Trojan

Should I remove “Trojan:Win32/Niktol.RPY!MTB”?

Malware Removal

The Trojan:Win32/Niktol.RPY!MTB is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Trojan:Win32/Niktol.RPY!MTB virus can do?

  • Sample contains Overlay data
  • Uses Windows utilities for basic functionality
  • The binary contains an unknown PE section name indicative of packing
  • Authenticode signature is invalid
  • Uses Windows utilities to create a scheduled task
  • Deletes executed files from disk

How to determine Trojan:Win32/Niktol.RPY!MTB?


File Info:

name: 90F6293936EC8D7A911D.mlw
path: /opt/CAPEv2/storage/binaries/bfee47809a08a2d39eb7b47a21823613205a2d648ea5b851812e50e357828936
crc32: 2D3035F9
md5: 90f6293936ec8d7a911d1f393ff04fa5
sha1: f8776642f11742a3e03d61fc40ca3a7d12f8f709
sha256: bfee47809a08a2d39eb7b47a21823613205a2d648ea5b851812e50e357828936
sha512: 4b98155ef977953295987fdc6e750b5f98405e74ee5cdbbac955c571688d2afae8591e1bd5a849d21768047aa569e7e644821e3a66622b0bfb0b8d5632f9c172
ssdeep: 1536:D7fPGykbOqjoHm4pICdfkLtAfupcWX50MxFY+yIOlnToIfzxy4Oy:fq6+ouCpk2mpcWJ0r+QNTBfzd
type: PE32 executable (GUI) Intel 80386, for MS Windows
tlsh: T1FAA36C05B3E142FAC5E2043201BA613F9776A5288714ADE7C34C3C879653ED99A7E3F9
sha3_384: aff220a3df3200700a491c334d010dd31790f64bc477c85f6efb24bed77b88ef593caa1b5b7f476d09ff7a9de5b09169
ep_bytes: 68ac00000068000000006810804100e8
timestamp: 2019-07-30 08:52:50

Version Info:

0: [No Data]

Trojan:Win32/Niktol.RPY!MTB also known as:

BkavW32.AIDetectMalware
LionicTrojan.Win32.Tiny.trFe
Elasticmalicious (high confidence)
MicroWorld-eScanTrojan.Generic.34305635
ClamAVWin.Malware.Agentb-10018199-0
FireEyeGeneric.mg.90f6293936ec8d7a
SkyhighBehavesLike.Win32.Generic.nh
Cylanceunsafe
ZillyaTool.Lazagne.Win32.102
SangforTrojan.Win32.Save.a
K7AntiVirusRiskware ( 00584baa1 )
AlibabaTrojan:Win32/Niktol.3a4623b0
K7GWRiskware ( 00584baa1 )
Cybereasonmalicious.2f1174
VirITTrojan.Win32.Genus.IHW
SymantecML.Attribute.HighConfidence
ESET-NOD32BAT/Agent.QBP
ZonerTrojan.Win32.85523
APEXMalicious
CynetMalicious (score: 100)
KasperskyHEUR:Trojan.BAT.Agentb.gen
BitDefenderTrojan.Generic.34305635
AvastWin32:Evo-gen [Trj]
TencentTrojan.BAT.Agentb.hc
SophosMal/Generic-S
F-SecureTrojan.TR/Redcap.pmhod
VIPRETrojan.Generic.34305635
EmsisoftTrojan.Generic.34305635 (B)
IkarusTrojan.Win32.Agent
GDataWin32.Trojan.PSE.1I3XF62
WebrootW32.Trojan.Gen
GoogleDetected
AviraTR/Redcap.pmhod
Antiy-AVLTrojan/Win32.Tiggre
ArcabitTrojan.Generic.D20B7663
ZoneAlarmHEUR:Trojan.BAT.Agentb.gen
MicrosoftTrojan:Win32/Niktol.RPY!MTB
VaristW32/Trojan.VFBA-8001
AhnLab-V3Malware/Win.Generic.C5253524
ALYacTrojan.Generic.34305635
MAXmalware (ai score=80)
VBA32Trojan.BAT.Agentb
MalwarebytesGeneric.Malware.AI.DDS
RisingTrojan.Generic@AI.100 (RDML:xmJapJLUqP8d8+d7xHW6LA)
YandexTrojan.Agent!I4Q/548sWx4
SentinelOneStatic AI – Malicious PE
MaxSecureTrojan.Malware.300983.susgen
FortinetW32/Agent.EDI!tr
AVGWin32:Evo-gen [Trj]
DeepInstinctMALICIOUS
CrowdStrikewin/malicious_confidence_90% (D)

How to remove Trojan:Win32/Niktol.RPY!MTB?

Trojan:Win32/Niktol.RPY!MTB removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment