Trojan

Trojan:Win32/Niktol.RPY!MTB information

Malware Removal

The Trojan:Win32/Niktol.RPY!MTB is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Trojan:Win32/Niktol.RPY!MTB virus can do?

  • Executed a command line with /C or /R argument to terminate command shell on completion which can be used to hide execution
  • Sample contains Overlay data
  • The binary contains an unknown PE section name indicative of packing
  • Authenticode signature is invalid
  • Uses Windows utilities to create a scheduled task
  • Attempts to repeatedly call a single API many times in order to delay analysis time
  • Deletes executed files from disk

How to determine Trojan:Win32/Niktol.RPY!MTB?


File Info:

name: CD7CFC94784A6ABED167.mlw
path: /opt/CAPEv2/storage/binaries/ffb4197e168ea2e4c76b0756e5901251b5b19544b2f88d09405870ee14fc2bac
crc32: E6BF3703
md5: cd7cfc94784a6abed1671201847daf33
sha1: fab5456c70ca8c8d4145bef2774e8ef031bd45d9
sha256: ffb4197e168ea2e4c76b0756e5901251b5b19544b2f88d09405870ee14fc2bac
sha512: a7a03a7226446eeeae87b75db16b08d663b427def22195d1d3b3da510965e9a3c1aa9bff72b8e1db3e6ee9ee0342674365c60ac914f2990565795af8a72747cf
ssdeep: 1536:j7fbN3eEDhDPA/pICdUkbBtW7upvaLU0bI5taxKo0IOlnToIfSw77OQ:/7DhdC6kzWypvaQ0FxyNTBfSq
type: PE32 executable (console) Intel 80386, for MS Windows
tlsh: T149A35A06B3E143BAC5E2003602B9513F8B76E52887506DE7C74C3C969613E999B7E3F6
sha3_384: 0443ad428c0b1630be5e9a6a2fbea92d4d375c3b169b8a9ecfe4fc9587d893e0e3760580ac79c79267cc6fa908276743
ep_bytes: 68ac00000068000000006868804100e8
timestamp: 2019-07-30 08:52:45

Version Info:

0: [No Data]

Trojan:Win32/Niktol.RPY!MTB also known as:

BkavW32.AIDetectMalware
Elasticmalicious (high confidence)
MicroWorld-eScanTrojan.Generic.34305591
ClamAVWin.Malware.Agentb-10018199-0
CAT-QuickHealTrojan.GenericPMF.S15043657
SkyhighBehavesLike.Win32.RealProtect.ch
MalwarebytesGeneric.Malware.AI.DDS
SangforTrojan.Win32.Save.a
K7AntiVirusTrojan ( 0052419b1 )
K7GWTrojan ( 0052419b1 )
Cybereasonmalicious.c70ca8
ArcabitTrojan.Generic.D20B7637
SymantecML.Attribute.HighConfidence
ESET-NOD32BAT/Agent.QBP
CynetMalicious (score: 100)
KasperskyHEUR:Trojan.BAT.Agentb.gen
BitDefenderTrojan.Generic.34305591
AvastWin32:Malware-gen
EmsisoftTrojan.Generic.34305591 (B)
F-SecureTrojan.TR/Redcap.oxayp
VIPRETrojan.Generic.34305591
SophosGeneric ML PUA (PUA)
IkarusTrojan.BAT.Agent
GoogleDetected
AviraTR/Redcap.oxayp
Kingsoftmalware.kb.a.956
MicrosoftTrojan:Win32/Niktol.RPY!MTB
ZoneAlarmHEUR:Trojan.BAT.Agentb.gen
GDataWin32.Trojan.PSE.11TC70E
VaristW32/Kryptik.AYO.gen!Eldorado
AhnLab-V3Malware/Win.Generic.C5496484
VBA32Trojan.BAT.Agentb
ALYacTrojan.Generic.34305591
Cylanceunsafe
RisingTrojan.Generic@AI.90 (RDMK:X4bzyks/gnzV2d0EUpDIZg)
YandexTrojan.Agent!UpFcVi1xmYw
SentinelOneStatic AI – Suspicious PE
FortinetW32/Agent.EDI!tr
AVGWin32:Malware-gen
DeepInstinctMALICIOUS
CrowdStrikewin/malicious_confidence_70% (D)

How to remove Trojan:Win32/Niktol.RPY!MTB?

Trojan:Win32/Niktol.RPY!MTB removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment