft\Windows\UsrClass.dat
S-1-5-20=\Documents and Settings\NetworkService\NTUSER.DAT
S-1-5-20_Classes=\Documents and Settings\NetworkService\Local Settings\Application Data\Microsoft\Windows\UsrClass.dat
S-1-5-21-1606980848-413027322-725345543-1004=\Documents and Settings\VanVock\ntuser.dat
S-1-5-21-1606980848-413027322-725345543-1004_Classes=\Documents and Settings\VanVock\Local Settings\Application Data\Microsoft\Windows\UsrClass.dat
S-1-5-21-1606980848-413027322-725345543-500=\Documents and Settings\Administrator\NTUSER.DAT
S-1-5-21-1606980848-413027322-725345543-500_Classes=\Documents and Settings\Administrator\Local Settings\Application Data\Microsoft\Windows\UsrClass.dat
All Users=\Documents and Settings\All Users\ntuser.dat
Default User=\Documents and Settings\Default User\NTUSER.DAT
.DEFAULT=\WINDOWS\SYSTEM32\CONFIG\default
SAM=\WINDOWS\SYSTEM32\CONFIG\SAM
SECURITY=\WINDOWS\SYSTEM32\CONFIG\SECURITY
software=\WINDOWS\SYSTEM32\CONFIG\software
system=\WINDOWS\SYSTEM32\CONFIG\system
[Original Loc]
S-1-5-18=C:\WINDOWS\system32\config\systemprofile\NTUser.Dat
S-1-5-19=C:\Documents and Settings\LocalService\NTUSER.DAT
S-1-5-19_Classes=C:\Documents and Settings\LocalService\Local Settings\Application Data\Microsoft\Windows\UsrClass.dat
S-1-5-20=C:\Documents and Settings\NetworkService\NTUSER.DAT
S-1-5-20_Classes=C:\Documents and Settings\NetworkService\Local Settings\Application Data\Microsoft\Windows\UsrClass.dat
S-1-5-21-1606980848-413027322-725345543-1004=C:\Documents and Settings\VanVock\ntuser.dat
S-1-5-21-1606980848-413027322-725345543-1004_Classes=C:\Documents and Settings\VanVock\Local Settings\Application Data\Microsoft\Windows\UsrClass.dat
S-1-5-21-1606980848-413027322-725345543-500=C:\Documents and Settings\Administrator\NTUSER.DAT
S-1-5-21-1606980848-413027322-725345543-500_Classes=C:\Documents and Settings\Administrator\Local Settings\Application Data\Microsoft\Windows\UsrClass.dat
All Users=C:\Documents and Settings\All Users\ntuser.dat
Default User=C:\Documents and Settings\Default User\NTUSER.DAT
.DEFAULT=C:\WINDOWS\SYSTEM32\CONFIG\default
SAM=C:\WINDOWS\SYSTEM32\CONFIG\SAM
SECURITY=C:\WINDOWS\SYSTEM32\CONFIG\SECURITY
software=C:\WINDOWS\SYSTEM32\CONFIG\software
system=C:\WINDOWS\SYSTEM32\CONFIG\system
[Reg Key Type]
S-1-5-18=0
S-1-5-19=0
S-1-5-19_Classes=1
S-1-5-20=0
S-1-5-20_Classes=1
S-1-5-21-1606980848-413027322-725345543-1004=0
S-1-5-21-1606980848-413027322-725345543-1004_Classes=1
S-1-5-21-1606980848-413027322-725345543-500=0
S-1-5-21-1606980848-413027322-725345543-500_Classes=1
All Users=0
Default User=0
.DEFAULT=0
SAM=2
SECURITY=2
software=2
system=2
>>> This appears to be the file in question.
[Current Loc]
S-1-5-18=\WINDOWS\system32\config\systemprofile\NTUser.Dat
S-1-5-19=\Documents and Settings\LocalService\NTUSER.DAT
S-1-5-19_Classes=\Documents and Settings\LocalService\Local Settings\Application Data\Microsoft\Windows\UsrClass.dat
S-1-5-20=\Documents and Settings\NetworkService\NTUSER.DAT
S-1-5-20_Classes=\Documents and Settings\NetworkService\Local Settings\Application Data\Microsoft\Windows\UsrClass.dat
S-1-5-21-1606980848-413027322-725345543-1004=\Documents and Settings\VanVock\ntuser.dat
S-1-5-21-1606980848-413027322-725345543-1004_Classes=\Documents and Settings\VanVock\Local Settings\Application Data\Microsoft\Windows\UsrClass.dat
S-1-5-21-1606980848-413027322-725345543-500=\Documents and Settings\Administrator\NTUSER.DAT
S-1-5-21-1606980848-413027322-725345543-500_Classes=\Documents and Settings\Administrator\Local Settings\Application Data\Microsoft\Windows\UsrClass.dat
All Users=\Documents and Settings\All Users\ntuser.dat
Default User=\Documents and Settings\Default User\NTUSER.DAT
.DEFAULT=\WINDOWS\SYSTEM32\CONFIG\default
SAM=\WINDOWS\SYSTEM32\CONFIG\SAM
SECURITY=\WINDOWS\SYSTEM32\CONFIG\SECURITY
software=\WINDOWS\SYSTEM32\CONFIG\software
system=\WINDOWS\SYSTEM32\CONFIG\system
[Original Loc]
S-1-5-18=C:\WINDOWS\system32\config\systemprofile\NTUser.Dat
S-1-5-19=C:\Documents and Settings\LocalService\NTUSER.DAT
S-1-5-19_Classes=C:\Documents and Settings\LocalService\Local Settings\Application Data\Microsoft\Windows\UsrClass.dat
S-1-5-20=C:\Documents and Settings\NetworkService\NTUSER.DAT
S-1-5-20_Classes=C:\Documents and Settings\NetworkService\Local Settings\Application Data\Microsoft\Windows\UsrClass.dat
S-1-5-21-1606980848-413027322-725345543-1004=C:\Documents and Settings\VanVock\ntuser.dat
S-1-5-21-1606980848-413027322-725345543-1004_Classes=C:\Documents and Settings\VanVock\Local Settings\Application Data\Microsoft\Windows\UsrClass.dat
S-1-5-21-1606980848-413027322-725345543-500=C:\Documents and Settings\Administrator\NTUSER.DAT
S-1-5-21-1606980848-413027322-725345543-500_Classes=C:\Documents and Settings\Administrator\Local Settings\Application Data\Microsoft\Windows\UsrClass.dat
All Users=C:\Documents and Settings\All Users\ntuser.dat
Default User=C:\Documents and Settings\Default User\NTUSER.DAT
.DEFAULT=C:\WINDOWS\SYSTEM32\CONFIG\default
SAM=C:\WINDOWS\SYSTEM32\CONFIG\SAM
SECURITY=C:\WINDOWS\SYSTEM32\CONFIG\SECURITY
software=C:\WINDOWS\SYSTEM32\CONFIG\software
system=C:\WINDOWS\SYSTEM32\CONFIG\system
[Reg Key Type]
S-1-5-18=0
S-1-5-19=0
S-1-5-19_Classes=1
S-1-5-20=0
S-1-5-20_Classes=1
S-1-5-21-1606980848-413027322-725345543-1004=0
S-1-5-21-1606980848-413027322-725345543-1004_Classes=1
S-1-5-21-1606980848-413027322-725345543-500=0
S-1-5-21-1606980848-413027322-725345543-500_Classes=1
All Users=0
Default User=0
.DEFAULT=0
SAM=2
SECURITY=2
software=2
system=2
>>> This appears to be the file in question.