Severity scale:  
  (96/100)

Napoleon ransomware. How to remove? (Uninstall guide)

removal by Olivia Morelli - - | Type: Ransomware
12

Napoleon ransomware performs data encryption to obtain illegal profits

Napoleon ransomware image

Napoleon is a file-encrypting virus which encodes data and makes it inaccessible to the user[1]. After encryption, it appends .[supp01@airmail.cc].napoleon extension at the end of the file-name and provides the data recovery instructions in How_Decrypt_Files.hta file. 

The ransom note of Napoleon virus states the following:

If you want to restore files, write us to the e-mail: supp01@airmail.cc In subject line write encryption and attach your ID in body of your message also attach to email 3 crypted files. (files have to be less than 2 MB).

It is clear that the criminals want to look trustworthy. Likewise, they offer a free decryption of 3 files which are less than 2 MB. Additionally, they urge to contact them within a week, or they will delete Napoleon decrypter which is necessary in order to recover the corrupted data. 

Besides, the developers of Napoleon indicate an alternative supportdecrypt2@cock.li email address in case they do not respond within 48 hours. At the moment, there is no reliable information about the amount of money which is demanded to purchase the decryption key.

However, we do not recommend contacting the criminals in either way. Note that not only you might not receive a decryptor after you make a transaction but also get malspam emails to infiltrate other high-risk computer infections[2]. Therefore, you should remove Napoleon ransomware and try alternative recovery methods. This way you will preserve your system from any further damage.

Likewise, pick Reimage and let it scan your computer thoroughly. After several minutes, the termination of crypto-malware will be finished, and you will be able to proceed to the decryption steps which are provided below. If you don't know how to start Napoleon removal, scroll down to find the elimination guide. 

Distribution techniques

Cybercriminals employ several distribution methods to make sure that their malicious program reaches as many computers as possible. Currently, most of the ransomware spreads via fake software updates or spam emails. These techniques are highly advantageous since they are based on the delusional appearance — both emails and updates imitate legitimate companies, brands or their products. 

Usually, malspam campaigns are created in a way to trick inexperienced computer user into opening the malicious attachment in the email. For example, it might look like a legitimate invoice from DHL, UPS or other well-known companies. As a result, the user opens the false document which starts an automatic download of the ransomware.

Moreover, fake software updates employ the same technique — they disguise under the appearance of widely used programs, such as Adobe Flash or VLC Media Player. Typically, you can encounter the fraudulent upgrades on highly suspicious websites appearing as a pop-up. The message might tell you that your access to particular media content is limited and you can fix it by downloading the software update. 

At this point, we want to assure you that neither you should open emails from unknown senders nor install any updates offered elsewhere than in the official websites. These ransomware distribution techniques are based on the reckless behavior of gullible people. Therefore, you should carefully monitor your browsing activity and avoid any questionable content online.

Napoleon virus removal guide

It doesn't matter whether you have already been infected or not. Experts from NoVirus.uk[3] suggest you using a powerful security software all the time. It will not only help you to remove Napoleon from your system but protect from ransomware attack in the future as well. Note that this type of a virus is highly dangerous and trying to remove it by yourself might cause even more damage.

Therefore, you can complete Napoleon removal with a few simple steps:

  1. Download Reimage, Plumbytes Anti-MalwareWebroot SecureAnywhere AntiVirus or Malwarebytes Anti Malware;
  2. Let one of these antivirus programs to scan your files thoroughly;
  3. After it finishes ransomware elimination, proceed to the guide below and recover your files.

We might be affiliated with any product we recommend on the site. Full disclosure in our Agreement of Use. By Downloading any provided Anti-spyware software to remove Napoleon ransomware you agree to our privacy policy and agreement of use.
do it now!
Download
Reimage (remover) Happiness
Guarantee
Download
Reimage (remover) Happiness
Guarantee
Compatible with Microsoft Windows Compatible with OS X
What to do if failed?
If you failed to remove infection using Reimage, submit a question to our support team and provide as much details as possible.
Reimage is recommended to uninstall Napoleon ransomware. Free scanner allows you to check whether your PC is infected or not. If you need to remove malware, you have to purchase the licensed version of Reimage malware removal tool.
More information about this program can be found in Reimage review.
Press mentions on Reimage

Manual Napoleon virus Removal Guide:

Remove Napoleon using Safe Mode with Networking

You should start Napoleon removal by rebooting your PC to Safe Mode:

  • Step 1: Reboot your computer to Safe Mode with Networking

    Windows 7 / Vista / XP
    1. Click Start Shutdown Restart OK.
    2. When your computer becomes active, start pressing F8 multiple times until you see the Advanced Boot Options window.
    3. Select Safe Mode with Networking from the list Select 'Safe Mode with Networking'

    Windows 10 / Windows 8
    1. Press the Power button at the Windows login screen. Now press and hold Shift, which is on your keyboard, and click Restart..
    2. Now select Troubleshoot Advanced options Startup Settings and finally press Restart.
    3. Once your computer becomes active, select Enable Safe Mode with Networking in Startup Settings window. Select 'Enable Safe Mode with Networking'
  • Step 2: Remove Napoleon

    Log in to your infected account and start the browser. Download Reimage or other legitimate anti-spyware program. Update it before a full system scan and remove malicious files that belong to your ransomware and complete Napoleon removal.

If your ransomware is blocking Safe Mode with Networking, try further method.

Remove Napoleon using System Restore

In case you are still unable to install the security software, try the second method:

  • Step 1: Reboot your computer to Safe Mode with Command Prompt

    Windows 7 / Vista / XP
    1. Click Start Shutdown Restart OK.
    2. When your computer becomes active, start pressing F8 multiple times until you see the Advanced Boot Options window.
    3. Select Command Prompt from the list Select 'Safe Mode with Command Prompt'

    Windows 10 / Windows 8
    1. Press the Power button at the Windows login screen. Now press and hold Shift, which is on your keyboard, and click Restart..
    2. Now select Troubleshoot Advanced options Startup Settings and finally press Restart.
    3. Once your computer becomes active, select Enable Safe Mode with Command Prompt in Startup Settings window. Select 'Enable Safe Mode with Command Prompt'
  • Step 2: Restore your system files and settings
    1. Once the Command Prompt window shows up, enter cd restore and click Enter. Enter 'cd restore' without quotes and press 'Enter'
    2. Now type rstrui.exe and press Enter again.. Enter 'rstrui.exe' without quotes and press 'Enter'
    3. When a new window shows up, click Next and select your restore point that is prior the infiltration of Napoleon. After doing that, click Next. When 'System Restore' window shows up, select 'Next' Select your restore point and click 'Next'
    4. Now click Yes to start system restore. Click 'Yes' and start system restore
    Once you restore your system to a previous date, download and scan your computer with Reimage and make sure that Napoleon removal is performed successfully.

Bonus: Recover your data

Guide which is presented above is supposed to help you remove Napoleon from your computer. To recover your encrypted files, we recommend using a detailed guide prepared by 2-spyware.com security experts.

If your files are encrypted by Napoleon, you can use several methods to restore them:

Use Data Recovery Pro

You can try to retrieve your data with the help of this tool.

Windows Previous Versions feature might restore separate files

If you want to recover data with .napoleon extension, you should check whether the System Restore function was enabled. If it was, follow the instructions below:

  • Find an encrypted file you need to restore and right-click on it;
  • Select “Properties” and go to “Previous versions” tab;
  • Here, check each of available copies of the file in “Folder versions”. You should select the version you want to recover and click “Restore”.

Try ShadowExplorer

This tool is extremely helpful if the ransomware hasn't deleted Shadow Volume Copies from your system.

  • Download Shadow Explorer (http://shadowexplorer.com/);
  • Follow a Shadow Explorer Setup Wizard and install this application on your computer;
  • Launch the program and go through the drop down menu on the top left corner to select the disk of your encrypted data. Check what folders are there;
  • Right-click on the folder you want to restore and select “Export”. You can also select where you want it to be stored.

Currently, there is no official Napoleon Decryptor

Finally, you should always think about the protection of crypto-ransomwares. In order to protect your computer from Napoleon and other ransomwares, use a reputable anti-spyware, such as Reimage, Plumbytes Anti-MalwareWebroot SecureAnywhere AntiVirus or Malwarebytes Anti Malware

About the author

Olivia Morelli
Olivia Morelli - Ransomware analyst

If this free removal guide helped you and you are satisfied with our service, please consider making a donation to keep this service alive. Even a smallest amount will be appreciated.

Contact Olivia Morelli
About the company Esolutions

References