xwizards.dll

  • File Path: C:\Windows\SysWOW64\xwizards.dll
  • Description: Extensible Wizards Manager Module

Hashes

Type Hash
MD5 176C52C5815229248005CD7C2ED2FCB9
SHA1 926F8AACE9DDC9640BD539EFCC27308BA7A29BE0
SHA256 46C0107D294DC104DCE10FE5B151730128D123F67C911D4CAA58CE7B76943D2E
SHA384 A817ACDF8BA5E1D5B6A00C842EF832325EF7A7E53D6034244541E50E44D5891DCA19E9669F119310BF2D20C793EC68A3
SHA512 2C32CC7C8D8DCFA5A19B4CB0AE82E007B3288394E44AEF3302671385059CED80D1450334C74BFE5FEF1AD253C73B81F2B695EDE94727A59340F03666C8D7DB93
SSDEEP 6144:ZuZVA1XindiQwBhm9DJYmNpakAtLnD68wlaW:ZuZuZUlwBY9y4AdD68wV
IMP 21F96BD1B2FFF2C409E65B451E4817DD
PESHA1 1F80C5AE406DA040654C8324051A6EA7BC83A17E
PE256 3CEAC274F62C965682896C24D615088EF481F79267FC04B925A2C1F91ABEBAB3

DLL Exports:

Function Name Ordinal Type
XWRegisterTaskWithHost 15 Exported Function
XWUnregisterHost 16 Exported Function
XWRegisterPageWithTask 14 Exported Function
XWRegisterHost 12 Exported Function
XWRegisterPageWithPage 13 Exported Function
XWUnregisterTask 20 Exported Function
XWUnregisterTaskPageLink 21 Exported Function
XWUnregisterPagesLink 19 Exported Function
XWUnregisterHostTaskLink 17 Exported Function
XWUnregisterPage 18 Exported Function
XWProcessXMLFile 11 Exported Function
ProcessXMLFileW 4 Exported Function
ResetRegistrationA 5 Exported Function
ProcessXMLFileA 3 Exported Function
DllCanUnloadNow 1 Exported Function
DllGetClassObject 2 Exported Function
RunWizardA 9 Exported Function
RunWizardW 10 Exported Function
RunPropertySheetW 8 Exported Function
ResetRegistrationW 6 Exported Function
RunPropertySheetA 7 Exported Function

Signature

  • Status: Signature verified.
  • Serial: 3300000266BD1580EFA75CD6D3000000000266
  • Thumbprint: A4341B9FD50FB9964283220A36A1EF6F6FAA7840
  • Issuer: CN=Microsoft Windows Production PCA 2011, O=Microsoft Corporation, L=Redmond, S=Washington, C=US
  • Subject: CN=Microsoft Windows, O=Microsoft Corporation, L=Redmond, S=Washington, C=US

File Metadata

  • Original Filename: xwizards.dll.mui
  • Product Name: Microsoft Windows Operating System
  • Company Name: Microsoft Corporation
  • File Version: 10.0.19041.1 (WinBuild.160101.0800)
  • Product Version: 10.0.19041.1
  • Language: English (United States)
  • Legal Copyright: Microsoft Corporation. All rights reserved.
  • Machine Type: 32-bit

File Scan

  • VirusTotal Detections: 0/70
  • VirusTotal Link: https://www.virustotal.com/gui/file/46c0107d294dc104dce10fe5b151730128d123f67c911d4caa58ce7b76943d2e/detection/

Possible Misuse

The following table contains possible examples of xwizards.dll being misused. While xwizards.dll is not inherently malicious, its legitimate functionality can be abused for malicious purposes.

Source Source File Example License
sigma proc_creation_win_dll_sideload_xwizard.yml description: Detects the execution of Xwizard tool from the non-default directory which can be used to sideload a custom xwizards.dll DRL 1.0

MIT License. Copyright (c) 2020-2021 Strontic.