Trojan

Trojan:Win32/Niktol.RPY!MTB removal guide

Malware Removal

The Trojan:Win32/Niktol.RPY!MTB is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Trojan:Win32/Niktol.RPY!MTB virus can do?

  • Sample contains Overlay data
  • Uses Windows utilities for basic functionality
  • The binary contains an unknown PE section name indicative of packing
  • Authenticode signature is invalid
  • Uses Windows utilities to create a scheduled task
  • Deletes executed files from disk

How to determine Trojan:Win32/Niktol.RPY!MTB?


File Info:

name: EEF13D97618D0D5F2124.mlw
path: /opt/CAPEv2/storage/binaries/e16bdd12231d759d86f8ddd7b524b691705d44cead678fa340df802b0cdb9f77
crc32: DF455B90
md5: eef13d97618d0d5f21247d83b7c10712
sha1: 3d3bebf6420440cc6844adec0cf9d8c314efcb2d
sha256: e16bdd12231d759d86f8ddd7b524b691705d44cead678fa340df802b0cdb9f77
sha512: ff699de704ca8bdd6fc574a1fbb0bba4d80ea92b7b3c81e428f13cad7a327f7768540112869905b6dbf56c67063853c8dc3bf3c0064051a0b9a7d7da3c18c7c1
ssdeep: 1536:D7fPGykbOqjoHm4pICdfkLtAfupcWX50MxFY+yIOlnToIfzxy4Oz:fq6+ouCpk2mpcWJ0r+QNTBfzq
type: PE32 executable (GUI) Intel 80386, for MS Windows
tlsh: T10EA35B05B3E142FAC5E2043201BA513F9776A5288724ADE7C74C3C879653E998A7E3F9
sha3_384: 414c205c2a5384b6240fe813e0e828a0d7d6263d1ba083be17c863e582f42cebe32fbddac0158cdc00d0293e8b34def4
ep_bytes: 68ac00000068000000006810804100e8
timestamp: 2019-07-30 08:52:50

Version Info:

0: [No Data]

Trojan:Win32/Niktol.RPY!MTB also known as:

BkavW32.AIDetectMalware
LionicTrojan.Win32.Tiny.trFe
AVGWin32:Evo-gen [Trj]
MicroWorld-eScanTrojan.Generic.34305635
FireEyeGeneric.mg.eef13d97618d0d5f
SkyhighBehavesLike.Win32.Generic.nh
McAfeeArtemis!EEF13D97618D
MalwarebytesGeneric.Malware.AI.DDS
VIPRETrojan.Generic.34305635
SangforTrojan.Win32.Save.a
K7AntiVirusRiskware ( 00584baa1 )
AlibabaTrojan:Win32/Niktol.3a4623b0
K7GWRiskware ( 00584baa1 )
CrowdStrikewin/malicious_confidence_90% (D)
VirITTrojan.Win32.Genus.IHW
SymantecML.Attribute.HighConfidence
Elasticmalicious (high confidence)
ESET-NOD32BAT/Agent.QBP
CynetMalicious (score: 100)
APEXMalicious
ClamAVWin.Malware.Agentb-10018199-0
KasperskyHEUR:Trojan.BAT.Agentb.gen
BitDefenderTrojan.Generic.34305635
AvastWin32:Evo-gen [Trj]
EmsisoftTrojan.Generic.34305635 (B)
ZillyaTool.Lazagne.Win32.102
SophosMal/Generic-S
IkarusTrojan.Win32.Agent
WebrootW32.Trojan.Gen
AviraTR/Redcap.pmhod
Antiy-AVLTrojan/Win32.Tiggre
MicrosoftTrojan:Win32/Niktol.RPY!MTB
ArcabitTrojan.Generic.D20B7663
ZoneAlarmHEUR:Trojan.BAT.Agentb.gen
GDataWin32.Trojan.PSE.1I3XF62
GoogleDetected
AhnLab-V3Malware/Win.Generic.C5253524
VBA32Trojan.BAT.Agentb
ALYacTrojan.Generic.34305635
MAXmalware (ai score=82)
Cylanceunsafe
TencentTrojan.BAT.Agentb.hc
YandexTrojan.Agent!I4Q/548sWx4
SentinelOneStatic AI – Malicious PE
MaxSecureTrojan.Malware.300983.susgen
FortinetW32/Agent.EDI!tr
ZonerTrojan.Win32.85523
Cybereasonmalicious.7618d0
DeepInstinctMALICIOUS

How to remove Trojan:Win32/Niktol.RPY!MTB?

Trojan:Win32/Niktol.RPY!MTB removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment