Trojan

Trojan:Win32/Niktol.AB!MTB removal instruction

Malware Removal

The Trojan:Win32/Niktol.AB!MTB is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Trojan:Win32/Niktol.AB!MTB virus can do?

  • Behavioural detection: Executable code extraction – unpacking
  • Sample contains Overlay data
  • Uses Windows utilities for basic functionality
  • Reads data out of its own binary image
  • CAPE extracted potentially suspicious content
  • The binary contains an unknown PE section name indicative of packing
  • Authenticode signature is invalid
  • Uses Windows utilities to create a scheduled task
  • Behavioural detection: Injection (inter-process)
  • Behavioural detection: Injection with CreateRemoteThread in a remote process
  • Attempts to modify proxy settings
  • Deletes executed files from disk
  • Touches a file containing cookies, possibly for information gathering

How to determine Trojan:Win32/Niktol.AB!MTB?


File Info:

name: FEE65911914DCB594D01.mlw
path: /opt/CAPEv2/storage/binaries/672f54ebf7fe3b6e45f93cd11f28d86c187da9d06c8c34fb989c1876999e5862
crc32: 5AB0A832
md5: fee65911914dcb594d01828c46a2aec1
sha1: d19407ea06d26dfdc1790bbc0805ce1a0c68f3dc
sha256: 672f54ebf7fe3b6e45f93cd11f28d86c187da9d06c8c34fb989c1876999e5862
sha512: 23972e578ca7f2b1fa6462ee4118b02ab9a562f92df10d0120b644835182d1a21f47f12c554c3543f6fded4604eeb90633bfa54f45b6e23c1943c7f215883c5c
ssdeep: 1536:b7fbN3eEDhDPA/pICdUkbBtW7upvaLU0bI5taxKo0IOlnToIfkwEO:37DhdC6kzWypvaQ0FxyNTBfk
type: PE32 executable (console) Intel 80386, for MS Windows
tlsh: T118936D41F3E202F7E6F2053100A6726F973663389764A8EBC74C2D529913AD5A63D3F9
sha3_384: 4801963799580ac37730aea410b7350f2a23af7aecbfd7c8ff9fd3f7dfe5e98e53a406b4daadd047d0d7db3a8cc6f626
ep_bytes: 68ac00000068000000006868804100e8
timestamp: 2019-07-30 08:52:45

Version Info:

0: [No Data]

Trojan:Win32/Niktol.AB!MTB also known as:

BkavW32.AIDetectMalware
LionicTrojan.Win32.Generic.4!c
MicroWorld-eScanTrojan.GenericKD.70387967
FireEyeGeneric.mg.fee65911914dcb59
CAT-QuickHealTrojan.GenericPMF.S18974517
SkyhighBehavesLike.Win32.RealProtect.mh
ALYacTrojan.GenericKD.70387967
Cylanceunsafe
SangforTrojan.Win32.Save.a
K7AntiVirusRiskware ( 00584baa1 )
AlibabaTrojan:Win32/Niktol.dc301997
K7GWRiskware ( 00584baa1 )
Cybereasonmalicious.a06d26
ArcabitTrojan.Generic.D43208FF
SymantecML.Attribute.HighConfidence
Elasticmalicious (high confidence)
ESET-NOD32BAT/Starter.NKC
CynetMalicious (score: 100)
ClamAVWin.Trojan.Generic-10011119-0
BitDefenderTrojan.GenericKD.70387967
AvastWin32:Malware-gen
TencentTrojan.Win32.Redcap.hg
SophosGeneric ML PUA (PUA)
F-SecureTrojan.TR/Redcap.lfolj
VIPRETrojan.GenericKD.70387967
TrendMicroTROJ_GEN.R002C0DK423
EmsisoftTrojan.GenericKD.70387967 (B)
IkarusTrojan.Win32.Occamy
VaristW32/Kryptik.AYO.gen!Eldorado
AviraTR/Redcap.lfolj
MicrosoftTrojan:Win32/Niktol.AB!MTB
GDataTrojan.GenericKD.70387967
GoogleDetected
AhnLab-V3Malware/Win.Malware-gen.C5535005
McAfeeArtemis!FEE65911914D
MAXmalware (ai score=89)
MalwarebytesGeneric.Malware/Suspicious
TrendMicro-HouseCallTROJ_GEN.R002C0DK423
RisingTrojan.Starter/BAT!8.13291 (CLOUD)
SentinelOneStatic AI – Malicious PE
MaxSecureTrojan.Malware.8040.susgen
FortinetW32/Nitol.AB!tr
AVGWin32:Malware-gen
DeepInstinctMALICIOUS
CrowdStrikewin/malicious_confidence_70% (D)

How to remove Trojan:Win32/Niktol.AB!MTB?

Trojan:Win32/Niktol.AB!MTB removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment