Trojan

Trojan:Win32/Niktol.RPY!MTB removal tips

Malware Removal

The Trojan:Win32/Niktol.RPY!MTB is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Trojan:Win32/Niktol.RPY!MTB virus can do?

  • Sample contains Overlay data
  • Uses Windows utilities for basic functionality
  • The binary contains an unknown PE section name indicative of packing
  • Authenticode signature is invalid
  • Uses Windows utilities to create a scheduled task
  • Deletes executed files from disk

How to determine Trojan:Win32/Niktol.RPY!MTB?


File Info:

name: 0DB63A62E5807E2C36A0.mlw
path: /opt/CAPEv2/storage/binaries/337a84acf9e1ad2107c708a292b3b5e2bd9ff6126cd7797c1d6945d2cd2c5caf
crc32: 447B1FFE
md5: 0db63a62e5807e2c36a0c02759c84e59
sha1: fd504cdfc93eae97fde5fffc437860a5484d5b24
sha256: 337a84acf9e1ad2107c708a292b3b5e2bd9ff6126cd7797c1d6945d2cd2c5caf
sha512: 7d3573be81d6758c9de2437c8319f9999b0778a0e24ed502b0aaaece3815c23381bfe8a1cb9c64b94c6d340a1689d8cefb1e1ab8a215fd94a0d81d6928cfdfe0
ssdeep: 1536:D7fPGykbOqjoHm4pICdfkLtAfupcWX50MxFY+yIOlnToIfzxy4OE:fq6+ouCpk2mpcWJ0r+QNTBfzh
type: PE32 executable (GUI) Intel 80386, for MS Windows
tlsh: T1E0935C45F3E242F6D9E2053200B6612F9776A6248724ACEBC34C3C839653ED59A7D3F9
sha3_384: 3b6c90741f5d5fdcdf3f310a38051d6d1cf4c309872a21fcc1654172225a572e49057037aec218c2d7735f430957e5da
ep_bytes: 68ac00000068000000006810804100e8
timestamp: 2019-07-30 08:52:50

Version Info:

0: [No Data]

Trojan:Win32/Niktol.RPY!MTB also known as:

BkavW32.AIDetectMalware
MicroWorld-eScanTrojan.Generic.34256960
FireEyeGeneric.mg.0db63a62e5807e2c
SkyhighBehavesLike.Win32.RealProtect.nh
ALYacTrojan.Generic.34256960
MalwarebytesGeneric.Malware.AI.DDS
VIPRETrojan.Generic.34256960
SangforTrojan.Win32.Save.a
K7AntiVirusRiskware ( 00584baa1 )
BitDefenderTrojan.Generic.34256960
K7GWRiskware ( 00584baa1 )
CrowdStrikewin/malicious_confidence_90% (D)
VirITTrojan.Win32.Genus.IHW
Elasticmalicious (high confidence)
APEXMalicious
KasperskyHEUR:Trojan.BAT.Agentb.gen
RisingTrojan.Generic@AI.99 (RDML:xmJapJLUqP8d8+d7xHW6LA)
SophosGeneric ML PUA (PUA)
F-SecureTrojan.TR/Redcap.pmhod
ZillyaTool.Lazagne.Win32.102
EmsisoftTrojan.Generic.34256960 (B)
IkarusTrojan.Win32.Agent
WebrootW32.Trojan.Gen
GoogleDetected
AviraTR/Redcap.pmhod
VaristW32/Trojan.VFBA-8001
Antiy-AVLTrojan/Win32.Tiggre
MicrosoftTrojan:Win32/Niktol.RPY!MTB
ArcabitTrojan.Generic.D20AB840
ZoneAlarmHEUR:Trojan.BAT.Agentb.gen
GDataTrojan.Generic.34256960
CynetMalicious (score: 100)
AhnLab-V3Malware/Win.Generic.C5253524
MAXmalware (ai score=89)
DeepInstinctMALICIOUS
Cylanceunsafe
PandaTrj/Genetic.gen
ZonerTrojan.Win32.85523
TencentTrojan.BAT.Agentb.hb
SentinelOneStatic AI – Malicious PE
MaxSecureTrojan.Malware.300983.susgen
FortinetW32/VFBA.8001!tr
AVGWin32:Evo-gen [Trj]
Cybereasonmalicious.fc93ea
AvastWin32:Evo-gen [Trj]

How to remove Trojan:Win32/Niktol.RPY!MTB?

Trojan:Win32/Niktol.RPY!MTB removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment