Malware

What is “Win32/Cozer.D”?

Malware Removal

The Win32/Cozer.D is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Win32/Cozer.D virus can do?

  • Injection (inter-process)
  • Injection (Process Hollowing)
  • Creates RWX memory
  • The binary likely contains encrypted or compressed data.
  • Executed a process and injected code into it, probably while unpacking
  • Network activity detected but not expressed in API logs
  • Anomalous binary characteristics

How to determine Win32/Cozer.D?


File Info:

crc32: 5395E90B
md5: 08f13dad9a2b986aea6f1f903f848895
name: 08F13DAD9A2B986AEA6F1F903F848895.mlw
sha1: 6bba2f6d1d84db9078c71c0f3927e600d6e12c32
sha256: b7a0223ab7a4793928f07a591d2ab715f0b75669770f09fe85681773dc170c55
sha512: 3743786761008d75d4fcbcc2e4ea20434a2afbc1564144574a5d22250431b063b5b3f3e771da0da57c432a135b5d7a330dae1955c45d7d438e7b9cdf5f3493d7
ssdeep: 12288:Jqu6NFlNKJAPLKlp+LEBQn0TH9mbjzKvWYItSq3ZsGN8:JUNKJ88pwaQ0T8LKvWYEv3bN8
type: PE32 executable (console) Intel 80386, for MS Windows

Version Info:

0: [No Data]

Win32/Cozer.D also known as:

K7AntiVirusTrojan ( 0053caf01 )
Elasticmalicious (high confidence)
DrWebBackDoor.CozyDuke.42
CynetMalicious (score: 100)
ALYacTrojan.GenericKD.38017939
CylanceUnsafe
CrowdStrikewin/malicious_confidence_60% (W)
AlibabaTrojan:Win32/CozyDuke.b80b3407
K7GWTrojan ( 0053caf01 )
Cybereasonmalicious.d1d84d
SymantecML.Attribute.HighConfidence
ESET-NOD32a variant of Win32/Cozer.D
APEXMalicious
AvastWin32:CozyDuke-F [Cryp]
ClamAVWin.Dropper.Cozybear-3
KasperskyHEUR:Trojan.Win32.CozyDuke.gen
BitDefenderTrojan.GenericKD.38017939
MicroWorld-eScanTrojan.GenericKD.38017939
TencentWin32.Trojan.Midie.Isn
Ad-AwareTrojan.GenericKD.38017939
SophosMal/Generic-R
BitDefenderThetaGen:NN.ZexaF.34266.PuW@aipi@Tai
TrendMicroTROJ_GEN.R002C0RKD21
McAfee-GW-EditionBehavesLike.Win32.Generic.jc
FireEyeGeneric.mg.08f13dad9a2b986a
EmsisoftTrojan.GenericKD.38017939 (B)
SentinelOneStatic AI – Malicious PE
AviraTR/Dropper.Gen
eGambitUnsafe.AI_Score_100%
Antiy-AVLTrojan/Generic.ASMalwS.34CDCD1
MicrosoftTrojan:Win32/Wacatac.B!ml
GDataTrojan.GenericKD.38017939
AhnLab-V3Trojan/Win.Malware-gen.R450089
Acronissuspicious
McAfeeGenericRXAA-AA!08F13DAD9A2B
MAXmalware (ai score=83)
VBA32Malware-Cryptor.Inject.gen
MalwarebytesMalware.AI.1627101304
PandaTrj/GdSda.A
TrendMicro-HouseCallTROJ_GEN.R002C0RKD21
RisingTrojan.Generic@ML.94 (RDML:CiGds4/wWQFdZ6CA2JNTqg)
YandexTrojan.CozyDuke!jydiWfzbkMA
IkarusTrojan.Win32.Cozer
FortinetW32/Cozer.D!tr
AVGWin32:CozyDuke-F [Cryp]

How to remove Win32/Cozer.D?

Win32/Cozer.D removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment