credwiz.exe

  • File Path: C:\windows\SysWOW64\credwiz.exe
  • Description: Credential Backup and Restore Wizard

Screenshot

credwiz.exe

Hashes

Type Hash
MD5 B6BC8EB212990545DF8CE8CB1BD20B82
SHA1 7567FF48C7071FE759EF6CB23E98754549C76DA4
SHA256 9932324E1CDFC4BC88D5BC908B90AE7E032CE999C46091F97E6784FAAF8AC97F
SHA384 E8CB4CB37B000BC8BEA729ABCDBE3D13684AEE40C9880B49D96182712ED18B39BB67D4003E0B99A12562C4AC91AE678E
SHA512 6D6541576D7299310ACA05BAB0BD59F6515B7EA746D2A4E607FA7807B3F1FA7EC1AD99E1475EFCCFE4A9E227B6F388BBA48BE889ABF80DCE05315CC76E1DB35F
SSDEEP 384:AFBrFGSB17fI0yr1lkbJArmQgGooIYi7z/LUG4qKZXpeO6tZUMb3KEjWv5WiNusZ:kJ1C1jrDlbIYicnepoM+EgU

Signature

  • Status: The file C:\windows\SysWOW64\credwiz.exe is not digitally signed. You cannot run this script on the current system. For more information about running scripts and setting execution policy, see about_Execution_Policies at http://go.microsoft.com/fwlink/?LinkID=135170
  • Serial: ``
  • Thumbprint: ``
  • Issuer:
  • Subject:

File Metadata

  • Original Filename: credwiz.exe.mui
  • Product Name: Microsoft Windows Operating System
  • Company Name: Microsoft Corporation
  • File Version: 6.3.9600.16384 (winblue_rtm.130821-1623)
  • Product Version: 6.3.9600.16384
  • Language: English (United States)
  • Legal Copyright: Microsoft Corporation. All rights reserved.

Possible Misuse

The following table contains possible examples of credwiz.exe being misused. While credwiz.exe is not inherently malicious, its legitimate functionality can be abused for malicious purposes.

Source Source File Example License
malware-ioc badiis.yar $s8 = "C:\\Windows\\System32\\credwiz.exe" ascii wide © ESET 2014-2018

MIT License. Copyright (c) 2020-2021 Strontic.