I would agree with ManipUni's appoach.  You could run this: RootkitRevealer v1.71