Trojan

Trojan:Win32/Niktol.RPY!MTB (file analysis)

Malware Removal

The Trojan:Win32/Niktol.RPY!MTB is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Trojan:Win32/Niktol.RPY!MTB virus can do?

  • Sample contains Overlay data
  • The binary contains an unknown PE section name indicative of packing
  • Authenticode signature is invalid
  • Uses Windows utilities to create a scheduled task
  • Deletes executed files from disk

How to determine Trojan:Win32/Niktol.RPY!MTB?


File Info:

name: 9A7ED25A8F28FDE2E366.mlw
path: /opt/CAPEv2/storage/binaries/e77b9caed5e5e3301da77ded047a168e87ca107e3b27b40e0e8b923b215b5777
crc32: 87970770
md5: 9a7ed25a8f28fde2e3662828c9add205
sha1: e7fda8ef59ced9841fcddc6ad1486ab13ea7c7af
sha256: e77b9caed5e5e3301da77ded047a168e87ca107e3b27b40e0e8b923b215b5777
sha512: b5925068ca3a9f5f2e2de83fd275beea70914e6adaaadcbfcf119f674c764ade470de38822be0b90a954ac75a65150758f98f95318d17ae994146cb3bdf8b49a
ssdeep: 1536:j7fbN3eEDhDPA/pICdUkbBtW7upvaLU0bI5taxKo0IOlnToIfSw77OA:/7DhdC6kzWypvaQ0FxyNTBfSK
type: PE32 executable (console) Intel 80386, for MS Windows
tlsh: T1B1A35B02B3E143FAD5E2003601B9513F9B76E12887506DE7C74C3D869613E999B7E3EA
sha3_384: 7b4b8afb6a00ccaf6dc1637d7bc64c7d7b3573d5574af99e2e73627ee9206d062e0b074d8857ca6bf23f529ddc3dfc8b
ep_bytes: 68ac00000068000000006868804100e8
timestamp: 2019-07-30 08:52:45

Version Info:

0: [No Data]

Trojan:Win32/Niktol.RPY!MTB also known as:

BkavW32.AIDetectMalware
Elasticmalicious (high confidence)
MicroWorld-eScanTrojan.Generic.34305591
CAT-QuickHealTrojan.GenericPMF.S15043657
SkyhighBehavesLike.Win32.RealProtect.nh
MalwarebytesGeneric.Malware.AI.DDS
VIPRETrojan.Generic.34305591
SangforTrojan.Win32.Save.a
K7AntiVirusTrojan ( 0052419b1 )
K7GWTrojan ( 0052419b1 )
Cybereasonmalicious.f59ced
SymantecML.Attribute.HighConfidence
ESET-NOD32BAT/Agent.QBP
CynetMalicious (score: 100)
ClamAVWin.Malware.Agentb-10018199-0
KasperskyHEUR:Trojan.BAT.Agentb.gen
BitDefenderTrojan.Generic.34305591
AvastWin32:Malware-gen
RisingTrojan.Generic@AI.90 (RDMK:X4bzyks/gnzV2d0EUpDIZg)
EmsisoftTrojan.Generic.34305591 (B)
F-SecureTrojan.TR/Redcap.oxayp
TrendMicroTROJ_GEN.R03BC0DA924
SophosGeneric ML PUA (PUA)
IkarusTrojan.BAT.Agent
GDataWin32.Trojan.PSE.11TC70E
VaristW32/Kryptik.AYO.gen!Eldorado
AviraTR/Redcap.oxayp
Kingsoftmalware.kb.a.958
ArcabitTrojan.Generic.D20B7637
ZoneAlarmHEUR:Trojan.BAT.Agentb.gen
MicrosoftTrojan:Win32/Niktol.RPY!MTB
GoogleDetected
AhnLab-V3Malware/Win.Generic.C5496484
ALYacTrojan.Generic.34305591
Cylanceunsafe
PandaTrj/CI.A
TrendMicro-HouseCallTROJ_GEN.R03BC0DA924
TencentMalware.Win32.Gencirc.10bf73f8
YandexTrojan.Agent!UpFcVi1xmYw
SentinelOneStatic AI – Suspicious PE
MaxSecureTrojan.Malware.300983.susgen
FortinetW32/Agent.EDI!tr
AVGWin32:Malware-gen
DeepInstinctMALICIOUS
CrowdStrikewin/malicious_confidence_90% (W)

How to remove Trojan:Win32/Niktol.RPY!MTB?

Trojan:Win32/Niktol.RPY!MTB removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment