Trojan

About “Trojan:Win32/Niktol.RPX!MTB” infection

Malware Removal

The Trojan:Win32/Niktol.RPX!MTB is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Trojan:Win32/Niktol.RPX!MTB virus can do?

  • Behavioural detection: Executable code extraction – unpacking
  • Executed a command line with /C or /R argument to terminate command shell on completion which can be used to hide execution
  • Sample contains Overlay data
  • Presents an Authenticode digital signature
  • Uses Windows utilities for basic functionality
  • Reads data out of its own binary image
  • The binary contains an unknown PE section name indicative of packing
  • Authenticode signature is invalid
  • Uses Windows utilities to create a scheduled task
  • Behavioural detection: Injection (Process Hollowing)
  • Behavioural detection: Injection (inter-process)
  • Attempts to modify proxy settings
  • Deletes executed files from disk
  • Touches a file containing cookies, possibly for information gathering
  • Yara rule detections observed from a process memory dump/dropped files/CAPE

How to determine Trojan:Win32/Niktol.RPX!MTB?


File Info:

name: CA4DD591291F8A7D930F.mlw
path: /opt/CAPEv2/storage/binaries/372c3197184c262d49ea5384cd3521f05414ca7f099dce4aaa76569060b455ff
crc32: D8426F19
md5: ca4dd591291f8a7d930f6d70e99e4d8a
sha1: 83e39010ee2e272b27b92ee8b68e12fe703c1ea0
sha256: 372c3197184c262d49ea5384cd3521f05414ca7f099dce4aaa76569060b455ff
sha512: 34e8897374701ecc827130e8c2f795d9211d5f20eede49da1ebe7ef822690a682a09ea95aa2a134506a395b7199ac4ef93b2dab4c1d041143b38900a49a75d01
ssdeep: 1536:i7fbN3eEDhDPA/pICdUkbBtW7upvaLU0bI5taxKo0IOlnToIfUwiAOG6:A7DhdC6kzWypvaQ0FxyNTBfUrt
type: PE32 executable (console) Intel 80386, for MS Windows
tlsh: T18DA36D41F2E142F7EAF2093100E6762F9B3663289760A8DBC75C2D525943BD1A73D3E9
sha3_384: aae67776bf8a403524c3467f93468e23810ec35485a1452f13dd3e6acdeff51c95cfe9d8bbe15c9909853800494412c3
ep_bytes: 68ac00000068000000006868804100e8
timestamp: 2019-07-30 08:52:45

Version Info:

0: [No Data]

Trojan:Win32/Niktol.RPX!MTB also known as:

BkavW32.AIDetectMalware
LionicTrojan.Win32.RanSerKD.4!c
MicroWorld-eScanTrojan.GenericKD.69660522
FireEyeGeneric.mg.ca4dd591291f8a7d
CAT-QuickHealTrojan.GenericPMF.S18974517
SkyhighBehavesLike.Win32.RealProtect.nh
ALYacTrojan.GenericKD.69660522
MalwarebytesTrojan.MalPack.CD
VIPRETrojan.GenericKD.69660522
SangforTrojan.Win32.Agent.Vjmi
K7AntiVirusRiskware ( 00584baa1 )
BitDefenderTrojan.GenericKD.69660522
K7GWRiskware ( 00584baa1 )
BitDefenderThetaGen:NN.ZexaF.36792.guY@aC6xFQc
SymantecML.Attribute.HighConfidence
Elasticmalicious (high confidence)
APEXMalicious
ClamAVWin.Trojan.Generic-10009708-0
AlibabaTrojan:Win32/Niktol.183ba256
SophosGeneric ML PUA (PUA)
TrendMicroTROJ_GEN.R002C0DJE23
EmsisoftTrojan.GenericKD.69660522 (B)
IkarusTrojan.Win32.Niktol
JiangminTrojan.BAT.aww
GoogleDetected
VaristW32/Kryptik.KUH.gen!Eldorado
MicrosoftTrojan:Win32/Niktol.RPX!MTB
ArcabitTrojan.Generic.D426EF6A
GDataTrojan.GenericKD.69660522
CynetMalicious (score: 100)
AhnLab-V3Trojan/Win32.Generic.C2839558
McAfeeArtemis!CA4DD591291F
MAXmalware (ai score=87)
DeepInstinctMALICIOUS
Cylanceunsafe
PandaTrj/Genetic.gen
TrendMicro-HouseCallTROJ_GEN.R002C0DJE23
SentinelOneStatic AI – Malicious PE
MaxSecureTrojan.Malware.300983.susgen
FortinetW32/PossibleThreat
AVGWin32:Malware-gen
AvastWin32:Malware-gen
CrowdStrikewin/malicious_confidence_90% (W)

How to remove Trojan:Win32/Niktol.RPX!MTB?

Trojan:Win32/Niktol.RPX!MTB removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment