I know that rootkits operate as part of the kernel, driver or service running on the system, injecting themself into DLLs or installing as a legitimate applications.
If I were to scan the system with sigverif.exe, would the files injected with the rootkit have broken signatures?