[{"data":1,"prerenderedAt":-1},["ShallowReactive",2],{"$fZiNOQjOJB_80UjJV9NZp1-o-j6bX3LBymo2drk1J-Vs":3},{"id":4,"question":5,"answer":6,"answerHtml":7,"slug":8,"keywords":9,"article":10,"status":34,"aiModel":39,"aiConfidence":39,"updatedAt":51,"createdAt":51,"_status":50},1202,"Which parameters are required when running xwizard.exe to trigger the loading of xwizards.dll?","The key parameter is `processXMLFile` followed by a filename (e.g., `xwizard processXMLFile 1.txt`). Other supported parameters include `RunWizard` and `RunPropertySheet`, which require a properly formatted GUID. If the GUID length is incorrect, an error dialog appears. The `processXMLFile` parameter is the easiest to use for DLL hijacking, as demonstrated in [Use xwizard.exe to load dll](\u002Fnews\u002Fuse-xwizard-exe-to-load-dll).","\u003Cp>The key parameter is `processXMLFile` followed by a filename (e.g., `xwizard processXMLFile 1.txt`). Other supported parameters include `RunWizard` and `RunPropertySheet`, which require a properly formatted GUID. If the GUID length is incorrect, an error dialog appears. The `processXMLFile` parameter is the easiest to use for DLL hijacking, as demonstrated in [Use xwizard.exe to load dll](\u002Fnews\u002Fuse-xwizard-exe-to-load-dll).\u003C\u002Fp>\u003Cp>\u003Ca href=\"\u002Fnews\u002Fuse-xwizard-exe-to-load-dll\">Read the related One Day Sec article\u003C\u002Fa>\u003C\u002Fp>","which-parameters-are-required-when-running-xwizardexe-to-trigger-the-loading-of--1777480087970","xwizard.exe parameters, processXMLFile, RunWizard, RunPropertySheet, GUID",{"id":11,"title":12,"slug":13,"description":14,"content":15,"contentHtml":30,"cover":31,"author":32,"views":19,"readingTime":33,"status":34,"publishedAt":35,"seo":36,"tags":41,"qaPairs":42,"meta":47,"updatedAt":48,"createdAt":49,"_status":50},291,"Use xwizard.exe to load dll","use-xwizard-exe-to-load-dll","Learn how to use xwizard.exe, a Microsoft-signed binary, to load custom DLLs and bypass application whitelist restrictions. Step-by-step guide with practical testing on Win7 x86.",{"root":16},{"type":17,"format":18,"indent":19,"version":20,"children":21,"direction":29},"root","",0,1,[22],{"type":23,"format":18,"indent":19,"version":20,"children":24,"direction":29},"paragraph",[25],{"mode":26,"text":27,"type":28,"style":18,"detail":19,"format":19,"version":20},"normal","\u003Chtml>\u003Chead>\u003C\u002Fhead>\u003Cbody>\u003Ch2>0x00 Preface\u003C\u002Fh2>\u003Cp>---\u003C\u002Fp>\u003Cp>A previous article introduced the technique of loading DLLs using Excel.Application object's RegisterXLL(). This article continues by introducing a more universal method recently learned—using xwizard.exe to load DLLs.\u003C\u002Fp>\u003Cp>The most notable feature of this method is that xwizard.exe comes with Microsoft's signature, which to some extent can bypass application whitelist blocking.\u003C\u002Fp>\u003Cp>Reference link:\u003C\u002Fp>\u003Cp>http:\u002F\u002Fwww.hexacorn.com\u002Fblog\u002F2017\u002F07\u002F31\u002Fthe-wizard-of-x-oppa-plugx-style\u002F\u003C\u002Fp>\u003Ch2>0x01 Introduction\u003C\u002Fh2>\u003Cp>---\u003C\u002Fp>\u003Cp>This article will cover the following:\u003C\u002Fp>\u003Cul>\u003Cli>Introduction to xwizard.exe\u003C\u002Fli>\u003Cli>Exploitation approach\u003C\u002Fli>\u003Cli>Practical testing\u003C\u002Fli>\u003C\u002Ful>\u003Ch2>0x02 Introduction to xwizard.exe\u003C\u002Fh2>\u003Cp>---\u003C\u002Fp>\u003Cp>Should be the abbreviation for Extensible wizard, Chinese translation: Extensible Wizard Host Process, official documentation currently unavailable\u003C\u002Fp>\u003Cul>\u003Cli>Supports Windows 7 and above operating systems\u003C\u002Fli>\u003Cli>Located under %windir%\\system32\\\u003C\u002Fli>\u003C\u002Ful>\u003Cp>Double-click to run, a usage guide pops up, as shown in the figure below\u003C\u002Fp>\u003Cp>\u003Cimg alt=\"Alt text\" src=\"\u002Fuploads\u002Fdocx_image_1770016721377_0_ec3d553a48.jpeg\">\u003C\u002Fp>\u003Cp>Supported parameters are as follows:\u003C\u002Fp>\u003Cul>\u003Cli>xwizard processXMLFile\u003C\u002Fli>\u003Cli>xwizard RunWizard\u003C\u002Fli>\u003Cli>xwizard RunPropertySheet\u003C\u002Fli>\u003C\u002Ful>\u003Cp>\u003Cstrong>Example:\u003C\u002Fstrong>\u003C\u002Fp>\u003Cul>\u003Cli>xwizard processXMLFile 1.txt\u003C\u002Fli>\u003Cli>xwizard RunWizard \u002Fu {11111111-1111-1111-1111-111111111111}\u003C\u002Fli>\u003Cli>xwizard RunPropertySheet \u002Fu {11111111-1111-1111-1111-111111111111}\u003C\u002Fli>\u003C\u002Ful>\u003Cp>\u003Cstrong>Note:\u003C\u002Fstrong>\u003C\u002Fp>\u003Cp>The GUID length in the parameters is fixed; otherwise, an error dialog box will pop up, as shown in the figure below\u003C\u002Fp>\u003Cp>\u003Cimg alt=\"Alt text\" src=\"\u002Fuploads\u002Fdocx_image_1770016727714_1_1f126b9469.jpeg\">\u003C\u002Fp>\u003Ch2>0x03 Exploitation Approach\u003C\u002Fh2>\u003Cp>---\u003C\u002Fp>\u003Cp>This section verifies the approach proposed by Adam@Hexacorn. Article link:\u003C\u002Fp>\u003Cp>http:\u002F\u002Fwww.hexacorn.com\u002Fblog\u002F2017\u002F07\u002F31\u002Fthe-wizard-of-x-oppa-plugx-style\u002F\u003C\u002Fp>\u003Cp>A special file xwizards.dll exists in the same directory as xwizard.exe\u003C\u002Fp>\u003Cp>Using IDA to view the exported functions of xwizards.dll, as shown in the figure below\u003C\u002Fp>\u003Cp>\u003Cimg alt=\"Alt text\" src=\"\u002Fuploads\u002Fdocx_image_1770016732097_2_cf3e6a18ca.jpeg\">\u003C\u002Fp>\u003Cp>We can see that the names of the exported functions in xwizards.dll are very similar to the parameter names supported by xwizard.exe\u003C\u002Fp>\u003Cp>It is speculated that the functionality of xwizard.exe is implemented by calling xwizards.dll\u003C\u002Fp>\u003Cp>Using IDA to reverse engineer xwizard.exe to verify our hypothesis, as shown in the figure below\u003C\u002Fp>\u003Cp>\u003Cimg alt=\"Alt text\" src=\"\u002Fuploads\u002Fdocx_image_1770016736513_3_23467f773c.jpeg\">\u003C\u002Fp>\u003Cp>For the function LoadLibraryEx, since no absolute path for the DLL is specified and a relative path is used, the search order is:\u003C\u002Fp>\u003Col>\u003Cli>The current directory of the process\u003C\u002Fli>\u003Cli>The path set via SetDllDirectory\u003C\u002Fli>\u003Cli>Windows system directory + PATH, i.e., c:\\windows\\system32\u003C\u002Fli>\u003Cli>16-bit system directory, i.e., c:\\windows\\system\u003C\u002Fli>\u003Cli>Windows directory, i.e., c:\\windows\u003C\u002Fli>\u003Cli>Directories listed in the PATH environment variable\u003C\u002Fli>\u003C\u002Fol>\u003Cp>That is to say, if xwizard.exe is copied to another arbitrary directory, and a self-written xwizards.dll is saved in the same directory, then when executing xwizard.exe, the xwizards.dll in the same directory will be called first, and the xwizards.dll under %windir%\\system32\\ will no longer be loaded\u003C\u002Fp>\u003Cp>This achieves loading our own written DLL using xwizard.exe\u003C\u002Fp>\u003Ch2>0x04 Actual Testing\u003C\u002Fh2>\u003Cp>---\u003C\u002Fp>\u003Cp>Test system: Win7 x86\u003C\u002Fp>\u003Ch3>1. Copy xwizard.exe to a new directory C:\\x\u003C\u002Fh3>\u003Ch3>2. Write the DLL\u003C\u002Fh3>\u003Cp>Using VC 6.0, create a new DLL project, and add pop-up code under case DLL_PROCESS_ATTACH\u003C\u002Fp>\u003Cp>The process and optimization methods will not be elaborated here; refer to the article 'Use Office to maintain persistence'\u003C\u002Fp>\u003Cp>Download link for the compiled DLL is as follows:\u003C\u002Fp>\u003Cp>An open-source project\u003C\u002Fp>\u003Cp>A dialog box will pop up after the DLL is successfully loaded\u003C\u002Fp>\u003Ch3>3. Testing\u003C\u002Fh3>\u003Cp>Directly execute xwizard.exe, no help dialog box pops up\u003C\u002Fp>\u003Cp>Use Process Monitor to monitor the system and check if xwizard.exe executes normally\u003C\u002Fp>\u003Cp>As shown in the figure below\u003C\u002Fp>\u003Cp>\u003Cimg alt=\"Alt text\" src=\"\u002Fuploads\u002Fdocx_image_1770016739618_4_c9388d76b1.jpeg\">\u003C\u002Fp>\u003Cp>xwizard.exe executes normally, but does not attempt to load xwizards.dll\u003C\u002Fp>\u003Cp>Test again, execute via command line with the following parameters:\u003C\u002Fp>\u003Cp>xwizard processXMLFile 1.txt\u003C\u002Fp>\u003Cp>Check the Process Monitor output\u003C\u002Fp>\u003Cp>As shown in the figure below\u003C\u002Fp>\u003Cp>\u003Cimg alt=\"Alt text\" src=\"\u002Fuploads\u002Fdocx_image_1770016743389_5_922e23f6cb.jpeg\">\u003C\u002Fp>\u003Cp>xwizard.exe first attempts to load C:\\x\\xwizards.dll, and after failing to load, attempts to load C:\\windows\\system32\\xwizards.dll (again confirming the judgment on DLL loading order)\u003C\u002Fp>\u003Cp>Next, rename msg.dll to xwizards.dll and save it in C:\\x\u003C\u002Fp>\u003Cp>Execute via command line:\u003C\u002Fp>\u003Cp>xwizard processXMLFile 1.txt\u003C\u002Fp>\u003Cp>Successfully loaded C:\\x\\xwizards.dll, dialog box popped up\u003C\u002Fp>\u003Cp>As shown in the figure below\u003C\u002Fp>\u003Cp>\u003Cimg alt=\"Alt text\" src=\"\u002Fuploads\u002Fdocx_image_1770016746437_6_1cd0509bf4.jpeg\">\u003C\u002Fp>\u003Cp>Test successful\u003C\u002Fp>\u003Ch2>0x05 Supplement\u003C\u002Fh2>\u003Cp>---\u003C\u002Fp>\u003Cp>64-bit system:\u003C\u002Fp>\u003Cp>%windir%\\system32\\ corresponds to 64-bit xwizard.exe, can only load 64-bit xwizards.dll\u003C\u002Fp>\u003Cp>Test as shown in the figure below\u003C\u002Fp>\u003Cp>\u003Cimg alt=\"Alt text\" src=\"\u002Fuploads\u002Fdocx_image_1770016748518_7_07b8315aa1.jpeg\">\u003C\u002Fp>\u003Cp>%windir%\\SysWOW64\\ corresponds to 32-bit xwizard.exe, can only load 32-bit xwizards.dll\u003C\u002Fp>\u003Cp>Test as shown in the figure below\u003C\u002Fp>\u003Cp>\u003Cimg alt=\"Alt text\" src=\"\u002Fuploads\u002Fdocx_image_1770016750045_8_d0c86cc0e7.jpeg\">\u003C\u002Fp>\u003Ch2>0x06 Summary\u003C\u002Fh2>\u003Cp>---\u003C\u002Fp>\u003Cp>This article introduces the technique of using xwizard.exe to load DLLs, with the particularity that xwizard.exe contains a Microsoft signature, thus to some extent, it can bypass application whitelist blocking.\u003C\u002Fp>\u003C\u002Fbody>\u003C\u002Fhtml>","text","ltr","\u003Chtml>\u003Chead>\u003C\u002Fhead>\u003Cbody>\u003Ch2>0x00 Preface\u003C\u002Fh2>\u003Cp>---\u003C\u002Fp>\u003Cp>A previous article introduced the technique of loading DLLs using Excel.Application object's RegisterXLL(). This article continues by introducing a more universal method recently learned—using xwizard.exe to load DLLs.\u003C\u002Fp>\u003Cp>The most notable feature of this method is that xwizard.exe comes with Microsoft's signature, which to some extent can bypass application whitelist blocking.\u003C\u002Fp>\u003Cp>Reference link:\u003C\u002Fp>\u003Cp>http:\u002F\u002Fwww.hexacorn.com\u002Fblog\u002F2017\u002F07\u002F31\u002Fthe-wizard-of-x-oppa-plugx-style\u002F\u003C\u002Fp>\u003Ch2>0x01 Introduction\u003C\u002Fh2>\u003Cp>---\u003C\u002Fp>\u003Cp>This article will cover the following:\u003C\u002Fp>\u003Cul>\u003Cli>Introduction to xwizard.exe\u003C\u002Fli>\u003Cli>Exploitation approach\u003C\u002Fli>\u003Cli>Practical testing\u003C\u002Fli>\u003C\u002Ful>\u003Ch2>0x02 Introduction to xwizard.exe\u003C\u002Fh2>\u003Cp>---\u003C\u002Fp>\u003Cp>Should be the abbreviation for Extensible wizard, Chinese translation: Extensible Wizard Host Process, official documentation currently unavailable\u003C\u002Fp>\u003Cul>\u003Cli>Supports Windows 7 and above operating systems\u003C\u002Fli>\u003Cli>Located under %windir%\\system32\\\u003C\u002Fli>\u003C\u002Ful>\u003Cp>Double-click to run, a usage guide pops up, as shown in the figure below\u003C\u002Fp>\u003Cp>\u003Cimg alt=\"Alt text\" src=\"\u002Fapi\u002Fmedia\u002Ffile\u002Fdocx_image_1770016721377_0_ec3d553a48-1.jpeg\">\u003C\u002Fp>\u003Cp>Supported parameters are as follows:\u003C\u002Fp>\u003Cul>\u003Cli>xwizard processXMLFile\u003C\u002Fli>\u003Cli>xwizard RunWizard\u003C\u002Fli>\u003Cli>xwizard RunPropertySheet\u003C\u002Fli>\u003C\u002Ful>\u003Cp>\u003Cstrong>Example:\u003C\u002Fstrong>\u003C\u002Fp>\u003Cul>\u003Cli>xwizard processXMLFile 1.txt\u003C\u002Fli>\u003Cli>xwizard RunWizard \u002Fu {11111111-1111-1111-1111-111111111111}\u003C\u002Fli>\u003Cli>xwizard RunPropertySheet \u002Fu {11111111-1111-1111-1111-111111111111}\u003C\u002Fli>\u003C\u002Ful>\u003Cp>\u003Cstrong>Note:\u003C\u002Fstrong>\u003C\u002Fp>\u003Cp>The GUID length in the parameters is fixed; otherwise, an error dialog box will pop up, as shown in the figure below\u003C\u002Fp>\u003Cp>\u003Cimg alt=\"Alt text\" src=\"\u002Fapi\u002Fmedia\u002Ffile\u002Fdocx_image_1770016727714_1_1f126b9469-1.jpeg\">\u003C\u002Fp>\u003Ch2>0x03 Exploitation Approach\u003C\u002Fh2>\u003Cp>---\u003C\u002Fp>\u003Cp>This section verifies the approach proposed by Adam@Hexacorn. Article link:\u003C\u002Fp>\u003Cp>http:\u002F\u002Fwww.hexacorn.com\u002Fblog\u002F2017\u002F07\u002F31\u002Fthe-wizard-of-x-oppa-plugx-style\u002F\u003C\u002Fp>\u003Cp>A special file xwizards.dll exists in the same directory as xwizard.exe\u003C\u002Fp>\u003Cp>Using IDA to view the exported functions of xwizards.dll, as shown in the figure below\u003C\u002Fp>\u003Cp>\u003Cimg alt=\"Alt text\" src=\"\u002Fapi\u002Fmedia\u002Ffile\u002Fdocx_image_1770016732097_2_cf3e6a18ca-1.jpeg\">\u003C\u002Fp>\u003Cp>We can see that the names of the exported functions in xwizards.dll are very similar to the parameter names supported by xwizard.exe\u003C\u002Fp>\u003Cp>It is speculated that the functionality of xwizard.exe is implemented by calling xwizards.dll\u003C\u002Fp>\u003Cp>Using IDA to reverse engineer xwizard.exe to verify our hypothesis, as shown in the figure below\u003C\u002Fp>\u003Cp>\u003Cimg alt=\"Alt text\" src=\"\u002Fapi\u002Fmedia\u002Ffile\u002Fdocx_image_1770016736513_3_23467f773c-1.jpeg\">\u003C\u002Fp>\u003Cp>For the function LoadLibraryEx, since no absolute path for the DLL is specified and a relative path is used, the search order is:\u003C\u002Fp>\u003Col>\u003Cli>The current directory of the process\u003C\u002Fli>\u003Cli>The path set via SetDllDirectory\u003C\u002Fli>\u003Cli>Windows system directory + PATH, i.e., c:\\windows\\system32\u003C\u002Fli>\u003Cli>16-bit system directory, i.e., c:\\windows\\system\u003C\u002Fli>\u003Cli>Windows directory, i.e., c:\\windows\u003C\u002Fli>\u003Cli>Directories listed in the PATH environment variable\u003C\u002Fli>\u003C\u002Fol>\u003Cp>That is to say, if xwizard.exe is copied to another arbitrary directory, and a self-written xwizards.dll is saved in the same directory, then when executing xwizard.exe, the xwizards.dll in the same directory will be called first, and the xwizards.dll under %windir%\\system32\\ will no longer be loaded\u003C\u002Fp>\u003Cp>This achieves loading our own written DLL using xwizard.exe\u003C\u002Fp>\u003Ch2>0x04 Actual Testing\u003C\u002Fh2>\u003Cp>---\u003C\u002Fp>\u003Cp>Test system: Win7 x86\u003C\u002Fp>\u003Ch3>1. Copy xwizard.exe to a new directory C:\\x\u003C\u002Fh3>\u003Ch3>2. Write the DLL\u003C\u002Fh3>\u003Cp>Using VC 6.0, create a new DLL project, and add pop-up code under case DLL_PROCESS_ATTACH\u003C\u002Fp>\u003Cp>The process and optimization methods will not be elaborated here; refer to the article 'Use Office to maintain persistence'\u003C\u002Fp>\u003Cp>Download link for the compiled DLL is as follows:\u003C\u002Fp>\u003Cp>An open-source project\u003C\u002Fp>\u003Cp>A dialog box will pop up after the DLL is successfully loaded\u003C\u002Fp>\u003Ch3>3. Testing\u003C\u002Fh3>\u003Cp>Directly execute xwizard.exe, no help dialog box pops up\u003C\u002Fp>\u003Cp>Use Process Monitor to monitor the system and check if xwizard.exe executes normally\u003C\u002Fp>\u003Cp>As shown in the figure below\u003C\u002Fp>\u003Cp>\u003Cimg alt=\"Alt text\" src=\"\u002Fapi\u002Fmedia\u002Ffile\u002Fdocx_image_1770016739618_4_c9388d76b1-1.jpeg\">\u003C\u002Fp>\u003Cp>xwizard.exe executes normally, but does not attempt to load xwizards.dll\u003C\u002Fp>\u003Cp>Test again, execute via command line with the following parameters:\u003C\u002Fp>\u003Cp>xwizard processXMLFile 1.txt\u003C\u002Fp>\u003Cp>Check the Process Monitor output\u003C\u002Fp>\u003Cp>As shown in the figure below\u003C\u002Fp>\u003Cp>\u003Cimg alt=\"Alt text\" src=\"\u002Fapi\u002Fmedia\u002Ffile\u002Fdocx_image_1770016743389_5_922e23f6cb-1.jpeg\">\u003C\u002Fp>\u003Cp>xwizard.exe first attempts to load C:\\x\\xwizards.dll, and after failing to load, attempts to load C:\\windows\\system32\\xwizards.dll (again confirming the judgment on DLL loading order)\u003C\u002Fp>\u003Cp>Next, rename msg.dll to xwizards.dll and save it in C:\\x\u003C\u002Fp>\u003Cp>Execute via command line:\u003C\u002Fp>\u003Cp>xwizard processXMLFile 1.txt\u003C\u002Fp>\u003Cp>Successfully loaded C:\\x\\xwizards.dll, dialog box popped up\u003C\u002Fp>\u003Cp>As shown in the figure below\u003C\u002Fp>\u003Cp>\u003Cimg alt=\"Alt text\" src=\"\u002Fapi\u002Fmedia\u002Ffile\u002Fdocx_image_1770016746437_6_1cd0509bf4-1.jpeg\">\u003C\u002Fp>\u003Cp>Test successful\u003C\u002Fp>\u003Ch2>0x05 Supplement\u003C\u002Fh2>\u003Cp>---\u003C\u002Fp>\u003Cp>64-bit system:\u003C\u002Fp>\u003Cp>%windir%\\system32\\ corresponds to 64-bit xwizard.exe, can only load 64-bit xwizards.dll\u003C\u002Fp>\u003Cp>Test as shown in the figure below\u003C\u002Fp>\u003Cp>\u003Cimg alt=\"Alt text\" src=\"\u002Fapi\u002Fmedia\u002Ffile\u002Fdocx_image_1770016748518_7_07b8315aa1-1.jpeg\">\u003C\u002Fp>\u003Cp>%windir%\\SysWOW64\\ corresponds to 32-bit xwizard.exe, can only load 32-bit xwizards.dll\u003C\u002Fp>\u003Cp>Test as shown in the figure below\u003C\u002Fp>\u003Cp>\u003Cimg alt=\"Alt text\" src=\"\u002Fapi\u002Fmedia\u002Ffile\u002Fdocx_image_1770016750045_8_d0c86cc0e7-1.jpeg\">\u003C\u002Fp>\u003Ch2>0x06 Summary\u003C\u002Fh2>\u003Cp>---\u003C\u002Fp>\u003Cp>This article introduces the technique of using xwizard.exe to load DLLs, with the particularity that xwizard.exe contains a Microsoft signature, thus to some extent, it can bypass application whitelist blocking.\u003C\u002Fp>\u003C\u002Fbody>\u003C\u002Fhtml>",14,"Onedaysec",3,"published","2026-02-02T07:25:19.684Z",{"title":37,"description":14,"keywords":38,"ogImage":39,"canonicalUrl":39,"noIndex":40},"Use xwizard.exe to Load DLLs: Bypass Whitelists with Microsoft Signed Binary","xwizard.exe, DLL loading, Microsoft signed binary, application whitelist bypass, persistence techniques, Windows security, xwizards.dll, process injection, exploit testing, Win7 x86",null,false,[],{"docs":43,"hasNextPage":40},[4,44,45,46],1201,1200,1199,{"title":39,"description":39,"image":39},"2026-07-24T15:37:08.918Z","2026-07-23T16:02:39.974Z","draft","2026-07-23T16:17:23.014Z"]