Are these rootkits?

HiJackThis1.99

Posts: 91   +0
From my experience of fighting against trojans I realized that (for Windows) a lot of them are downloader viruses and download stuff of the internet. They are randomly named ".dll" files which are located in the:
/HKLM/SOFTWARE/MICROSOFT/WINDOWS NT/CURRENT VERSION/WINLOGON/ .....

After that .... it changes from XP to Vista. In XP I remember it was Notify32, or something like that. And it gives you all the OS dll's. While in Vista it is something else. Do you know what I am talking about?

So my questions are:
1)What is the analogue of that Registry location for Vista?
2)Are these dll rootkits?

I am asking because I once had difficulty removing a trojan off my computer because it was a .dll file which make the OS thing it was a system file. But AVG Anti-Spyware had this nice feature to delete on reboot which solved the problem.
 
HiJackThis1.99 said:
So my questions are:
1)What is the analogue of that Registry location for Vista?
2)Are these dll rootkits?

(1) the XP registry files are in
\windows\system32\config; there are FIVE that act as a database=='the registry'

(2) a rootkit differs from a trojan or virus in that it hides inside an existing module
of the OS, where as trojans and viri add modules and then make them run at boot time.
Obviously, extra modules are easier to defeat than mods to REAL OS code!
 
Back