Sigh,. Setting the Hidden attribute on a file or directory is not being a rootkit. Just because you can't see it from brain damaged Explore rdoesn't mean it's not there. Hint: You can see both from the *horrors* command line by typing:
dir /a
Hide a file with
attr +H filename
Bring it back with
attr -H filename
The rootkit puts code in the OS's functionality that prevents ANYTHING in the OS from seeing the files.
From the discussions it's not clear if this is a true rootkit, or is just using he hidden attribute. FSecure claims the stuff is hidden from the "Windows API" but there are others who say it's hidden from all but the command line.
EVERYBODY PANIC! The anti-virus vendors don't mind people thinking it's a dangerous world out there.