Trojan

About “Trojan:Win32/Niktol.RPY!MTB” infection

Malware Removal

The Trojan:Win32/Niktol.RPY!MTB is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Trojan:Win32/Niktol.RPY!MTB virus can do?

  • Executed a command line with /C or /R argument to terminate command shell on completion which can be used to hide execution
  • Sample contains Overlay data
  • Uses Windows utilities for basic functionality
  • The binary contains an unknown PE section name indicative of packing
  • Authenticode signature is invalid
  • Uses Windows utilities to create a scheduled task
  • Deletes executed files from disk

How to determine Trojan:Win32/Niktol.RPY!MTB?


File Info:

name: BC563AB2C0317C2B3314.mlw
path: /opt/CAPEv2/storage/binaries/7b43670bd7a9a5a4145e25458a3d6bd6d3ee15573dbd7d1b8f8ab1019f2feb6d
crc32: D64B4599
md5: bc563ab2c0317c2b33147be6a2df9eb3
sha1: 2630b97f971541bb397f3916437e2cd151beb511
sha256: 7b43670bd7a9a5a4145e25458a3d6bd6d3ee15573dbd7d1b8f8ab1019f2feb6d
sha512: 0204420d2bea2b49fa82434c9bc4bec45024babdecdc4b4e4619f71c6faeaaa265f9568b3e9fd6526fbcaadb325216c7b69075d4625f6bbe3e409356db3a70ec
ssdeep: 1536:D7fPGykbOqjoHm4pICdfkLtAfupcWX50MxFY+yIOlnToIfzxy4Om:fq6+ouCpk2mpcWJ0r+QNTBfzf
type: PE32 executable (GUI) Intel 80386, for MS Windows
tlsh: T129935C45B3E242FAD9E2053200B6613F9776A6248724ACDBC34C3C839653ED59A7D3F9
sha3_384: 9fe40fd1aebad2fce1b76f585702779a75d1ffff177d04854a7bfa4d5ed240742d042f73f8096709aa370aff89ca3552
ep_bytes: 68ac00000068000000006810804100e8
timestamp: 2019-07-30 08:52:50

Version Info:

0: [No Data]

Trojan:Win32/Niktol.RPY!MTB also known as:

BkavW32.AIDetectMalware
MicroWorld-eScanTrojan.Generic.34256960
FireEyeGeneric.mg.bc563ab2c0317c2b
SkyhighBehavesLike.Win32.RealProtect.nh
MalwarebytesGeneric.Malware.AI.DDS
VIPRETrojan.Generic.34256960
SangforTrojan.Win32.Save.a
K7AntiVirusRiskware ( 00584baa1 )
BitDefenderTrojan.Generic.34256960
K7GWRiskware ( 00584baa1 )
Cybereasonmalicious.f97154
VirITTrojan.Win32.Genus.IHW
Elasticmalicious (high confidence)
APEXMalicious
KasperskyHEUR:Trojan.BAT.Agentb.gen
RisingTrojan.Generic@AI.99 (RDML:xmJapJLUqP8d8+d7xHW6LA)
SophosGeneric ML PUA (PUA)
F-SecureTrojan.TR/Redcap.pmhod
ZillyaTool.Lazagne.Win32.102
EmsisoftTrojan.Generic.34256960 (B)
IkarusTrojan.Win32.Agent
MAXmalware (ai score=89)
WebrootW32.Trojan.Gen
GoogleDetected
AviraTR/Redcap.pmhod
VaristW32/Trojan.VFBA-8001
Antiy-AVLTrojan/Win32.Tiggre
MicrosoftTrojan:Win32/Niktol.RPY!MTB
ArcabitTrojan.Generic.D20AB840
ZoneAlarmHEUR:Trojan.BAT.Agentb.gen
GDataTrojan.Generic.34256960
CynetMalicious (score: 100)
AhnLab-V3Malware/Win.Generic.C5253524
ALYacTrojan.Generic.34256960
DeepInstinctMALICIOUS
Cylanceunsafe
PandaTrj/Genetic.gen
ZonerTrojan.Win32.85523
SentinelOneStatic AI – Malicious PE
MaxSecureTrojan.Malware.300983.susgen
FortinetW32/VFBA.8001!tr
AVGWin32:Evo-gen [Trj]
AvastWin32:Evo-gen [Trj]
CrowdStrikewin/malicious_confidence_90% (D)

How to remove Trojan:Win32/Niktol.RPY!MTB?

Trojan:Win32/Niktol.RPY!MTB removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment