Trojan

Should I remove “Trojan:Win32/Niktol.RPY!MTB”?

Malware Removal

The Trojan:Win32/Niktol.RPY!MTB is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Trojan:Win32/Niktol.RPY!MTB virus can do?

  • Sample contains Overlay data
  • The binary contains an unknown PE section name indicative of packing
  • Authenticode signature is invalid
  • Uses Windows utilities to create a scheduled task
  • Attempts to repeatedly call a single API many times in order to delay analysis time
  • Deletes executed files from disk

How to determine Trojan:Win32/Niktol.RPY!MTB?


File Info:

name: 58CBB94CC9DC6C71B046.mlw
path: /opt/CAPEv2/storage/binaries/5139e688e67a9f10ba6c76a329ca610c4d1997edbe297a272a64ab3f4d432cf7
crc32: 6386040E
md5: 58cbb94cc9dc6c71b0467093d3f670d0
sha1: 1b027d9ad0c81f876e264e55152acc8e8b8f5c16
sha256: 5139e688e67a9f10ba6c76a329ca610c4d1997edbe297a272a64ab3f4d432cf7
sha512: be2d8e1ffc099ac2280ae7a878303653a2f1c4977f2ab51c40d680e3eae7fee9c8df61d284f7a03028d2e28e3e233ab54f17569e43f0278231d745348c16d910
ssdeep: 1536:j7fbN3eEDhDPA/pICdUkbBtW7upvaLU0bI5taxKo0IOlnToIfSw77OF:/7DhdC6kzWypvaQ0FxyNTBfSD
type: PE32 executable (console) Intel 80386, for MS Windows
tlsh: T1AD935C01F3E142F7E6E2053201BA613F9736A2288764ADE7C74C3D929513ED5963E3E9
sha3_384: fb55a139893ad31a5928a023609844d48e47b46b5a7f9d4d4476f08e6fdbd60e6e637472b4b3482003348515e5475df8
ep_bytes: 68ac00000068000000006868804100e8
timestamp: 2019-07-30 08:52:45

Version Info:

0: [No Data]

Trojan:Win32/Niktol.RPY!MTB also known as:

BkavW32.AIDetectMalware
MicroWorld-eScanTrojan.GenericKD.69911469
FireEyeGeneric.mg.58cbb94cc9dc6c71
CAT-QuickHealTrojan.GenericPMF.S15043657
SkyhighBehavesLike.Win32.RealProtect.nh
MalwarebytesMalware.AI.2013693079
VIPRETrojan.GenericKD.69911469
SangforTrojan.Win32.Save.a
K7AntiVirusTrojan ( 0052419b1 )
BitDefenderTrojan.GenericKD.69911469
K7GWTrojan ( 0052419b1 )
Cybereasonmalicious.ad0c81
SymantecML.Attribute.HighConfidence
Elasticmalicious (high confidence)
APEXMalicious
KasperskyHEUR:Trojan.BAT.Agentb.gen
RisingTrojan.Generic@AI.90 (RDMK:X4bzyks/gnzV2d0EUpDIZg)
SophosGeneric ML PUA (PUA)
F-SecureTrojan.TR/Redcap.oxayp
EmsisoftTrojan.GenericKD.69911469 (B)
IkarusTrojan.BAT.Agent
JiangminTrojan.BAT.aww
GoogleDetected
AviraTR/Redcap.oxayp
VaristW32/Agent.EDI.gen!Eldorado
Kingsoftmalware.kb.a.932
MicrosoftTrojan:Win32/Niktol.RPY!MTB
ArcabitTrojan.Generic.D42AC3AD
ZoneAlarmHEUR:Trojan.BAT.Agentb.gen
GDataTrojan.GenericKD.69911469
CynetMalicious (score: 100)
AhnLab-V3Malware/Win.Generic.C5496484
VBA32Trojan.BAT.Agentb
ALYacTrojan.GenericKD.69911469
MAXmalware (ai score=82)
DeepInstinctMALICIOUS
Cylanceunsafe
PandaTrj/Genetic.gen
TencentTrojan.BAT.Agentb.ha
SentinelOneStatic AI – Malicious PE
MaxSecureTrojan.Malware.300983.susgen
FortinetW32/Agent.EDI!tr
AVGWin32:Malware-gen
AvastWin32:Malware-gen
CrowdStrikewin/malicious_confidence_60% (D)

How to remove Trojan:Win32/Niktol.RPY!MTB?

Trojan:Win32/Niktol.RPY!MTB removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment