Malware

Should I remove “Win32/Induc.A”?

Malware Removal

The Win32/Induc.A is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Win32/Induc.A virus can do?

  • Executable code extraction
  • Creates RWX memory
  • A process attempted to delay the analysis task.
  • Reads data out of its own binary image
  • Drops a binary and executes it
  • Performs some HTTP requests
  • Queries information on disks, possibly for anti-virtualization
  • Checks for the presence of known windows from debuggers and forensic tools
  • Installs itself for autorun at Windows startup
  • Checks for the presence of known devices from debuggers and forensic tools

Related domains:

www.apache-gui.ru

How to determine Win32/Induc.A?


File Info:

crc32: 7254A888
md5: a16986e8cb7cc583a39f8240453fdc00
name: 26116_pwdgenlite.exe
sha1: 3153fc6d366a96ed06f99231a270886a81340082
sha256: 55c7e4cbea4eb1a1c6f8c4ca1d026b831d9f5da7786a42a06fbc19c58b013e78
sha512: c30159828a36b033fe5c15bf6418b75f18a6d9fd9d3c82f487061136aaeff4a77cd13574749e79d0f74d515c44219c30ed9a276f3cdc6aed01a8d0b95ba23d8d
ssdeep: 49152:v2z/lB9P+cn1YgFl6W8QF47/D7X4kyAW5FRV5u7Iufrd2EnR04v/TuBVBtpJB5Yl:uzlBDn1h4yAAwnd2Ef/TozYNP
type: PE32 executable (GUI) Intel 80386, for MS Windows

Version Info:

LegalCopyright: Copyright (C) 2001-2009 x418x41f x417x438x43cx438x43d x421x435x440x433x435x439 x410x43bx435x43ax441x430x43dx434x440x43ex432x438x447
FileVersion: 4.1.0.0
CompanyName: x418x41f x417x438x43cx438x43d x421x435x440x433x435x439 x410x43bx435x43ax441x430x43dx434x440x43ex432x438x447
Comments: This installation was built with Inno Setup.
ProductName: Htpasswd Generator
ProductVersion: 4.1.0.0
FileDescription: Htpasswd Generator Setup
Translation: 0x0000 0x04b0

Win32/Induc.A also known as:

MicroWorld-eScanWin32.Induc.A
FireEyeWin32.Induc.A
CylanceUnsafe
VIPRETrojan.Win32.Generic!BT
BitDefenderWin32.Induc.A
Cybereasonmalicious.8cb7cc
SymantecTrojan.ADH.2
AvastWin32:Induc
GDataWin32.Induc.A (2x)
KasperskyVirus.Win32.Induc.b
AlibabaVirus:Win32/Induc.c6e41595
NANO-AntivirusTrojan.Win32.Induc.lkvlm
AegisLabVirus.Win32.Induc.n!c
TencentWin32.Virus.Agent.cjdh
EmsisoftWin32.Induc.A (B)
ComodoMalware@#1yyy72zfcq7cd
F-SecureMalware.W32/Induc.blr
DrWebWin32.Induc
McAfee-GW-EditionBehavesLike.Win32.Virus.vc
SophosMal/Generic-S
IkarusInduc.Win32
AviraappLiteHtpasswdGenerator.exe
ArcabitWin32.Induc.A
ZoneAlarmVirus.Win32.Induc.b
MicrosoftTrojan:Win32/Vigorf.A
BitDefenderThetaAI:FileInfector.CFA710080D
MAXmalware (ai score=99)
PandaTrj/CI.A
ESET-NOD32a variant of Win32/Induc.A
RisingVirus.Induc!1.9B53 (CLOUD)
FortinetW32/Induc.B
AVGWin32:Induc
Qihoo-360Malware.Radar03.Gen

How to remove Win32/Induc.A?

Win32/Induc.A removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment