Trojan

How to remove “Trojan:Win32/Niktol.RPY!MTB”?

Malware Removal

The Trojan:Win32/Niktol.RPY!MTB is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Trojan:Win32/Niktol.RPY!MTB virus can do?

  • Executed a command line with /C or /R argument to terminate command shell on completion which can be used to hide execution
  • Sample contains Overlay data
  • Uses Windows utilities for basic functionality
  • The binary contains an unknown PE section name indicative of packing
  • Authenticode signature is invalid
  • Uses Windows utilities to create a scheduled task
  • Deletes executed files from disk

How to determine Trojan:Win32/Niktol.RPY!MTB?


File Info:

name: 6556311DAF0D7F76D3A8.mlw
path: /opt/CAPEv2/storage/binaries/45a600e21993e94339e368ef8a9a3a8cf2ebf6493b895e2b3a7ece871db4d3a4
crc32: 36AAC4C2
md5: 6556311daf0d7f76d3a8a2d15133dc57
sha1: ac4bc49c31c125055adbd71b5cdad1afa31880c4
sha256: 45a600e21993e94339e368ef8a9a3a8cf2ebf6493b895e2b3a7ece871db4d3a4
sha512: 3bd43b7faa1d044ca5e38da785f65b2fedd023a164ea6cc97232ff3f16de57cfc473b9a83f3cbc652d2d93fd14a61c780834d426100447d28f09b2d4a56deeb2
ssdeep: 1536:D7fPGykbOqjoHm4pICdfkLtAfupcWX50MxFY+yIOlnToIfzxy4Oq:fq6+ouCpk2mpcWJ0r+QNTBfzp
type: PE32 executable (GUI) Intel 80386, for MS Windows
tlsh: T1E7A35A05B3E143FAC5E2043201BA503F9B76E52887546DE7C74C3C869653E998ABE3F9
sha3_384: c27f56715ff7242bb3724b239eac7d6527e0d6fa50d813567bb8e2cd1f3647bd18f3229878b63beb54cec65fb2832a3a
ep_bytes: 68ac00000068000000006810804100e8
timestamp: 2019-07-30 08:52:50

Version Info:

0: [No Data]

Trojan:Win32/Niktol.RPY!MTB also known as:

BkavW32.AIDetectMalware
Elasticmalicious (high confidence)
MicroWorld-eScanTrojan.Generic.34305635
ClamAVWin.Malware.Agentb-10018199-0
FireEyeGeneric.mg.6556311daf0d7f76
SkyhighBehavesLike.Win32.Generic.nh
MalwarebytesGeneric.Malware.AI.DDS
VIPRETrojan.Generic.34305635
SangforTrojan.Win32.Save.a
K7AntiVirusRiskware ( 00584baa1 )
K7GWRiskware ( 00584baa1 )
CrowdStrikewin/malicious_confidence_90% (D)
VirITTrojan.Win32.Genus.IHW
SymantecML.Attribute.HighConfidence
ESET-NOD32BAT/Agent.QBP
APEXMalicious
CynetMalicious (score: 100)
KasperskyHEUR:Trojan.BAT.Agentb.gen
BitDefenderTrojan.Generic.34305635
AvastWin32:Evo-gen [Trj]
TencentTrojan.BAT.Agentb.hc
SophosGeneric ML PUA (PUA)
F-SecureTrojan.TR/Redcap.pmhod
ZillyaTool.Lazagne.Win32.102
EmsisoftTrojan.Generic.34305635 (B)
SentinelOneStatic AI – Malicious PE
WebrootW32.Trojan.Gen
GoogleDetected
AviraTR/Redcap.pmhod
Antiy-AVLTrojan/Win32.Tiggre
MicrosoftTrojan:Win32/Niktol.RPY!MTB
ArcabitTrojan.Generic.D20B7663
ZoneAlarmHEUR:Trojan.BAT.Agentb.gen
GDataWin32.Trojan.PSE.1I3XF62
VaristW32/Trojan.VFBA-8001
AhnLab-V3Malware/Win.Generic.C5253524
ALYacTrojan.Generic.34305635
MAXmalware (ai score=89)
VBA32Trojan.BAT.Agentb
Cylanceunsafe
ZonerTrojan.Win32.85523
RisingTrojan.Generic@AI.89 (RDML:xmJapJLUqP8d8+d7xHW6LA)
YandexTrojan.Agent!I4Q/548sWx4
IkarusTrojan.Win32.Agent
MaxSecureTrojan.Malware.300983.susgen
FortinetW32/VFBA.8001!tr
AVGWin32:Evo-gen [Trj]
Cybereasonmalicious.c31c12
DeepInstinctMALICIOUS

How to remove Trojan:Win32/Niktol.RPY!MTB?

Trojan:Win32/Niktol.RPY!MTB removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment