Trojan

Trojan:Win32/Niktol.RPY!MTB removal instruction

Malware Removal

The Trojan:Win32/Niktol.RPY!MTB is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Trojan:Win32/Niktol.RPY!MTB virus can do?

  • Executed a command line with /C or /R argument to terminate command shell on completion which can be used to hide execution
  • Sample contains Overlay data
  • Uses Windows utilities for basic functionality
  • The binary contains an unknown PE section name indicative of packing
  • Authenticode signature is invalid
  • Uses Windows utilities to create a scheduled task
  • Deletes executed files from disk

How to determine Trojan:Win32/Niktol.RPY!MTB?


File Info:

name: CD085C425D180825E3FE.mlw
path: /opt/CAPEv2/storage/binaries/10701500f8018b9936f1e3dcb72a67b31cca4a6472e1054e2d147c3e079bd3d7
crc32: 412BD3E5
md5: cd085c425d180825e3fedfa5c2f923d2
sha1: 9c7463d171f8d93ebe92989f7f4681905a298c57
sha256: 10701500f8018b9936f1e3dcb72a67b31cca4a6472e1054e2d147c3e079bd3d7
sha512: e80328cd620bd10ca9d4a6fef1e214e43abe2251720edb5de6bff979f76088b0935502e14be8a0a38af8ba886775d29e12ffeb773fcf0faf62e24ed491878e82
ssdeep: 1536:D7fPGykbOqjoHm4pICdfkLtAfupcWX50MxFY+yIOlnToIfzxy4OD:fq6+ouCpk2mpcWJ0r+QNTBfzm
type: PE32 executable (GUI) Intel 80386, for MS Windows
tlsh: T1B5935C05B3E642FAD9E2053200B6613F9776A6248724ACE7C34C3C839653ED59A7D3F9
sha3_384: c13e51ac4a56add3f550494da54dd77556da9aa414bccd401ec3164892e5ada606f0f198e592885471674edc6f76e878
ep_bytes: 68ac00000068000000006810804100e8
timestamp: 2019-07-30 08:52:50

Version Info:

0: [No Data]

Trojan:Win32/Niktol.RPY!MTB also known as:

BkavW32.AIDetectMalware
Elasticmalicious (high confidence)
MicroWorld-eScanTrojan.Generic.34256960
FireEyeGeneric.mg.cd085c425d180825
SkyhighBehavesLike.Win32.RealProtect.nh
ALYacTrojan.Generic.34256960
MalwarebytesGeneric.Malware.AI.DDS
VIPRETrojan.Generic.34256960
SangforTrojan.Win32.Save.a
K7AntiVirusRiskware ( 00584baa1 )
BitDefenderTrojan.Generic.34256960
K7GWRiskware ( 00584baa1 )
CrowdStrikewin/malicious_confidence_90% (D)
VirITTrojan.Win32.Genus.IHW
SymantecML.Attribute.HighConfidence
APEXMalicious
KasperskyHEUR:Trojan.BAT.Agentb.gen
RisingTrojan.Generic@AI.100 (RDML:xmJapJLUqP8d8+d7xHW6LA)
SophosGeneric ML PUA (PUA)
F-SecureTrojan.TR/Redcap.pmhod
ZillyaTool.Lazagne.Win32.102
EmsisoftTrojan.Generic.34256960 (B)
IkarusTrojan.Win32.Agent
WebrootW32.Trojan.Gen
GoogleDetected
AviraTR/Redcap.pmhod
VaristW32/Trojan.VFBA-8001
Antiy-AVLTrojan/Win32.Tiggre
MicrosoftTrojan:Win32/Niktol.RPY!MTB
ArcabitTrojan.Generic.D20AB840
ZoneAlarmHEUR:Trojan.BAT.Agentb.gen
GDataTrojan.Generic.34256960
CynetMalicious (score: 100)
AhnLab-V3Malware/Win.Generic.C5253524
MAXmalware (ai score=81)
DeepInstinctMALICIOUS
Cylanceunsafe
ZonerTrojan.Win32.85523
TencentTrojan.BAT.Agentb.hb
SentinelOneStatic AI – Malicious PE
MaxSecureTrojan.Malware.300983.susgen
FortinetW32/VFBA.8001!tr
AVGWin32:Evo-gen [Trj]
Cybereasonmalicious.171f8d
AvastWin32:Evo-gen [Trj]

How to remove Trojan:Win32/Niktol.RPY!MTB?

Trojan:Win32/Niktol.RPY!MTB removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment