I recommend you UnHackMe - Ultimate Malware Killer for fast malware removal:
Free DownloadFully Functional 30-day Trial. No credit card is required.
Reviews. EULA. Privacy Policy. Uninstall.
We checked up the file NTMEND.EXE and found it hazardous.
The file NTMEND.EXE must be deleted from the system immediately.
Kill the process NTMEND.EXE and remove NTMEND.EXE from the Windows startup.
NTMEND.EXE Information and Removal:
NTMEND.EXE is known as: Trojan.Hider [Ikarus].
MD5 of NTMEND.EXE = AB03BEF566E8703F78D69CB08684EFA0
NTMEND.EXE size is 28672 bytes.
Full path on a computer: [PATHNAME WITH A STRING SHARE]\NTMEND.EXE
Related Files:
C:\A88343AB5F8DB6A0D0\INSTALL.EXE
C:\A88343AB5F8DB6A0D0\INSTALL.RES.1033.DLL
%WINDIR%\INSTALLER\2015D.MSI
%APPDATA%\GMARKET.ICO
%TEMP%\DD_VCREDISTMSI0A65.TXT
%TEMP%\DD_VCREDISTUI0A65.TXT
%TEMP%\MSI230F9.LOG
%TEMP%\URL4.TMP
C:\NAUTOUP.LOG
[PATHNAME WITH A STRING SHARE]\AUTOUP.INI
[PATHNAME WITH A STRING SHARE]\BHO.LOG
[PATHNAME WITH A STRING SHARE]\BHOCFG.INI
[PATHNAME WITH A STRING SHARE]\BHOCODE.INI
[PATHNAME WITH A STRING SHARE]\BHOEXE.LOG
[PATHNAME WITH A STRING SHARE]\EFBBAR.DLL
[PATHNAME WITH A STRING SHARE]\EFSBAR.DLL
[PATHNAME WITH A STRING SHARE]\IEWINDOW.EXE
[PATHNAME WITH A STRING SHARE]\IEWINDOW.LOG
[PATHNAME WITH A STRING SHARE]\NAUTOUP.LOG
[PATHNAME WITH A STRING SHARE]\NAVIGATOR.ICO
[PATHNAME WITH A STRING SHARE]\NNLOGON.EXE
[PATHNAME WITH A STRING SHARE]\NNLOGON.INI
[PATHNAME WITH A STRING SHARE]\NNLOGON.LOG
[PATHNAME WITH A STRING SHARE]\NTMEND.EXE
[PATHNAME WITH A STRING SHARE]\NTMURL.DLL
%SYSTEM%\NSEARCHER.EXE
[PATHNAME WITH A STRING SHARE]\SSLAUNCH.DLL
[PATHNAME WITH A STRING SHARE]\SSLAUNCH.LOG
[PATHNAME WITH A STRING SHARE]\TAGS.INI
[PATHNAME WITH A STRING SHARE]\TAGS.MDB
[PATHNAME WITH A STRING SHARE]\TAGSTEMP.MDB
[PATHNAME WITH A STRING SHARE]\UNINST.EXE
[PATHNAME WITH A STRING SHARE]\URLD.EXE
[PATHNAME WITH A STRING SHARE]\URLUPDATE1.EXE
[PATHNAME WITH A STRING SHARE]\VERSION.INI
%WINDIR%\INSTALLER\MSIB.TMP
%SYSTEM%\DWSBC80.OCX
%SYSTEM%\DWSHENGINE80.DLL
%SYSTEM%\DWSHK80.OCX
%SYSTEM%\VB6KO.DLL