Partizan.sys

RegRun Security Suite

Greatis Software, LLC

It runs as a Windows kernel mode device driver named “Partizan”.
Publisher:
Greatis Software  (signed by Greatis Software, LLC)

Product:
RegRun Security Suite

Description:
Partizan - Rootkit detector

Version:
1, 0, 0, 3

MD5:
3d2ab56021a0d4c18c0be90843e13bbf

SHA-1:
b563d0c7f122e3eb8892daf644b5bde5bf6f6aa9

SHA-256:
a16db9ab8fae3d0dc39b5e8afde333359728487c8cfa9b1fc011ce6b51d9205d

Scanner detections:
0 / 68

Status:
Clean (as of last analysis)

Analysis date:
4/25/2024 8:14:15 AM UTC  (today)

File size:
33.9 KB (34,760 bytes)

Product version:
5,1,0,21

Copyright:
Copyright © 2007

Trademarks:
Partizan

Original file name:
Partizan.sys

File type:
Driver (Win32 SYS)

Language:
English (United States)

Common path:
C:\Windows\System32\drivers\partizan.sys

Digital Signature
Authority:
The USERTRUST Network

Valid from:
11/23/2008 9:00:00 PM

Valid to:
11/24/2010 8:59:59 PM

Subject:
CN="Greatis Software, LLC", O="Greatis Software, LLC", STREET="1-65, Turgeneva", L=Yaroslavl, S=Yaroslavl, PostalCode=150054, C=RU

Issuer:
CN=UTN-USERFirst-Object, OU=http://www.usertrust.com, O=The USERTRUST Network, L=Salt Lake City, S=UT, C=US

Serial number:
4B5179A3ECC3D3E2BE18F660088FE088

File PE Metadata
Compilation timestamp:
2/13/2008 2:52:31 AM

OS version:
5.0

OS bitness:
Win32

Subsystem:
Native (none required)

Linker version:
6.0

CTPH (ssdeep):
384:Cel577V0+FKj/bMKM4K3aWe5MXU69sMIp5:Cel57Wvj/bFKiK9nIp5

Entry address:
0x19DB

Entry point:
55, 8B, EC, 81, EC, AC, 01, 00, 00, 56, 57, B9, 08, 00, 00, 00, BE, 90, 18, 01, 00, 8D, BD, 0C, FF, FF, FF, F3, A5, 66, A5, B9, 0A, 00, 00, 00, BE, B4, 18, 01, 00, 8D, BD, 48, FF, FF, FF, F3, A5, 66, A5, A1, E0, 18, 01, 00, 89, 85, E8, FE, FF, FF, 8B, 0D, E4, 18, 01, 00, 89, 8D, EC, FE, FF, FF, 8B, 15, E8, 18, 01, 00, 89, 95, F0, FE, FF, FF, B9, 22, 00, 00, 00, BE, EC, 18, 01, 00, 8D, BD, 74, FF, FF, FF, F3, A5, 66, A5, 68, 44, 64, 6B, 20, 8B, 45, 0C, 33, C9, 66, 8B, 08, 83, C1, 02, 51, 6A, 01, FF, 15, 24...
 
[+]

Developed / compiled with:
Microsoft Visual C++

Code size:
11.6 KB (11,840 bytes)

Driver
Display name:
Partizan

Type:
Kernel device driver (KernelDriver)

Group:
Boot Bus Extender


Scan Partizan.sys - Powered by Reason Core Security