Trojan

Trojan:Win32/Niktol.RPY!MTB removal guide

Malware Removal

The Trojan:Win32/Niktol.RPY!MTB is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Trojan:Win32/Niktol.RPY!MTB virus can do?

  • Sample contains Overlay data
  • The binary contains an unknown PE section name indicative of packing
  • Authenticode signature is invalid
  • Uses Windows utilities to create a scheduled task
  • Deletes executed files from disk

How to determine Trojan:Win32/Niktol.RPY!MTB?


File Info:

name: 33F0B3C61D83BED5E489.mlw
path: /opt/CAPEv2/storage/binaries/7d4d4ec5c6553a5f87f12837042cce92188bc6a34879b3ac82c8c86878d30c95
crc32: C0505FE4
md5: 33f0b3c61d83bed5e489235e02580a20
sha1: 6e076d6e6a5086b9bc9290f7a22f66737428a968
sha256: 7d4d4ec5c6553a5f87f12837042cce92188bc6a34879b3ac82c8c86878d30c95
sha512: 0115131e3f0d4da4610ce567e8928d9f164b1ab2dc651975bf155bab8cb677b2857a326762dd4457ace28ed82cd8f0e8951a38df560dac8e6165f71f24c37fba
ssdeep: 1536:j7fbN3eEDhDPA/pICdUkbBtW7upvaLU0bI5taxKo0IOlnToIfSw77OO:/7DhdC6kzWypvaQ0FxyNTBfSk
type: PE32 executable (console) Intel 80386, for MS Windows
tlsh: T1DDA36C01F3E142FAD5E2043201BA613F9B36A6288750ADE7C74C3D929513ED59B7E3E9
sha3_384: a97fc719450c5d701746d5bfa4deef90bd8dc98276e95c7dea759bf498962bb09089961ca8a7a41a3d0fb154178217d0
ep_bytes: 68ac00000068000000006868804100e8
timestamp: 2019-07-30 08:52:45

Version Info:

0: [No Data]

Trojan:Win32/Niktol.RPY!MTB also known as:

BkavW32.AIDetectMalware
LionicTrojan.Win32.Agentb.X!c
Elasticmalicious (high confidence)
MicroWorld-eScanTrojan.Generic.34298972
CAT-QuickHealTrojan.GenericPMF.S15043657
SkyhighBehavesLike.Win32.RealProtect.nh
ALYacTrojan.Generic.34291854
MalwarebytesMalware.AI.3894574204
VIPRETrojan.Generic.34291854
SangforTrojan.Win32.Save.a
K7AntiVirusTrojan ( 0052419b1 )
BitDefenderTrojan.Generic.34298972
K7GWTrojan ( 0052419b1 )
Cybereasonmalicious.e6a508
SymantecML.Attribute.HighConfidence
APEXMalicious
KasperskyHEUR:Trojan.BAT.Agentb.gen
AlibabaTrojan:Win32/Niktol.5cdf92e0
ViRobotTrojan.Win.Z.Agent.98311.B
RisingTrojan.Generic@AI.90 (RDMK:X4bzyks/gnzV2d0EUpDIZg)
SophosMal/Generic-S
F-SecureTrojan.TR/Redcap.oxayp
TrendMicroTROJ_GEN.R002C0DKC23
FireEyeGeneric.mg.33f0b3c61d83bed5
EmsisoftTrojan.Generic.34298972 (B)
IkarusTrojan.BAT.Agent
JiangminTrojan.BAT.aww
GoogleDetected
AviraTR/Redcap.oxayp
VaristW32/Agent.EDI.gen!Eldorado
MicrosoftTrojan:Win32/Niktol.RPY!MTB
ArcabitTrojan.Generic.D20B5C5C
ZoneAlarmHEUR:Trojan.BAT.Agentb.gen
GDataWin32.Trojan.PSE.13RXIS3
CynetMalicious (score: 100)
AhnLab-V3Malware/Win.Generic.C5496484
McAfeeArtemis!33F0B3C61D83
MAXmalware (ai score=85)
DeepInstinctMALICIOUS
Cylanceunsafe
TrendMicro-HouseCallTROJ_GEN.R002C0DKC23
TencentTrojan.Win32.Redcap.hg
SentinelOneStatic AI – Malicious PE
MaxSecureTrojan.Malware.300983.susgen
FortinetW32/Agent.EDI!tr
AVGWin32:Malware-gen
AvastWin32:Malware-gen
CrowdStrikewin/malicious_confidence_90% (W)

How to remove Trojan:Win32/Niktol.RPY!MTB?

Trojan:Win32/Niktol.RPY!MTB removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment