xwizards.dll

  • File Path: C:\Windows\system32\xwizards.dll
  • Description: Extensible Wizards Manager Module

Hashes

Type Hash
MD5 7A83D27177A5A49F2871C679C081F76F
SHA1 946C711FA5FA3717769D80C05DA791FA092901A9
SHA256 219498C3C4A1B2A34CFB5F859533475D6BE220A36B7965ED18F543122DFE2A2C
SHA384 176C4AD06975B48DD9D47770FEA32BC64D6A44536D07E103CC0D3276ADCCDCABBFE3565739BB7872B28391F5D34C47BE
SHA512 BC624E765C22D881C8B44E7062DD8B6DD848DC3158EA7E32D417B3C63362571B7F32F9B334935F4FBF82D54864154670A99595CA031311596A24F4D98E1E8EAC
SSDEEP 6144:ovbaIvp4IX9Ad6m9JXuDObE2zD5C5p480sA5dz6AzrD68w:ovbVXwJE052FAbZD68w
IMP D2FD36B82D61DD393D51258CDF3AE863
PESHA1 094E0C8FE38A0043AC193A6EDE3753C3C45903F4
PE256 844D6EDE0D68BF6241AC2C6A8477C709D479E2DBB86D3CBB1AAC985465583216

DLL Exports:

Function Name Ordinal Type
XWRegisterTaskWithHost 15 Exported Function
XWUnregisterHost 16 Exported Function
XWRegisterPageWithTask 14 Exported Function
XWRegisterHost 12 Exported Function
XWRegisterPageWithPage 13 Exported Function
XWUnregisterTask 20 Exported Function
XWUnregisterTaskPageLink 21 Exported Function
XWUnregisterPagesLink 19 Exported Function
XWUnregisterHostTaskLink 17 Exported Function
XWUnregisterPage 18 Exported Function
XWProcessXMLFile 11 Exported Function
ProcessXMLFileW 4 Exported Function
ResetRegistrationA 5 Exported Function
ProcessXMLFileA 3 Exported Function
DllCanUnloadNow 1 Exported Function
DllGetClassObject 2 Exported Function
RunWizardA 9 Exported Function
RunWizardW 10 Exported Function
RunPropertySheetW 8 Exported Function
ResetRegistrationW 6 Exported Function
RunPropertySheetA 7 Exported Function

Signature

  • Status: Signature verified.
  • Serial: 3300000266BD1580EFA75CD6D3000000000266
  • Thumbprint: A4341B9FD50FB9964283220A36A1EF6F6FAA7840
  • Issuer: CN=Microsoft Windows Production PCA 2011, O=Microsoft Corporation, L=Redmond, S=Washington, C=US
  • Subject: CN=Microsoft Windows, O=Microsoft Corporation, L=Redmond, S=Washington, C=US

File Metadata

  • Original Filename: xwizards.dll.mui
  • Product Name: Microsoft Windows Operating System
  • Company Name: Microsoft Corporation
  • File Version: 10.0.19041.1 (WinBuild.160101.0800)
  • Product Version: 10.0.19041.1
  • Language: English (United States)
  • Legal Copyright: Microsoft Corporation. All rights reserved.
  • Machine Type: 64-bit

File Scan

  • VirusTotal Detections: 0/71
  • VirusTotal Link: https://www.virustotal.com/gui/file/219498c3c4a1b2a34cfb5f859533475d6be220a36b7965ed18f543122dfe2a2c/detection/

Possible Misuse

The following table contains possible examples of xwizards.dll being misused. While xwizards.dll is not inherently malicious, its legitimate functionality can be abused for malicious purposes.

Source Source File Example License
sigma proc_creation_win_dll_sideload_xwizard.yml description: Detects the execution of Xwizard tool from the non-default directory which can be used to sideload a custom xwizards.dll DRL 1.0

MIT License. Copyright (c) 2020-2021 Strontic.