I got infected right after a Java and Adobe update on my Windows7 machine.
folder \jnihmpibahpjjmcodbopcpdaelkbpjnc is most likely a random generated folder.
Note on malware PriceLess (pops up as Chrome extension, highlights strings for ads):
PriceLess is in folders:
C:\Users\HomeGroupUser$\AppData\Local\Chromatic Browser\User Data\Default\Extensions\jnihmpibahpjjmcodbopcpdaelkbpjnc\5.2
C:\Users\HomeGroupUser$\AppData\Local\Comodo\Dragon\User Data\Default\Extensions\jnihmpibahpjjmcodbopcpdaelkbpjnc\5.2
C:\Users\HomeGroupUser$\AppData\Local\Google\Chrome\User Data\Default\Extensions\jnihmpibahpjjmcodbopcpdaelkbpjnc\5.2
C:\Users\HomeGroupUser$\AppData\Local\Google\Chrome SxS\User Data\Default\Extensions\jnihmpibahpjjmcodbopcpdaelkbpjnc\5.2
C:\Users\HomeGroupUser$\AppData\Local\Torch\User Data\Default\Extensions\jnihmpibahpjjmcodbopcpdaelkbpjnc\5.2
go down to /Extensions each and delete folder \jnihmpibahpjjmcodbopcpdaelkbpjnc
do the same for folders:
C:\Users\Guest\AppData\Local\Chromatic Browser\User Data\Default\Extensions
C:\Users\Guest\AppData\Local\Comodo\Dragon\User Data\Default\Extensions
C:\Guest\AppData\Local\Google\Chrome\User Data\Default\Extensions
C:\Users\Guest\AppData\Local\Google\Chrome SxS\User Data\Default\Extensions
C:\Users\Guest\AppData\Local\Torch\User Data\Default\Extensions
also do the same for folders:
C:\Users\Administrator\AppData\Local\Chromatic Browser\User Data\Default\Extensions
C:\Users\Administrator\AppData\Local\Comodo\Dragon\User Data\Default\Extensions
C:\Users\Administrator\AppData\Local\Google\Chrome\User Data\Default\Extensions
C:\Users\Administrator\AppData\Local\Google\Chrome SxS\User Data\Default\Extensions
C:\Users\Administrator\AppData\Local\Torch\User Data\Default\Extensions
in each case remove folder /jnihmpibahpjjmcodbopcpdaelkbpjnc
contains subfolder /5.2
with files -->
background.html
content.js
lsdb.js
manifest.json --> contains ref to "PriceLess"
r1Iz.js
Do a FindFile search for
*/5.2/r1Iz.js
to make sure you deleted them all
Clear your Recycle Bin