Partizan.sys

RegRun Security Suite

Greatis Software, LLC

It runs as a Windows kernel mode device driver named “Partizan”.
Publisher:
Greatis Software  (signed by Greatis Software, LLC)

Product:
RegRun Security Suite

Description:
Partizan - Rootkit detector

Version:
1, 0, 0, 5

MD5:
2003d6ddbc6ceb0e6e96be84bc7dd64e

SHA-1:
926c19bf2582cc7d6127c9aabde0fe6f3ebb2859

Scanner detections:
0 / 68

Status:
Clean (as of last analysis)

Analysis date:
4/25/2024 6:15:55 AM UTC  (today)

File size:
34.1 KB (34,952 bytes)

Product version:
6, 8, 0, 0

Copyright:
Copyright © 2007-2010

Trademarks:
Partizan

Original file name:
Partizan.sys

File type:
Driver (Win32 SYS)

Language:
English (United States)

Common path:
C:\Windows\System32\drivers\partizan.sys

Digital Signature
Authority:
The USERTRUST Network

Valid from:
6/3/2009 2:00:00 AM

Valid to:
6/4/2011 1:59:59 AM

Subject:
CN="Greatis Software, LLC", O="Greatis Software, LLC", STREET=Turgeneva 1-65, L=Yaroslavl, S=Yarosalvl, PostalCode=150054, C=RU

Issuer:
CN=UTN-USERFirst-Object, OU=http://www.usertrust.com, O=The USERTRUST Network, L=Salt Lake City, S=UT, C=US

Serial number:
00A8D1B87F5FA913FEF96BA854DF246392

File PE Metadata
Compilation timestamp:
2/26/2010 1:35:04 PM

OS version:
5.0

OS bitness:
Win32

Subsystem:
Native (none required)

Linker version:
6.0

Entry address:
0x1A9B

Entry point:
55, 8B, EC, 81, EC, AC, 01, 00, 00, 56, 57, B9, 08, 00, 00, 00, BE, 50, 19, 01, 00, 8D, BD, 0C, FF, FF, FF, F3, A5, 66, A5, B9, 0A, 00, 00, 00, BE, 74, 19, 01, 00, 8D, BD, 48, FF, FF, FF, F3, A5, 66, A5, A1, A0, 19, 01, 00, 89, 85, E8, FE, FF, FF, 8B, 0D, A4, 19, 01, 00, 89, 8D, EC, FE, FF, FF, 8B, 15, A8, 19, 01, 00, 89, 95, F0, FE, FF, FF, B9, 22, 00, 00, 00, BE, AC, 19, 01, 00, 8D, BD, 74, FF, FF, FF, F3, A5, 66, A5, 68, 44, 64, 6B, 20, 8B, 45, 0C, 33, C9, 66, 8B, 08, 83, C1, 02, 51, 6A, 01, FF, 15, E4...
 
[+]

Developed / compiled with:
Microsoft Visual C++

Code size:
11.8 KB (12,032 bytes)

Driver
Display name:
Partizan

Type:
Kernel device driver (KernelDriver)

Group:
Boot Bus Extender


Scan Partizan.sys - Powered by Reason Core Security