Trojan

Trojan:Win32/Napolar.A removal guide

Malware Removal

The Trojan:Win32/Napolar.A is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Trojan:Win32/Napolar.A virus can do?

  • Behavioural detection: Executable code extraction – unpacking
  • Reads data out of its own binary image
  • Drops a binary and executes it
  • Authenticode signature is invalid
  • Installs itself for autorun at Windows startup
  • Creates a copy of itself
  • Yara rule detections observed from a process memory dump/dropped files/CAPE

How to determine Trojan:Win32/Napolar.A?


File Info:

name: 73017018F06F8D220BA3.mlw
path: /opt/CAPEv2/storage/binaries/dae487db55808c01296ebf65c09a1c32e4eab45151704434b14764c2dccdd590
crc32: 39A9E527
md5: 73017018f06f8d220ba35e2d28c30a1d
sha1: a645fcb19ea14d7ba355c3103fa5729c255efeba
sha256: dae487db55808c01296ebf65c09a1c32e4eab45151704434b14764c2dccdd590
sha512: fb11df2746bdfcafb6dfeaee5ccea68a22e55fcdbd8f6bd0f8cffa2f8ca6b353e7f54d9391e3f758802905d8f9c51eb69b6961c129769f5fc5519cce1690b22e
ssdeep: 1536:+HxCaqYLXJOfEbvdTvqGORq0H/waHXxoqNFcMeYxoPRr:+Hx8YL02HamwFDoP
type: PE32 executable (GUI) Intel 80386, for MS Windows
tlsh: T13E937C739B0BE1B1F05B2578A2DEC971351FAD346224A984D550FE8039F3FD7A12A60B
sha3_384: 602c9bb30e73c74366fbba807533ad4a4354576c2dfcd49bcf003e1f8c6b5b99dd9cd4acdd9555c59cfcf89275b33afb
ep_bytes: 5589e583ec2ce800000000588945fc90
timestamp: 1970-01-01 00:00:00

Version Info:

0: [No Data]

Trojan:Win32/Napolar.A also known as:

BkavW32.AIDetectMalware
LionicTrojan.Win32.Generic.lNkP
tehtrisGeneric.Malware
DrWebTrojan.Hottrend.355
MicroWorld-eScanTrojan.AutoIT.Injector.AP
ClamAVWin.Trojan.Napolar-9809317-0
FireEyeGeneric.mg.73017018f06f8d22
ALYacTrojan.AutoIT.Injector.AP
MalwarebytesGeneric.Malware.AI.DDS
ZillyaTrojan.Cossta.Win32.8040
SangforSuspicious.Win32.Save.a
K7AntiVirusTrojan ( 0040f6b31 )
AlibabaTrojan:Win32/Napolar.be5fb596
K7GWTrojan ( 0040f6b31 )
Cybereasonmalicious.19ea14
ArcabitTrojan.AutoIT.Injector.AP
BitDefenderThetaAI:Packer.A2BE3C361E
VirITTrojan.Win32.Generic.AZBI
CyrenW32/Napolar.A.gen!Eldorado
SymantecInfostealer.Napolar
Elasticmalicious (high confidence)
ESET-NOD32Win32/Napolar.A
APEXMalicious
CynetMalicious (score: 100)
KasperskyHEUR:Trojan.Win32.Generic
BitDefenderTrojan.AutoIT.Injector.AP
NANO-AntivirusTrojan.Win32.Hottrend.fgdqhl
SUPERAntiSpywareTrojan.Agent/Gen-Napolar
AvastWin32:Napolar-D [Trj]
TACHYONTrojan/W32.Cossta.95232.B
EmsisoftTrojan.AutoIT.Injector.AP (B)
F-SecureTrojan:W32/Napolar.A
BaiduWin32.Trojan.Napolar.b
VIPRETrojan.AutoIT.Injector.AP
TrendMicroBKDR_NAPOLAR.SM0
McAfee-GW-EditionBehavesLike.Win32.Generic.nh
Trapminemalicious.high.ml.score
SophosML/PE-A
SentinelOneStatic AI – Suspicious PE
JiangminTrojanDropper.Dapato.nxc
WebrootW32.Trojan.Gen
AviraTR/Crypt.XPACK.Gen
Antiy-AVLTrojan/Win32.Cossta
XcitiumTrojWare.Win32.Kryptik.BLGK@53zl6n
MicrosoftTrojan:Win32/Napolar.A
ViRobotTrojan.Win32.Agent.95232.V
ZoneAlarmHEUR:Trojan.Win32.Generic
GDataWin32.Backdoor.Napolar.B
GoogleDetected
AhnLab-V3Trojan/Win32.Cossta.C211827
Acronissuspicious
McAfeeGenericRXDB-VH!73017018F06F
MAXmalware (ai score=100)
VBA32BScope.Trojan.Hottrend
Cylanceunsafe
PandaTrj/Napolar.A
TrendMicro-HouseCallBKDR_NAPOLAR.SM0
RisingTrojan.Napolar!1.AAB2 (CLASSIC)
YandexTrojan.Agent!kkwKOGErytc
IkarusTrojan.Win32.Napolar
MaxSecureTrojan.Malware.300983.susgen
FortinetW32/Cossta.A!tr
AVGWin32:Napolar-D [Trj]
DeepInstinctMALICIOUS
CrowdStrikewin/malicious_confidence_100% (W)

How to remove Trojan:Win32/Napolar.A?

Trojan:Win32/Napolar.A removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment