Trojan

What is “Trojan:Win32/Niktol.RPY!MTB”?

Malware Removal

The Trojan:Win32/Niktol.RPY!MTB is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Trojan:Win32/Niktol.RPY!MTB virus can do?

  • Sample contains Overlay data
  • Uses Windows utilities for basic functionality
  • The binary contains an unknown PE section name indicative of packing
  • Authenticode signature is invalid
  • Uses Windows utilities to create a scheduled task
  • Deletes executed files from disk

How to determine Trojan:Win32/Niktol.RPY!MTB?


File Info:

name: 8CE497973C45A7AF5BE3.mlw
path: /opt/CAPEv2/storage/binaries/670e6dac117ee7658c46a207f86b3d70c6511583f29fe189cfc16b42137bdf4e
crc32: FEEC5A3B
md5: 8ce497973c45a7af5be3b94ec47c39f5
sha1: 7df7876c9698bf8d068dcecd07d0816e31281ab6
sha256: 670e6dac117ee7658c46a207f86b3d70c6511583f29fe189cfc16b42137bdf4e
sha512: c6aa8cce9909f8e20e7cacbac8e9460e32b97fe810bc6f9e202fad5e55e29611cd3002616983f0c133d585974c175ae76c1cbe6af3f9f842ac3f135206393538
ssdeep: 1536:D7fPGykbOqjoHm4pICdfkLtAfupcWX50MxFY+yIOlnToIfzxy4Os:fq6+ouCpk2mpcWJ0r+QNTBfzj
type: PE32 executable (GUI) Intel 80386, for MS Windows
tlsh: T11AA35B05B3E143FAC5E2043201BA503F9B76E52887546DE7C74C3C869653E998A7E3F9
sha3_384: 640ec6f95c95e6f1672c46e942ae8f51441bdceed473483b1f12752f74ee2f1d6574527078fa185aeafdaf4bbd6e31ff
ep_bytes: 68ac00000068000000006810804100e8
timestamp: 2019-07-30 08:52:50

Version Info:

0: [No Data]

Trojan:Win32/Niktol.RPY!MTB also known as:

BkavW32.AIDetectMalware
LionicTrojan.Win32.Tiny.trFe
MicroWorld-eScanTrojan.Generic.34305635
FireEyeGeneric.mg.8ce497973c45a7af
SkyhighBehavesLike.Win32.RealProtect.nh
McAfeeArtemis!8CE497973C45
Cylanceunsafe
SangforTrojan.Win32.Save.a
CrowdStrikewin/malicious_confidence_90% (D)
AlibabaTrojan:Win32/Niktol.3a4623b0
K7GWRiskware ( 00584baa1 )
K7AntiVirusRiskware ( 00584baa1 )
VirITTrojan.Win32.Genus.IHW
SymantecML.Attribute.HighConfidence
Elasticmalicious (high confidence)
ESET-NOD32BAT/Agent.QBP
APEXMalicious
ClamAVWin.Malware.Agentb-10018199-0
KasperskyHEUR:Trojan.BAT.Agentb.gen
BitDefenderTrojan.Generic.34305635
AvastWin32:Evo-gen [Trj]
TencentTrojan.BAT.Agentb.hc
SophosMal/Generic-S (PUA)
F-SecureTrojan.TR/Redcap.pmhod
VIPRETrojan.Generic.34305635
EmsisoftTrojan.Generic.34305635 (B)
IkarusTrojan.Win32.Agent
GDataWin32.Trojan.PSE.1I3XF62
WebrootW32.Trojan.Gen
GoogleDetected
AviraTR/Redcap.pmhod
VaristW32/Trojan.VFBA-8001
Antiy-AVLTrojan/Win32.Tiggre
ArcabitTrojan.Generic.D20B7663
ZoneAlarmHEUR:Trojan.BAT.Agentb.gen
MicrosoftTrojan:Win32/Niktol.RPY!MTB
CynetMalicious (score: 100)
AhnLab-V3Malware/Win.Generic.C5253524
ALYacTrojan.Generic.34305635
MAXmalware (ai score=86)
VBA32Trojan.BAT.Agentb
MalwarebytesGeneric.Malware.AI.DDS
ZonerTrojan.Win32.85523
RisingTrojan.Generic@AI.95 (RDML:xmJapJLUqP8d8+d7xHW6LA)
YandexTrojan.Agent!I4Q/548sWx4
SentinelOneStatic AI – Malicious PE
MaxSecureTrojan.Malware.300983.susgen
FortinetW32/VFBA.8001!tr
AVGWin32:Evo-gen [Trj]
Cybereasonmalicious.c9698b
DeepInstinctMALICIOUS

How to remove Trojan:Win32/Niktol.RPY!MTB?

Trojan:Win32/Niktol.RPY!MTB removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment