Recommended Posts

Ok I found this mysterious program in my C:\ root directory called "gendel32.exe"

I have searched various search engines with no real luck, ran AdAware, spybot S&D, and of course norton anti-virus on it, all with latest updates and reference files. I have found nothing. The file is also referenced in "windows\wininit.ini"

So does anyone have any idea of what this is or does?....apparently if deleted it reappears after reboot. Any help is appreciated.

P.S. Sorry if this is not in the right forum, mods please move if needed.

Link to comment
https://www.neowin.net/forum/topic/134781-what-is-gendel32exe/
Share on other sites

sounds like a virus. reasons:

you say it's in wininit.ini. that file is not part of windows, so gendel32.exe isn't used by windows.

search engines return few results. even if it was a legit file, it would show up.

it's in your root directory. i don't know of any programs/applications that place executables in the root of your hard drive...

most importantly: it reappears when you reboot. this means there is a second copy or another infected file that creates gendel32.exe on bootup.

sounds like a virus. reasons:

you say it's in wininit.ini. that file is not part of windows, so gendel32.exe isn't used by windows.

search engines return few results. even if it was a legit file, it would show up.

it's in your root directory. i don't know of any programs/applications that place executables in the root of your hard drive...

most importantly: it reappears when you reboot. this means there is a second copy or another infected file that creates gendel32.exe on bootup.

Yeah it is suspicious, I just don't know why none of the programs I ran detetcted it. :/

first, find out how it's starting. run msconfig and look on the startup tab. find the item that starts gendel32.exe, and post it's location here.

also, run regedit and run a search for gendel32. post the keys that it shows up in, but don't delete them (they might be used by windows).

first, find out how it's starting. run msconfig and look on the startup tab. find the item that starts gendel32.exe, and post it's location here.

also, run regedit and run a search for gendel32. post the keys that it shows up in, but don't delete them (they might be used by windows).

Yeah i did both them too, it doesn't appear in either msconfig or regedit. Also zonealarm has never asked for an outgoing connection related with it. So it is a mystery.

check HKCR\exefile\shell\open\command and see what the default value is set to. it should be "%1 *1", but if it's not, post what it's set to. if it's set to something else, then the virus is probably launching every time you open a new program :pinch:

Well I edited wininit.ini just now, adding a ' ; ' character to each line and renamed the gendel.exe to gendel.bak and rebooted...after which it hasn't renamed back, so maayyyybee I've stopped it for now. I'm still not sure what it is though seeing as none of the detection programs for adware, spyware and antivirus detects it. I can only assume some website put it there without permission, since I am very careful about the stuff I install etc.

BTW, thanks for your help and ideas gameguy. :)

If anyone does find out what this is, let us know.

Hi

No need to worry, afaik it's part of the install-software from http://www.install-us.com

One of the programs you have or had installed prolly used that installer and gendel32.exe is either a leftover from some installation or it'll be needed for a prog to uninstall.

Suggestion: rename it to gendel32.exe.bak or something similiar and wait for a program to say "hey, I need gendel32.exe" =)

NoNeX

Hi

No need to worry, afaik it's part of the install-software from http://www.install-us.com

One of the programs you have or had installed prolly used that installer and gendel32.exe is either a leftover from some installation or it'll be needed for a prog to uninstall.

Suggestion: rename it to gendel32.exe.bak or something similiar and wait for a program to say "hey, I need gendel32.exe" =)

NoNeX

Ok thanks NoNex. :)

I also got this program in C:.

I checked it with help of ResHacker and all strings is in German, eg:

STRINGTABLE

LANGUAGE LANG_NEUTRAL, SUBLANG_NEUTRAL

{

65440, "Samstag"

65441, "%s kann nicht zu %s zugewiesen werden"

65442, "Datei %s kann nicht erstellt werden"

65443, "Datei %s kann nicht ge?ffnet werden"

65444, "Stream-Read-Fehler"

65445, "Stream-Write-Fehler"

65446, "Der Index der Liste ?berschreitet das Maximum (%d)"

65447, "Die Kapazit?t der Liste ist ersch?pft (%d)"

65448, "Zu viele Eintr?ge in der Liste (%d)"

65449, "Operation bei sortierten Stringlisten nicht erlaubt"

65450, "In der Stringliste sind Duplikate nicht erlaubt"

65451, "Ung?ltiger Wert der Eigenschaft"

}

and since "install-us" is from a german company, it can be from that package.

I think I got it from installing the latest version of Nero.

/Michael

This topic is now closed to further replies.
  • Recently Browsing   0 members

    • No registered users viewing this page.
  • Posts

    • Well again I do not mind seeing it charge my stuff if it does it well. "yeah charge my phone like that, charge it good"
    • Getting so tired of this push for that new useless slop over the less-useless old slop that at this point I just want M$ to have this nice, big, hearty cup of *FU*.
    • Brave Browser 1.91.168 by Razvan Serea Brave Browser is a lightning-fast, secure web browser that stands out from the competition with its focus on privacy, security, and speed. With features like HTTPS Everywhere and built-in tracker blocking, Brave keeps your online activities safe from prying eyes. Brave is one of the safest browsers on the market today. It blocks third-party data storage. It protects from browser fingerprinting. And it does all this by default. Speed - Brave is built on Chromium, the same technology that powers Google Chrome, and is optimized for speed, providing a fast and responsive browsing experience. Brave Browser also features Brave Rewards, a system that rewards users with Basic Attention Tokens (BAT) for viewing opt-in ads. This innovative system provides an alternative revenue model for content creators and a way to support the Brave community. SlimBrave Neo takes all the good things about Brave and makes them even better by keeping everything clean, light, and privacy-focused. It removes the extra clutter, turns off features you might not need, and cuts down on anything that could slow you down or collect unnecessary data. Because it relies on simple settings and policies instead of modifying the browser itself, you still get full Brave compatibility—just in a smoother, lighter, and more privacy-friendly package. Brave Browser 1.91.168 changelog: Web3 Added “Get Started” section to the “Portfolio” page. (#54029) Added the ability to view “Asset Distribution” in “Portfolio”. (#54028) Added dotted texture to wallet line chart. (#54216) Migrated Jupiter swap provider to “Gate3”. (#51848) Updated the “Permission” panel to display the site origin. (#54482) Updated NFT balance fetch to remove duplicate entries prior to fetching balances. (#55036) Fixed missing back button on the “Deposit Funds” page. (#55842) Fixed reloading an account tab redirecting to the “Accounts” page. (#54826) Leo Added support for text file uploads with renderer-based extraction. (#54062) Added PDF text extraction at upload time. (#51911) Updated display of Brave Leo attachment previews to scroll horizontally instead of vertically. (#54258) Updated the “Copy” button for the code block header to be sticky when scrolling. (#53704) Updated the staged content in the Leo side panel to be the active tab. (#53533) Updated the search terms in the answer’s footer to be left aligned. (#54204) Fixed crash which could occur in certain cases when using multiple tool requests. (#55438) General Added support for Brave Origin. (#37127) [Security] Added the ability to disable or delay automatic extension updates when brave://flags/#brave-user-extension-auto-update is enabled. (#7200) Enabled ability to force context menu using “Shift + Right Click” by default. (#54790) Improved performance by caching adblock DATs. (#27161) Updated background color for PWA install button in the omnibox. (#54736) Fixed tab hover card position when using vertical tabs. (#54199) Fixed extra border displaying around the content area when vertical tabs are used on macOS. (#54153 & #52961) Fixed audio farbling distortion in multi-voice Web Audio API synthesized music. (#52906) Upgraded Chromium to 149.0.7827.54. (#55943) Download: Brave Browser 64-bit | 1.2 MB (Freeware) Download: Brave Browser 32-bit View: Brave Homepage | Offline Installers | Screenshot Get alerted to all of our Software updates on Twitter at @NeowinSoftware
    • Thanks Microsoft but no, I find both iterations of Outlook terrible nowadays and switched back to Thunderbird at home.
  • Recent Achievements

    • One Year In
      CHUNWEI earned a badge
      One Year In
    • Conversation Starter
      FBSPL earned a badge
      Conversation Starter
    • Week One Done
      I2D earned a badge
      Week One Done
    • Week One Done
      Dr Jared Dental Studio earned a badge
      Week One Done
    • Week One Done
      RG INVESTMENT GROUP earned a badge
      Week One Done
  • Popular Contributors

    1. 1
      +primortal
      470
    2. 2
      PsYcHoKiLLa
      255
    3. 3
      Skyfrog
      80
    4. 4
      FloatingFatMan
      62
    5. 5
      Michael Scrip
      62
  • Tell a friend

    Love Neowin? Tell a friend!