Recommended Posts

Ok I found this mysterious program in my C:\ root directory called "gendel32.exe"

I have searched various search engines with no real luck, ran AdAware, spybot S&D, and of course norton anti-virus on it, all with latest updates and reference files. I have found nothing. The file is also referenced in "windows\wininit.ini"

So does anyone have any idea of what this is or does?....apparently if deleted it reappears after reboot. Any help is appreciated.

P.S. Sorry if this is not in the right forum, mods please move if needed.

Link to comment
https://www.neowin.net/forum/topic/134781-what-is-gendel32exe/
Share on other sites

sounds like a virus. reasons:

you say it's in wininit.ini. that file is not part of windows, so gendel32.exe isn't used by windows.

search engines return few results. even if it was a legit file, it would show up.

it's in your root directory. i don't know of any programs/applications that place executables in the root of your hard drive...

most importantly: it reappears when you reboot. this means there is a second copy or another infected file that creates gendel32.exe on bootup.

sounds like a virus. reasons:

you say it's in wininit.ini. that file is not part of windows, so gendel32.exe isn't used by windows.

search engines return few results. even if it was a legit file, it would show up.

it's in your root directory. i don't know of any programs/applications that place executables in the root of your hard drive...

most importantly: it reappears when you reboot. this means there is a second copy or another infected file that creates gendel32.exe on bootup.

Yeah it is suspicious, I just don't know why none of the programs I ran detetcted it. :/

first, find out how it's starting. run msconfig and look on the startup tab. find the item that starts gendel32.exe, and post it's location here.

also, run regedit and run a search for gendel32. post the keys that it shows up in, but don't delete them (they might be used by windows).

first, find out how it's starting. run msconfig and look on the startup tab. find the item that starts gendel32.exe, and post it's location here.

also, run regedit and run a search for gendel32. post the keys that it shows up in, but don't delete them (they might be used by windows).

Yeah i did both them too, it doesn't appear in either msconfig or regedit. Also zonealarm has never asked for an outgoing connection related with it. So it is a mystery.

check HKCR\exefile\shell\open\command and see what the default value is set to. it should be "%1 *1", but if it's not, post what it's set to. if it's set to something else, then the virus is probably launching every time you open a new program :pinch:

Well I edited wininit.ini just now, adding a ' ; ' character to each line and renamed the gendel.exe to gendel.bak and rebooted...after which it hasn't renamed back, so maayyyybee I've stopped it for now. I'm still not sure what it is though seeing as none of the detection programs for adware, spyware and antivirus detects it. I can only assume some website put it there without permission, since I am very careful about the stuff I install etc.

BTW, thanks for your help and ideas gameguy. :)

If anyone does find out what this is, let us know.

Hi

No need to worry, afaik it's part of the install-software from http://www.install-us.com

One of the programs you have or had installed prolly used that installer and gendel32.exe is either a leftover from some installation or it'll be needed for a prog to uninstall.

Suggestion: rename it to gendel32.exe.bak or something similiar and wait for a program to say "hey, I need gendel32.exe" =)

NoNeX

Hi

No need to worry, afaik it's part of the install-software from http://www.install-us.com

One of the programs you have or had installed prolly used that installer and gendel32.exe is either a leftover from some installation or it'll be needed for a prog to uninstall.

Suggestion: rename it to gendel32.exe.bak or something similiar and wait for a program to say "hey, I need gendel32.exe" =)

NoNeX

Ok thanks NoNex. :)

I also got this program in C:.

I checked it with help of ResHacker and all strings is in German, eg:

STRINGTABLE

LANGUAGE LANG_NEUTRAL, SUBLANG_NEUTRAL

{

65440, "Samstag"

65441, "%s kann nicht zu %s zugewiesen werden"

65442, "Datei %s kann nicht erstellt werden"

65443, "Datei %s kann nicht ge?ffnet werden"

65444, "Stream-Read-Fehler"

65445, "Stream-Write-Fehler"

65446, "Der Index der Liste ?berschreitet das Maximum (%d)"

65447, "Die Kapazit?t der Liste ist ersch?pft (%d)"

65448, "Zu viele Eintr?ge in der Liste (%d)"

65449, "Operation bei sortierten Stringlisten nicht erlaubt"

65450, "In der Stringliste sind Duplikate nicht erlaubt"

65451, "Ung?ltiger Wert der Eigenschaft"

}

and since "install-us" is from a german company, it can be from that package.

I think I got it from installing the latest version of Nero.

/Michael

This topic is now closed to further replies.
  • Recently Browsing   0 members

    • No registered users viewing this page.
  • Posts

    • Rescind the stupid "Show more options" in context menus and just give us the full menu instead of adding more steps to get to what we want. The "simpler by default" makes me think they'll go in the opposite direction. Every context menu should have a configure button so you can pick and choose what options should be shown, I know you can do that with some registry fu but that shouldn't be required.
    • This is why competition must exist. Finally, pressure is mounting on Microsoft to move in the right direction.
    • Microsoft is making Windows 11's context menus faster, simpler, and configurable by Taras Buria Five years ago, Windows 11 introduced redesigned context menus, offering users a simpler, more modern design. However, customers quickly discovered that the new menus leave a lot to be desired. Many are unhappy with performance (they are really slow), while others dislike the double-layed design, where many options are hidden behind the "Show more options" button. In addition, over the years, menus became cluttered and overloaded. While Microsoft has already fixed plenty of pain points across Windows 11, context menus remain mostly unchanged. Fortunately, Microsoft is finally listening. Marcus Ash, Design and Research Lead for Windows at Microsoft, responded to a tweet on X, confirming that the company is working on fixing Windows 11's context menus. Reworked context menus are supposed to be faster, simpler by default, and "configurable to what you use most." What the latter means is unknown, just like whether Microsoft plans to keep the classic menu alongside the modern one, but according to Marcus, the wait should finally be over soon, as he promised to "share our approach soon." Improved context menus will most likely appear first in Windows 11 preview builds in the Experimental Channel. While we wait for Microsoft to release them, you can try fixing context menus on your PC with a simple tool called Windows 11 Context Menu Manager. It lets you disable entries you do not need, not only cleaning up context menus, but also making them significantly faster. Microsoft has already improved Windows 11's Start menu and taskbar, so hopefully it will address user criticism of the context menu as well. Stay tuned for new Windows 11 preview builds, which usually arrive every Friday.
    • If the drive/memory is soldered to the board, which it probably is, then it's a no from me
    • Driver Genius 25.0.0.143 by Razvan Serea Driver Genius is a professional driver management tool features both driver management and hardware diagnostics. Driver Genius provides such practical functions as driver backup, restoration, update and removal for computer users. If you often reinstall your operating system, you may not forget such painful experiences of searching all around for all kinds of drivers. If unfortunately you have lost your driver CD, the search will be more troublesome and time-consuming. Driver Genius can automatically find drivers for a device when the system can't find a driver for it. It can recognize the name and vendor's information of the device, and directly provide download URL for the required driver. Driver Genius also supports online updates for drivers of existing hardware devices. Driver Genius customers can obtain information for latest drivers by Driver Genius's LiveUpdate program, which can synchronize to the database on Driver Genius site. Features at a glance: Find the latest drivers for your computer. One click to update all drivers silently. Automatically install driver updates silently. Make your drivers are always up to date. New rollback driver design for safer driver update. Free to backup all drivers now! Package all drivers to an executable auto installer. One click to restore all drivers. Remove invalid or useless drivers/devices, improve system performance and stability. New system information tool. Detailed hardware inventory. Hardware temperature monitor. Protect your CPU, GPU and HDD. New system transfer assistant. Upgrade/degrade your windows system easily. New SSD Speeder. Improve your disk performance and reliability. New System booster provides over 90 optimization options that make your computer run faster and smoother. New System Cleanup can help you to clean up the temporary files and cache files or other junk files in system. Driver Genius 25.0.0.143 changelog: Enhanced detection for Windows Runtime components. Update the hardware detection component to support more new hardware. Update the compression component to address security issues. Download: Driver Genius 25.0.0.143 | 20.7 MB (Shareware) View: Driver Genius Home Page | Screenshot Get alerted to all of our Software updates on Twitter at @NeowinSoftware
  • Recent Achievements

    • One Month Later
      Carru_123 earned a badge
      One Month Later
    • Week One Done
      Dr Jared Dental Studio earned a badge
      Week One Done
    • Week One Done
      RG INVESTMENT GROUP earned a badge
      Week One Done
    • Very Popular
      The Norwegian Drone Pilot earned a badge
      Very Popular
    • Very Popular
      s0nic69 earned a badge
      Very Popular
  • Popular Contributors

    1. 1
      +primortal
      472
    2. 2
      PsYcHoKiLLa
      250
    3. 3
      Skyfrog
      79
    4. 4
      FloatingFatMan
      67
    5. 5
      Michael Scrip
      60
  • Tell a friend

    Love Neowin? Tell a friend!