Security
•  Greatis •  AppDatabase •  Utilities •  Delphi/CB •  Visual Basic • .NET •  just4fun
RegRun Security Suite
Not an antivirus. A powerful tool kit against Trojans, viruses, spyware, adware and rootkits
Features
Benefits

Startup Monitor...

Bootlog Analyser...

Advanced MSConfig...

Know more?
Screenshots

FAQ

On-line manual

Print PDF

One-click purchase
RegRun NIVA Platinum

NIVA+CD-ROM

Download trial
RegRun NIVA Platinum
Forums
Greatis Forum

NI Forum

Mickey Forum

Thank you!

International
Download Russian

Download Ukrainian

Join our localization team

Home Download Order Support   Newsletter Your shopping cart ?
Partizan is the newest rootkit detection technology in the world!

Looking to the progress of rootkit development since last year we have the opinion that the rootkit detection on the working computer is not real. We can not get you the 100% guarantee free of rootkits on the working computer connected to network.

The simple way to do it is using Windows PE boot CD for checking a computer.

But how often you will do it?

Sometimes: May be one time per week, may be not.

It's not enough!

The rootkit can start his work today or tomorrow. This why you need a way to quickly check a computer for rootkits without luck.

We can offer you to check your computer every Windows boot-up!

How does the Partizan work?

Partizan starts using the BootExecute registry key on the early stage of the Windows boot process. It can get the access to any file or registry keys. Using another words, Partizan is a king on your computer at the moment.

Partizan Boot Screenshot Partizan executes 2 main tasks:

  1. Getting file/registry information.
  2. Delete Files/Registry Keys.
The kernel rootkits can cause the trouble with detecting hidden registry keys/files etc.

But rootkits are not invulnerable!

The simple way to kill a rootkit is to shutdown your computer.

A rootkit can revive after reboot using:

  1. Rootkit service/driver with auto start setting (to be more hidden for user mode checkers).
  2. Injection to the executable file or to the process memory. The body may be hidden in the mother file.
  3. Using registry startup keys.
  4. Infection from network.
The last chance is very dangerous but it can be resolved by simple cut off the network cable.

The second chance is not the simple because the user can control the file integrity using Microsoft or another software.

Third chance is more often used. But rootkit detectors easily detect it.

The fake Winlogon DLLs are not the surprise for us very long ago :-)

The hidden kernel driver is the top of the hacker skills. This is one reason why the Partizan was created.

Unfortunately Microsoft prevents Partizan for interacting with user using keyboard and it is a real problem for creating the shell like "cmd". Why they don't?

I think you need ask Microsoft.

Anyway it's not a technical problem. It's the Microsoft decision.

We need to get a workaround.

We use the command file (RRI). Partizan opens the command file and executes the tasks listed in it. After that the Windows boot will continue.

RegRun Platinum Secure Start will run the special copy of UnHackMe software for comparing Partizan information with current visible. It will be notify you if it found something suspicious.

To be sure that it's not false positive alert you will be prompted to reboot again. It's required because the some services drivers may be deleted at startup and this will cause the alarm.

Does Partizan is a panacea?

Hackers use a lot of rootkit modification combining with spyware components. RegRun Platinum guarantees that you can clean your computer from a deep hidden rootkits and from common spyware.

Does it clean rootkits in the auto mode?

No. It uses Greatis Application Database for detecting known root-kits/viruses/spyware. We suggest you to update the database. But some of the software will be detected as unknown - suspicious.

What you need to do in this case?

If you have enough computer skill to use professional tools included to the RegRun Platinum - OK, you can do it. If not, you can send detailed system report to the Greatis Support center: http://greatis.com/support and we will send the special file for auto cleaning your computer. The service is free for RegRun's users.

What's about self-protection?

  1. You can specify the own file name for Partizan executable.
  2. RegRun generates the random name for executable in the Windows mode. In addition, it will crypt the executable for preventing de-tection using MD5 signature and strings.

How to start rootkit detection using Partizan?

  1. Open RegRun Control Center.
  2. Choose the "Partizan" tab and set up the Partizan checkbox.

Does Partizan work with Platinum Edition only?

The rootkit auto detection is allowed for RegRun Platinum users only. Other users can use it for deleting virus files. Partizan is included to the free Reanimator software too.

How to uninstall Partizan?

Uninstall Partizan
  1. Open RegRun Start Control.
  2. Go to the Features menu.
  3. Choose "Partizan" item.
  4. Click on the "Remove" button.

Would you like to add your opinion?

Your Name (Not Required):

Your E-mail to contact (Not Required):


Description:

What's new?

March 7 2008
Partizan.exe is not a worm. Partizan.exe is a part of RegRun Suite, UnHackMe antirootkit. Updated. Symantec fixed false positive.

February 19 2008
RegRun Platinum Ukrainian 5.70

February 14 2008
Happy Valentine's day!
RegRun 5.7 released

February 11 2008
Spyware Doctor false positive. Partizan.sys wrong detection.

What is spXX.sys?

January 28 2007
Removing Medichi Rootkit

October 26 2007
Removal of Noskrnl.exe and Noskrnl.sys Rootkit (Spooldr clone)

July 25 2007
Removal Baidu rootkit (cnprov.sys)

July 24 2007
Removal Spooldr(ecard.exe) rootkit

June 25 2007
Fixing BSOD
in Winlogon Process

June 4 2007
Removal Areses Trojan

May 25 2007
Virus Feebs rootkit removal story

RegRun 5.5 beta updated

Release RegRun Reanimator 5.5.5.900

April 5 2007
What's this? Rthdcpl.exe - Illegal System DLL Relocation...

March 1 2007
Warning! Rootkit Unhooker

February 9 2007
Read our article about Unreal rootkit...

December 28 2006
Released free Rustock Rootkit(lzx32.sys) removal tool

November 29 2006
A#######.sys is a rootkit?

September 8 2006
Rootkit Removal instructions: ntsystem.exe

April 24 2006
What is BDGuard.sys?

April 17 2006
Virus or not? SPTD####.sys

March 31 2006
What is mc21.tmp, mc22.tmp, mc23.tmp?

January 19 2006
ICQCHK.exe, MSX.DLL free remover...
Educational discount...

Services
Ask Computer Guys

Windows startup programs

Articles
Using Registry Tracer...

RegRun against Trojans and Viruses

Specify an order for startup programs

RunGuard prevents a launch...

Using Bootlog Analyser...

They say
The Washinton Post suggests: "Consult the Greatis...

Wilders.ORG. Security advisors recommend...

Testimonials
You guys are awesome!!!!
Traci www.pentagonattack911.com

Bob Schmulian:
Absolutely love it and have recommended to many people!

Ian Robinson:
It is FANTASTIC! It has saved my life on more than one occasion since I purchased it less than 6 months ago. I now would not run my system without it... it's worth many times the cost! The service and support are terrific. Helpful - friendly - and accommodating; and generally a reply is received within 12 hours. Just great.

Theodore Soucie:
Since RegRun was installed my system is more stable. I use to experience freezeup daily. I have not had a crash.

Awards
Paul's Picks
Shareware Winner  

More...


Greatis Software Greatis | Security | AppDatabase | Utilities | Delphi/CB | Visual Basic | .NET | just4fun

Contacts | Add to Favorites | Recommend to a Friend | Privacy Policy | Copyright © 1998-2008 Greatis Software