Recommended Posts

Ok I found this mysterious program in my C:\ root directory called "gendel32.exe"

I have searched various search engines with no real luck, ran AdAware, spybot S&D, and of course norton anti-virus on it, all with latest updates and reference files. I have found nothing. The file is also referenced in "windows\wininit.ini"

So does anyone have any idea of what this is or does?....apparently if deleted it reappears after reboot. Any help is appreciated.

P.S. Sorry if this is not in the right forum, mods please move if needed.

Link to comment
https://www.neowin.net/forum/topic/134781-what-is-gendel32exe/
Share on other sites

sounds like a virus. reasons:

you say it's in wininit.ini. that file is not part of windows, so gendel32.exe isn't used by windows.

search engines return few results. even if it was a legit file, it would show up.

it's in your root directory. i don't know of any programs/applications that place executables in the root of your hard drive...

most importantly: it reappears when you reboot. this means there is a second copy or another infected file that creates gendel32.exe on bootup.

sounds like a virus. reasons:

you say it's in wininit.ini. that file is not part of windows, so gendel32.exe isn't used by windows.

search engines return few results. even if it was a legit file, it would show up.

it's in your root directory. i don't know of any programs/applications that place executables in the root of your hard drive...

most importantly: it reappears when you reboot. this means there is a second copy or another infected file that creates gendel32.exe on bootup.

Yeah it is suspicious, I just don't know why none of the programs I ran detetcted it. :/

first, find out how it's starting. run msconfig and look on the startup tab. find the item that starts gendel32.exe, and post it's location here.

also, run regedit and run a search for gendel32. post the keys that it shows up in, but don't delete them (they might be used by windows).

first, find out how it's starting. run msconfig and look on the startup tab. find the item that starts gendel32.exe, and post it's location here.

also, run regedit and run a search for gendel32. post the keys that it shows up in, but don't delete them (they might be used by windows).

Yeah i did both them too, it doesn't appear in either msconfig or regedit. Also zonealarm has never asked for an outgoing connection related with it. So it is a mystery.

check HKCR\exefile\shell\open\command and see what the default value is set to. it should be "%1 *1", but if it's not, post what it's set to. if it's set to something else, then the virus is probably launching every time you open a new program :pinch:

Well I edited wininit.ini just now, adding a ' ; ' character to each line and renamed the gendel.exe to gendel.bak and rebooted...after which it hasn't renamed back, so maayyyybee I've stopped it for now. I'm still not sure what it is though seeing as none of the detection programs for adware, spyware and antivirus detects it. I can only assume some website put it there without permission, since I am very careful about the stuff I install etc.

BTW, thanks for your help and ideas gameguy. :)

If anyone does find out what this is, let us know.

Hi

No need to worry, afaik it's part of the install-software from http://www.install-us.com

One of the programs you have or had installed prolly used that installer and gendel32.exe is either a leftover from some installation or it'll be needed for a prog to uninstall.

Suggestion: rename it to gendel32.exe.bak or something similiar and wait for a program to say "hey, I need gendel32.exe" =)

NoNeX

Hi

No need to worry, afaik it's part of the install-software from http://www.install-us.com

One of the programs you have or had installed prolly used that installer and gendel32.exe is either a leftover from some installation or it'll be needed for a prog to uninstall.

Suggestion: rename it to gendel32.exe.bak or something similiar and wait for a program to say "hey, I need gendel32.exe" =)

NoNeX

Ok thanks NoNex. :)

I also got this program in C:.

I checked it with help of ResHacker and all strings is in German, eg:

STRINGTABLE

LANGUAGE LANG_NEUTRAL, SUBLANG_NEUTRAL

{

65440, "Samstag"

65441, "%s kann nicht zu %s zugewiesen werden"

65442, "Datei %s kann nicht erstellt werden"

65443, "Datei %s kann nicht ge?ffnet werden"

65444, "Stream-Read-Fehler"

65445, "Stream-Write-Fehler"

65446, "Der Index der Liste ?berschreitet das Maximum (%d)"

65447, "Die Kapazit?t der Liste ist ersch?pft (%d)"

65448, "Zu viele Eintr?ge in der Liste (%d)"

65449, "Operation bei sortierten Stringlisten nicht erlaubt"

65450, "In der Stringliste sind Duplikate nicht erlaubt"

65451, "Ung?ltiger Wert der Eigenschaft"

}

and since "install-us" is from a german company, it can be from that package.

I think I got it from installing the latest version of Nero.

/Michael

This topic is now closed to further replies.
  • Recently Browsing   0 members

    • No registered users viewing this page.
  • Posts

    • Media Player Classic - Home Cinema 2.7.2 by Razvan Serea Media Player Classic - Home Cinema (MPC-HC) is a free and open-source video and audio player for Windows. MPC-HC is based on the original Guliverkli project (which is no longer maintained) and contains many additional features and bug fixes. As the continuation of the original Media Player Classic, MPC-HC isn’t flashy but it works with nearly any media format. MPC-HC uses DXVA technology to pass decoding operations to your modern video card, enhancing your viewing experience. And MPC-HC supports both physical and software DVDs with menus, chapter navigation, and subtitles. Overview of features A lot of people seem to be unaware of some of the awesome features that have been added to MPC-HC in the past years. Here is a list of useful options and features that everyone should know about: Dark interface Menu > View > Dark Theme When using dark theme it is also possible to change the height of the seekbar and size of the toolbar buttons. Options > Advanced Video preview on the seekbar Options > Tweaks > Show preview on seek bar Adjust playback speed Menu > Play > Playback rate The buttons in the player that control playback rate take a 2x step by default. This can be customized to smaller values (like 10%): Options > Playback > Speed step Adjusting playback speed works best with the internal audio renderer. This also has automatic pitch correction. Options > Playback > Output > Audio Renderer MPC-HC can remember playback position, so you can resume from that point later Options > Player > History You can quickly seek through a video with Ctrl + Mouse Scrollwheel. You can jump to next/previous file in a folder by pressing PageUp/PageDown. You can perform automatic actions at end of file. For example to go to next file or close player. Options > Playback > After Playback (permanent setting) Menu > Play > After Playback (for current file only) A-B repeat - You can loop a segment of a video. Press [ and ] to set start and stop markers. You can rotate/flip/mirror/stretch/zoom the video Menu > View > Pan&Scan This is also easily done with hotkeys (see below). There are lots of keyboard hotkeys and mouse actions to control the player. They can be customized as well. Options > Player > Keys Tip: there is a search box above the table. You can stream videos directly from Youtube and many other video websites You can stream videos directly from Youtube and many other video websites Put yt-dlp.exe or youtube-dl.exe in the MPC-HC installation folder. Then you can open website URLs in the player: Menu > File > Open File/URL You can even download those videos: Menu > File > Save a copy Tip: to be able to download in best quality with yt-dlp/youtube-dl, it is recommended to also put ffmpeg.exe in the MPC-HC folder. Several YDL configuration options are found here: Options > Advanced This includes an option to specify the location of the .exe in case you don't want to put it in MPC-HC folder. Play HDR video This requires using madVR or MPC Video Renderer. After installation these renderers can be selected here: Options > Playback > Output Ability to search for and download subtitles, either automatically or manually (press D): Options > Subtitles > Misc Besides all these (new) features, there have also been many bugfixes and internal improvements in the player in the past years that give better performance and stability. It also has updated internal codecs. Support was added for CUE sheets, WebVTT subtitles, etc. Media Player Classic - Home Cinema 2.7.2 changelog: Updated LAV Filters to version 0.81-23-g6fadb Updated MPC Video Renderer to version 0.10.2.2540 Updated MediaInfo DLL to version 26.05 Updated MPC Audio Renderer Several crash fixes, bug fixes and small improvements. Download: MPC-HC 2.7.2 (x64) | Standalone | ~20.0 MB (Open Source) Download: MPC-HC 2.7.2 (x86) | Standalone Links: MPC-HC Home Page | Screenshot Get alerted to all of our Software updates on Twitter at @NeowinSoftware
    • No problems here using the new Outlook. In our company we started to default installing to users on new computers or when we're reimaging. But, if the user needs/ask for the classic one, we install it. Low reject rate at this point.
    • Yeah it's my only home/business computer. The Surface Pen magnetic Storage is on the left side, but it doesn't charge the Pen. I do the charging once every 6+ months by interchanging between 2 rechargeable AAAA batteries and charging the other via a USB A battery charger.
    • I have NO problem restricting minors having access to apps. Personally, I'd like to see the restriction extend to smartphones too, but that should be the parents anyway. But on the restrictions ? GOOD LUCK enforcing that. Between VPN's, side loading and what not, I'm sure kids will find a way around it.
  • Recent Achievements

    • Very Popular
      s0nic69 earned a badge
      Very Popular
    • Collaborator
      Asgardi earned a badge
      Collaborator
    • Conversation Starter
      mobandz earned a badge
      Conversation Starter
    • Apprentice
      fernan99 went up a rank
      Apprentice
    • One Month Later
      nothanks earned a badge
      One Month Later
  • Popular Contributors

    1. 1
      +primortal
      466
    2. 2
      PsYcHoKiLLa
      246
    3. 3
      Skyfrog
      79
    4. 4
      FloatingFatMan
      65
    5. 5
      Michael Scrip
      60
  • Tell a friend

    Love Neowin? Tell a friend!