The rogue creates files on the system so it can detects infected items.
A new componant came with TrustWarrior, it's going on with SaveDefender: the trojan-downloader downloads a RootKit (it patches files in memory: dump_atapi.sys and dump_WMILIB.SYS).
BleepingComputer Save Defender removal guide.