Rootkittens that hide files, directories and Registry keys can either execute in user mode by patching Windows APIs in each process that applications use to access those objects, or in kernel mode by intercepting the associated kernel-mode APIs.
Apparently, it’s a measure against entertainment piracy.
Ho-hum. Do you have a pussy? Try Sysinternals freeware rootkitten revealer!