elrawdsk.sys

RawDisk

EldoS Corporation

It runs as a Windows kernel mode device driver named “ElRawDisk”.
Publisher:
EldoS Corporation  (signed and verified)

Product:
RawDisk

Description:
RawDisk Driver. Allows write access to raw disk sectors for user mode applications in Windows 2000, XP, 2003, Vista, 2008.

Version:
1, 1, 13, 62

MD5:
0d58e6edc4570b03b03d4f95da81ba62

SHA-1:
b0adbbd0f4b478274fc65666e724a653b77ad2a2

Scanner detections:
0 / 68

Status:
Clean (as of last analysis)

Analysis date:
5/22/2025 6:08:15 AM UTC  (today)

File size:
28.8 KB (29,528 bytes)

Product version:
1, 1, 13, 0

Copyright:
Copyright (C) 2007-2008, EldoS Corporation

Original file name:
elrawdsk.sys

File type:
Driver (Win32 SYS)

Language:
English (United States)

Common path:
C:\Windows\System32\drivers\elrawdsk.sys

Digital Signature
Authority:
GlobalSign nv-sa

Valid from:
1/10/2007 4:20:07 PM

Valid to:
1/10/2010 4:20:07 PM

Subject:
E=info@eldos.com, CN=EldoS Corporation, O=EldoS Corporation, C=VG

Issuer:
CN=GlobalSign ObjectSign CA, OU=ObjectSign CA, O=GlobalSign nv-sa, C=BE

Serial number:
010000000001100C983A31

File PE Metadata
Compilation timestamp:
5/9/2008 2:45:45 PM

OS version:
6.0

OS bitness:
Win32

Subsystem:
Native (none required)

Linker version:
8.0

CTPH (ssdeep):
384:/gbCzj9kbn0NEaZv9HDsKxoz85JNAUZ970b9ANOZ9wquGN4fIJAbGFf2OJ06dUbs:iCNWnKEg9Hhx5dbgA2buGWQe4SJi6Y

Entry address:
0x44C7

Entry point:
8B, FF, 55, 8B, EC, A1, 8C, 0E, 01, 00, 85, C0, B9, 4E, E6, 40, BB, 74, 04, 3B, C1, 75, 1A, A1, 44, 0C, 01, 00, 8B, 00, 35, 8C, 0E, 01, 00, A3, 8C, 0E, 01, 00, 75, 07, 8B, C1, A3, 8C, 0E, 01, 00, F7, D0, A3, 90, 0E, 01, 00, 5D, E9, 0B, FE, FF, FF, CC, CC, CC, CC, CC, CC, CC, CC, CC, CC, CC, 49, 00, 6F, 00, 47, 00, 65, 00, 74, 00, 44, 00, 69, 00, 73, 00, 6B, 00, 44, 00, 65, 00, 76, 00, 69, 00, 63, 00, 65, 00, 4F, 00, 62, 00, 6A, 00, 65, 00, 63, 00, 74, 00, 00, 00, CC, CC, CC, CC, 49, 00, 6F, 00, 47, 00, 65...
 
[+]

Code size:
16.5 KB (16,896 bytes)

Driver
Display name:
ElRawDisk

Type:
Kernel device driver (KernelDriver)


Scan elrawdsk.sys - Powered by Reason Core Security