English
The Internet threat alert status is currently normal. At present, no major epidemics or other serious incidents have been recorded by Kaspersky Lab’s monitoring service. Internet threat level: 1

not-a-virus:PSWTool.Win32.RAS.g

Detected Apr 11 2008 22:45 GMT
Released Apr 12 2008 03:03 GMT
Published Jan 27 2009 06:58 GMT

Technical Details
Payload
Removal instructions

Technical Details

This hacker tool is designed to restore activation codes for Windows XP and Microsoft Office 2003. It is a Windows PE EXE file. It is 272357 bytes in size. It is packed using UPX. The unpacked file is approximately 310KB in size. It is written in C++.


Payload

This program shows the activation keys for Microsoft Windows XP and Microsoft Office 2003, making it possible to modify, print or save the keys. The program's interface is shown below:

The program also makes it possible to search the local network for Windows activation keys by giving a specific IP address or computer name.

The program makes it possible to modify the name of the registered user and the name of the organization:


Removal instructions

If your computer does not have an up-to-date antivirus, or does not have an antivirus solution at all, follow the instructions below to delete the malicious program:

  1. Delete the original program file (the location will depend on how the program originally penetrated the victim machine).
  2. Update your antivirus databases and perform a full scan of the computer (download a trial version of Kaspersky Anti-Virus).

Bookmark and Share
Share
PSWTool

Programs classified as PSWTool can be used to view or restore forgotten (often hidden) passwords. They can also be used with malicious intent, even though the programs themselves have no malicious payload.

If a user has installed such a program on his/her computer, or if it was installed by a system administrator, then it does not pose any threat.


Aliases

not-a-virus:PSWTool.Win32.RAS.g (Kaspersky Lab) is also known as:

  • Mal/Generic-L (Sophos)
  • Hacktool.Crack.XP-1 (ClamAV)
  • Application/PassRock (Panda)
  • W32/MalwareF.OHNY (FPROT)
  • Virtool.22729 (BitDef7)
  • Trojan.PSWTool!NQ2Yc+V+uPg (VirusBuster)
  • not-a-Virus.Hacktool.OfficeKey (Ikarus)
  • not-a-virus.HackTool.Findkey (Ikarus)
  • NseCheckFile2() returned 0x00010018 (Norman)
  • Trojan.Win32.Generic.1235CAFF (Rising)
  • Trojan.PSWTool!NQ2Yc+V+uPg (VirusBusterBeta)