ComboFix 15-02-16.01 - Jared 02/19/2015 7:45.2.2 - x86 Microsoft Windows 7 Home Basic 6.1.7601.1.1252.1.1033.18.3327.2417 [GMT 8:00] Running from: c:\users\Jared\Desktop\ufcom.exe AV: Microsoft Security Essentials *Enabled/Updated* {4F35CFC4-45A3-FC37-EF17-759A02E39AB1} FW: avast! Antivirus *Disabled* {2F96FC65-F07D-9D1E-5A6E-3DA5C487EAF0} SP: Microsoft Security Essentials *Enabled/Updated* {F4542E20-6399-F3B9-D5A7-4EE87964D00C} SP: Windows Defender *Disabled/Updated* {D68DDC3A-831F-4fae-9E44-DA132C1ACF46} . . ((((((((((((((((((((((((((((((((((((((( Other Deletions ))))))))))))))))))))))))))))))))))))))))))))))))) . . c:\users\Jared\AppData\Local\Google\Chrome\User Data\Default\Extensions\gighmmpiobklfepjocnamgkkbiglidom c:\users\Jared\AppData\Local\Google\Chrome\User Data\Default\Extensions\gighmmpiobklfepjocnamgkkbiglidom\2.18_0\_locales\ar\messages.json c:\users\Jared\AppData\Local\Google\Chrome\User Data\Default\Extensions\gighmmpiobklfepjocnamgkkbiglidom\2.18_0\_locales\bg\messages.json c:\users\Jared\AppData\Local\Google\Chrome\User Data\Default\Extensions\gighmmpiobklfepjocnamgkkbiglidom\2.18_0\_locales\ca\messages.json c:\users\Jared\AppData\Local\Google\Chrome\User Data\Default\Extensions\gighmmpiobklfepjocnamgkkbiglidom\2.18_0\_locales\cs\messages.json c:\users\Jared\AppData\Local\Google\Chrome\User Data\Default\Extensions\gighmmpiobklfepjocnamgkkbiglidom\2.18_0\_locales\da\messages.json c:\users\Jared\AppData\Local\Google\Chrome\User Data\Default\Extensions\gighmmpiobklfepjocnamgkkbiglidom\2.18_0\_locales\de\messages.json c:\users\Jared\AppData\Local\Google\Chrome\User Data\Default\Extensions\gighmmpiobklfepjocnamgkkbiglidom\2.18_0\_locales\el\messages.json c:\users\Jared\AppData\Local\Google\Chrome\User Data\Default\Extensions\gighmmpiobklfepjocnamgkkbiglidom\2.18_0\_locales\en\messages.json c:\users\Jared\AppData\Local\Google\Chrome\User Data\Default\Extensions\gighmmpiobklfepjocnamgkkbiglidom\2.18_0\_locales\es\messages.json c:\users\Jared\AppData\Local\Google\Chrome\User Data\Default\Extensions\gighmmpiobklfepjocnamgkkbiglidom\2.18_0\_locales\fi\messages.json c:\users\Jared\AppData\Local\Google\Chrome\User Data\Default\Extensions\gighmmpiobklfepjocnamgkkbiglidom\2.18_0\_locales\fr\messages.json c:\users\Jared\AppData\Local\Google\Chrome\User Data\Default\Extensions\gighmmpiobklfepjocnamgkkbiglidom\2.18_0\_locales\he\messages.json c:\users\Jared\AppData\Local\Google\Chrome\User Data\Default\Extensions\gighmmpiobklfepjocnamgkkbiglidom\2.18_0\_locales\hr\messages.json c:\users\Jared\AppData\Local\Google\Chrome\User Data\Default\Extensions\gighmmpiobklfepjocnamgkkbiglidom\2.18_0\_locales\hu\messages.json c:\users\Jared\AppData\Local\Google\Chrome\User Data\Default\Extensions\gighmmpiobklfepjocnamgkkbiglidom\2.18_0\_locales\id\messages.json c:\users\Jared\AppData\Local\Google\Chrome\User Data\Default\Extensions\gighmmpiobklfepjocnamgkkbiglidom\2.18_0\_locales\it\messages.json c:\users\Jared\AppData\Local\Google\Chrome\User Data\Default\Extensions\gighmmpiobklfepjocnamgkkbiglidom\2.18_0\_locales\ja\messages.json c:\users\Jared\AppData\Local\Google\Chrome\User Data\Default\Extensions\gighmmpiobklfepjocnamgkkbiglidom\2.18_0\_locales\ko\messages.json c:\users\Jared\AppData\Local\Google\Chrome\User Data\Default\Extensions\gighmmpiobklfepjocnamgkkbiglidom\2.18_0\_locales\nb\messages.json c:\users\Jared\AppData\Local\Google\Chrome\User Data\Default\Extensions\gighmmpiobklfepjocnamgkkbiglidom\2.18_0\_locales\nl\messages.json c:\users\Jared\AppData\Local\Google\Chrome\User Data\Default\Extensions\gighmmpiobklfepjocnamgkkbiglidom\2.18_0\_locales\pl\messages.json c:\users\Jared\AppData\Local\Google\Chrome\User Data\Default\Extensions\gighmmpiobklfepjocnamgkkbiglidom\2.18_0\_locales\pt_BR\messages.json c:\users\Jared\AppData\Local\Google\Chrome\User Data\Default\Extensions\gighmmpiobklfepjocnamgkkbiglidom\2.18_0\_locales\pt_PT\messages.json c:\users\Jared\AppData\Local\Google\Chrome\User Data\Default\Extensions\gighmmpiobklfepjocnamgkkbiglidom\2.18_0\_locales\ro\messages.json c:\users\Jared\AppData\Local\Google\Chrome\User Data\Default\Extensions\gighmmpiobklfepjocnamgkkbiglidom\2.18_0\_locales\ru\messages.json c:\users\Jared\AppData\Local\Google\Chrome\User Data\Default\Extensions\gighmmpiobklfepjocnamgkkbiglidom\2.18_0\_locales\sk\messages.json c:\users\Jared\AppData\Local\Google\Chrome\User Data\Default\Extensions\gighmmpiobklfepjocnamgkkbiglidom\2.18_0\_locales\sl\messages.json c:\users\Jared\AppData\Local\Google\Chrome\User Data\Default\Extensions\gighmmpiobklfepjocnamgkkbiglidom\2.18_0\_locales\sr\messages.json c:\users\Jared\AppData\Local\Google\Chrome\User Data\Default\Extensions\gighmmpiobklfepjocnamgkkbiglidom\2.18_0\_locales\sv\messages.json c:\users\Jared\AppData\Local\Google\Chrome\User Data\Default\Extensions\gighmmpiobklfepjocnamgkkbiglidom\2.18_0\_locales\te\messages.json c:\users\Jared\AppData\Local\Google\Chrome\User Data\Default\Extensions\gighmmpiobklfepjocnamgkkbiglidom\2.18_0\_locales\tr\messages.json c:\users\Jared\AppData\Local\Google\Chrome\User Data\Default\Extensions\gighmmpiobklfepjocnamgkkbiglidom\2.18_0\_locales\uk\messages.json c:\users\Jared\AppData\Local\Google\Chrome\User Data\Default\Extensions\gighmmpiobklfepjocnamgkkbiglidom\2.18_0\_locales\vi\messages.json c:\users\Jared\AppData\Local\Google\Chrome\User Data\Default\Extensions\gighmmpiobklfepjocnamgkkbiglidom\2.18_0\_locales\zh_CN\messages.json c:\users\Jared\AppData\Local\Google\Chrome\User Data\Default\Extensions\gighmmpiobklfepjocnamgkkbiglidom\2.18_0\_locales\zh_TW\messages.json c:\users\Jared\AppData\Local\Google\Chrome\User Data\Default\Extensions\gighmmpiobklfepjocnamgkkbiglidom\2.18_0\_metadata\computed_hashes.json c:\users\Jared\AppData\Local\Google\Chrome\User Data\Default\Extensions\gighmmpiobklfepjocnamgkkbiglidom\2.18_0\_metadata\verified_contents.json c:\users\Jared\AppData\Local\Google\Chrome\User Data\Default\Extensions\gighmmpiobklfepjocnamgkkbiglidom\2.18_0\adblock_start_chrome.js c:\users\Jared\AppData\Local\Google\Chrome\User Data\Default\Extensions\gighmmpiobklfepjocnamgkkbiglidom\2.18_0\adblock_start_common.js c:\users\Jared\AppData\Local\Google\Chrome\User Data\Default\Extensions\gighmmpiobklfepjocnamgkkbiglidom\2.18_0\background.js c:\users\Jared\AppData\Local\Google\Chrome\User Data\Default\Extensions\gighmmpiobklfepjocnamgkkbiglidom\2.18_0\bandaids.js c:\users\Jared\AppData\Local\Google\Chrome\User Data\Default\Extensions\gighmmpiobklfepjocnamgkkbiglidom\2.18_0\button\popup.css c:\users\Jared\AppData\Local\Google\Chrome\User Data\Default\Extensions\gighmmpiobklfepjocnamgkkbiglidom\2.18_0\button\popup.html c:\users\Jared\AppData\Local\Google\Chrome\User Data\Default\Extensions\gighmmpiobklfepjocnamgkkbiglidom\2.18_0\button\popup.js c:\users\Jared\AppData\Local\Google\Chrome\User Data\Default\Extensions\gighmmpiobklfepjocnamgkkbiglidom\2.18_0\button\search\search.css c:\users\Jared\AppData\Local\Google\Chrome\User Data\Default\Extensions\gighmmpiobklfepjocnamgkkbiglidom\2.18_0\button\search\search.js c:\users\Jared\AppData\Local\Google\Chrome\User Data\Default\Extensions\gighmmpiobklfepjocnamgkkbiglidom\2.18_0\CHANGELOG.txt c:\users\Jared\AppData\Local\Google\Chrome\User Data\Default\Extensions\gighmmpiobklfepjocnamgkkbiglidom\2.18_0\checkupdates.js c:\users\Jared\AppData\Local\Google\Chrome\User Data\Default\Extensions\gighmmpiobklfepjocnamgkkbiglidom\2.18_0\chrome_oauth_receiver.html c:\users\Jared\AppData\Local\Google\Chrome\User Data\Default\Extensions\gighmmpiobklfepjocnamgkkbiglidom\2.18_0\chrome_oauth_receiver.js c:\users\Jared\AppData\Local\Google\Chrome\User Data\Default\Extensions\gighmmpiobklfepjocnamgkkbiglidom\2.18_0\dropbox-datastores.js c:\users\Jared\AppData\Local\Google\Chrome\User Data\Default\Extensions\gighmmpiobklfepjocnamgkkbiglidom\2.18_0\filtering\domainset.js c:\users\Jared\AppData\Local\Google\Chrome\User Data\Default\Extensions\gighmmpiobklfepjocnamgkkbiglidom\2.18_0\filtering\filternormalizer.js c:\users\Jared\AppData\Local\Google\Chrome\User Data\Default\Extensions\gighmmpiobklfepjocnamgkkbiglidom\2.18_0\filtering\filteroptions.js c:\users\Jared\AppData\Local\Google\Chrome\User Data\Default\Extensions\gighmmpiobklfepjocnamgkkbiglidom\2.18_0\filtering\filterset.js c:\users\Jared\AppData\Local\Google\Chrome\User Data\Default\Extensions\gighmmpiobklfepjocnamgkkbiglidom\2.18_0\filtering\filtertypes.js c:\users\Jared\AppData\Local\Google\Chrome\User Data\Default\Extensions\gighmmpiobklfepjocnamgkkbiglidom\2.18_0\filtering\myfilters.js c:\users\Jared\AppData\Local\Google\Chrome\User Data\Default\Extensions\gighmmpiobklfepjocnamgkkbiglidom\2.18_0\functions.js c:\users\Jared\AppData\Local\Google\Chrome\User Data\Default\Extensions\gighmmpiobklfepjocnamgkkbiglidom\2.18_0\idlehandler.js c:\users\Jared\AppData\Local\Google\Chrome\User Data\Default\Extensions\gighmmpiobklfepjocnamgkkbiglidom\2.18_0\img\delete.gif c:\users\Jared\AppData\Local\Google\Chrome\User Data\Default\Extensions\gighmmpiobklfepjocnamgkkbiglidom\2.18_0\img\dropbox1.png c:\users\Jared\AppData\Local\Google\Chrome\User Data\Default\Extensions\gighmmpiobklfepjocnamgkkbiglidom\2.18_0\img\dropbox2.png c:\users\Jared\AppData\Local\Google\Chrome\User Data\Default\Extensions\gighmmpiobklfepjocnamgkkbiglidom\2.18_0\img\dropbox3.png c:\users\Jared\AppData\Local\Google\Chrome\User Data\Default\Extensions\gighmmpiobklfepjocnamgkkbiglidom\2.18_0\img\facebook-sprite.png c:\users\Jared\AppData\Local\Google\Chrome\User Data\Default\Extensions\gighmmpiobklfepjocnamgkkbiglidom\2.18_0\img\gifloader.gif c:\users\Jared\AppData\Local\Google\Chrome\User Data\Default\Extensions\gighmmpiobklfepjocnamgkkbiglidom\2.18_0\img\gplus-sprite.png c:\users\Jared\AppData\Local\Google\Chrome\User Data\Default\Extensions\gighmmpiobklfepjocnamgkkbiglidom\2.18_0\img\icon128.png c:\users\Jared\AppData\Local\Google\Chrome\User Data\Default\Extensions\gighmmpiobklfepjocnamgkkbiglidom\2.18_0\img\icon16.png c:\users\Jared\AppData\Local\Google\Chrome\User Data\Default\Extensions\gighmmpiobklfepjocnamgkkbiglidom\2.18_0\img\icon16_grayscale.png c:\users\Jared\AppData\Local\Google\Chrome\User Data\Default\Extensions\gighmmpiobklfepjocnamgkkbiglidom\2.18_0\img\icon16_grayscale@2x.png c:\users\Jared\AppData\Local\Google\Chrome\User Data\Default\Extensions\gighmmpiobklfepjocnamgkkbiglidom\2.18_0\img\icon19-grayscale.png c:\users\Jared\AppData\Local\Google\Chrome\User Data\Default\Extensions\gighmmpiobklfepjocnamgkkbiglidom\2.18_0\img\icon19-whitelisted.png c:\users\Jared\AppData\Local\Google\Chrome\User Data\Default\Extensions\gighmmpiobklfepjocnamgkkbiglidom\2.18_0\img\icon19.png c:\users\Jared\AppData\Local\Google\Chrome\User Data\Default\Extensions\gighmmpiobklfepjocnamgkkbiglidom\2.18_0\img\icon24.png c:\users\Jared\AppData\Local\Google\Chrome\User Data\Default\Extensions\gighmmpiobklfepjocnamgkkbiglidom\2.18_0\img\icon32.png c:\users\Jared\AppData\Local\Google\Chrome\User Data\Default\Extensions\gighmmpiobklfepjocnamgkkbiglidom\2.18_0\img\icon38-grayscale.png c:\users\Jared\AppData\Local\Google\Chrome\User Data\Default\Extensions\gighmmpiobklfepjocnamgkkbiglidom\2.18_0\img\icon38-whitelisted.png c:\users\Jared\AppData\Local\Google\Chrome\User Data\Default\Extensions\gighmmpiobklfepjocnamgkkbiglidom\2.18_0\img\icon38.png c:\users\Jared\AppData\Local\Google\Chrome\User Data\Default\Extensions\gighmmpiobklfepjocnamgkkbiglidom\2.18_0\img\icon48.png c:\users\Jared\AppData\Local\Google\Chrome\User Data\Default\Extensions\gighmmpiobklfepjocnamgkkbiglidom\2.18_0\img\logo.png c:\users\Jared\AppData\Local\Google\Chrome\User Data\Default\Extensions\gighmmpiobklfepjocnamgkkbiglidom\2.18_0\img\search\check.png c:\users\Jared\AppData\Local\Google\Chrome\User Data\Default\Extensions\gighmmpiobklfepjocnamgkkbiglidom\2.18_0\img\search\magnifying_glass.png c:\users\Jared\AppData\Local\Google\Chrome\User Data\Default\Extensions\gighmmpiobklfepjocnamgkkbiglidom\2.18_0\img\search\search-engine-card_no-shadow.png c:\users\Jared\AppData\Local\Google\Chrome\User Data\Default\Extensions\gighmmpiobklfepjocnamgkkbiglidom\2.18_0\img\search\search-engine-icons.png c:\users\Jared\AppData\Local\Google\Chrome\User Data\Default\Extensions\gighmmpiobklfepjocnamgkkbiglidom\2.18_0\img\search\search-omnibox-card_no-shadow.png c:\users\Jared\AppData\Local\Google\Chrome\User Data\Default\Extensions\gighmmpiobklfepjocnamgkkbiglidom\2.18_0\img\search\search_engine_select_arrow.png c:\users\Jared\AppData\Local\Google\Chrome\User Data\Default\Extensions\gighmmpiobklfepjocnamgkkbiglidom\2.18_0\img\twitter-sprite.png c:\users\Jared\AppData\Local\Google\Chrome\User Data\Default\Extensions\gighmmpiobklfepjocnamgkkbiglidom\2.18_0\jquery\css\images\ui-bg_flat_55_999999_40x100.png c:\users\Jared\AppData\Local\Google\Chrome\User Data\Default\Extensions\gighmmpiobklfepjocnamgkkbiglidom\2.18_0\jquery\css\images\ui-bg_flat_75_aaaaaa_40x100.png c:\users\Jared\AppData\Local\Google\Chrome\User Data\Default\Extensions\gighmmpiobklfepjocnamgkkbiglidom\2.18_0\jquery\css\images\ui-bg_glass_45_0078ae_1x400.png c:\users\Jared\AppData\Local\Google\Chrome\User Data\Default\Extensions\gighmmpiobklfepjocnamgkkbiglidom\2.18_0\jquery\css\images\ui-bg_glass_55_f8da4e_1x400.png c:\users\Jared\AppData\Local\Google\Chrome\User Data\Default\Extensions\gighmmpiobklfepjocnamgkkbiglidom\2.18_0\jquery\css\images\ui-bg_glass_75_79c9ec_1x400.png c:\users\Jared\AppData\Local\Google\Chrome\User Data\Default\Extensions\gighmmpiobklfepjocnamgkkbiglidom\2.18_0\jquery\css\images\ui-bg_gloss-wave_50_38cfff_500x100.png c:\users\Jared\AppData\Local\Google\Chrome\User Data\Default\Extensions\gighmmpiobklfepjocnamgkkbiglidom\2.18_0\jquery\css\images\ui-bg_gloss-wave_75_2191c0_500x100.png c:\users\Jared\AppData\Local\Google\Chrome\User Data\Default\Extensions\gighmmpiobklfepjocnamgkkbiglidom\2.18_0\jquery\css\images\ui-bg_inset-hard_100_fcfdfd_1x100.png c:\users\Jared\AppData\Local\Google\Chrome\User Data\Default\Extensions\gighmmpiobklfepjocnamgkkbiglidom\2.18_0\jquery\css\images\ui-icons_056b93_256x240.png c:\users\Jared\AppData\Local\Google\Chrome\User Data\Default\Extensions\gighmmpiobklfepjocnamgkkbiglidom\2.18_0\jquery\css\images\ui-icons_d8e7f3_256x240.png c:\users\Jared\AppData\Local\Google\Chrome\User Data\Default\Extensions\gighmmpiobklfepjocnamgkkbiglidom\2.18_0\jquery\css\jquery-ui.custom.css c:\users\Jared\AppData\Local\Google\Chrome\User Data\Default\Extensions\gighmmpiobklfepjocnamgkkbiglidom\2.18_0\jquery\css\override-page.css c:\users\Jared\AppData\Local\Google\Chrome\User Data\Default\Extensions\gighmmpiobklfepjocnamgkkbiglidom\2.18_0\jquery\jquery-ui.custom.min.js c:\users\Jared\AppData\Local\Google\Chrome\User Data\Default\Extensions\gighmmpiobklfepjocnamgkkbiglidom\2.18_0\jquery\jquery.cookie.js c:\users\Jared\AppData\Local\Google\Chrome\User Data\Default\Extensions\gighmmpiobklfepjocnamgkkbiglidom\2.18_0\jquery\jquery.min.js c:\users\Jared\AppData\Local\Google\Chrome\User Data\Default\Extensions\gighmmpiobklfepjocnamgkkbiglidom\2.18_0\LICENSE c:\users\Jared\AppData\Local\Google\Chrome\User Data\Default\Extensions\gighmmpiobklfepjocnamgkkbiglidom\2.18_0\manifest.json c:\users\Jared\AppData\Local\Google\Chrome\User Data\Default\Extensions\gighmmpiobklfepjocnamgkkbiglidom\2.18_0\options\customize.html c:\users\Jared\AppData\Local\Google\Chrome\User Data\Default\Extensions\gighmmpiobklfepjocnamgkkbiglidom\2.18_0\options\customize.js c:\users\Jared\AppData\Local\Google\Chrome\User Data\Default\Extensions\gighmmpiobklfepjocnamgkkbiglidom\2.18_0\options\filters.html c:\users\Jared\AppData\Local\Google\Chrome\User Data\Default\Extensions\gighmmpiobklfepjocnamgkkbiglidom\2.18_0\options\filters.js c:\users\Jared\AppData\Local\Google\Chrome\User Data\Default\Extensions\gighmmpiobklfepjocnamgkkbiglidom\2.18_0\options\general.html c:\users\Jared\AppData\Local\Google\Chrome\User Data\Default\Extensions\gighmmpiobklfepjocnamgkkbiglidom\2.18_0\options\general.js c:\users\Jared\AppData\Local\Google\Chrome\User Data\Default\Extensions\gighmmpiobklfepjocnamgkkbiglidom\2.18_0\options\index.html c:\users\Jared\AppData\Local\Google\Chrome\User Data\Default\Extensions\gighmmpiobklfepjocnamgkkbiglidom\2.18_0\options\index.js c:\users\Jared\AppData\Local\Google\Chrome\User Data\Default\Extensions\gighmmpiobklfepjocnamgkkbiglidom\2.18_0\options\options.css c:\users\Jared\AppData\Local\Google\Chrome\User Data\Default\Extensions\gighmmpiobklfepjocnamgkkbiglidom\2.18_0\options\support.html c:\users\Jared\AppData\Local\Google\Chrome\User Data\Default\Extensions\gighmmpiobklfepjocnamgkkbiglidom\2.18_0\options\support.js c:\users\Jared\AppData\Local\Google\Chrome\User Data\Default\Extensions\gighmmpiobklfepjocnamgkkbiglidom\2.18_0\pages\adreport.html c:\users\Jared\AppData\Local\Google\Chrome\User Data\Default\Extensions\gighmmpiobklfepjocnamgkkbiglidom\2.18_0\pages\adreport.js c:\users\Jared\AppData\Local\Google\Chrome\User Data\Default\Extensions\gighmmpiobklfepjocnamgkkbiglidom\2.18_0\pages\resourceblock.html c:\users\Jared\AppData\Local\Google\Chrome\User Data\Default\Extensions\gighmmpiobklfepjocnamgkkbiglidom\2.18_0\pages\resourceblock.js c:\users\Jared\AppData\Local\Google\Chrome\User Data\Default\Extensions\gighmmpiobklfepjocnamgkkbiglidom\2.18_0\pages\subscribe.html c:\users\Jared\AppData\Local\Google\Chrome\User Data\Default\Extensions\gighmmpiobklfepjocnamgkkbiglidom\2.18_0\pages\subscribe.js c:\users\Jared\AppData\Local\Google\Chrome\User Data\Default\Extensions\gighmmpiobklfepjocnamgkkbiglidom\2.18_0\port.js c:\users\Jared\AppData\Local\Google\Chrome\User Data\Default\Extensions\gighmmpiobklfepjocnamgkkbiglidom\2.18_0\README.markdown c:\users\Jared\AppData\Local\Google\Chrome\User Data\Default\Extensions\gighmmpiobklfepjocnamgkkbiglidom\2.18_0\search\focus.js c:\users\Jared\AppData\Local\Google\Chrome\User Data\Default\Extensions\gighmmpiobklfepjocnamgkkbiglidom\2.18_0\search\incognito.js c:\users\Jared\AppData\Local\Google\Chrome\User Data\Default\Extensions\gighmmpiobklfepjocnamgkkbiglidom\2.18_0\search\pitchpage.js c:\users\Jared\AppData\Local\Google\Chrome\User Data\Default\Extensions\gighmmpiobklfepjocnamgkkbiglidom\2.18_0\search\search-plus-one.js c:\users\Jared\AppData\Local\Google\Chrome\User Data\Default\Extensions\gighmmpiobklfepjocnamgkkbiglidom\2.18_0\search\secure_reminder.js c:\users\Jared\AppData\Local\Google\Chrome\User Data\Default\Extensions\gighmmpiobklfepjocnamgkkbiglidom\2.18_0\search\serp.js c:\users\Jared\AppData\Local\Google\Chrome\User Data\Default\Extensions\gighmmpiobklfepjocnamgkkbiglidom\2.18_0\stats.js c:\users\Jared\AppData\Local\Google\Chrome\User Data\Default\Extensions\gighmmpiobklfepjocnamgkkbiglidom\2.18_0\translators.json c:\users\Jared\AppData\Local\Google\Chrome\User Data\Default\Extensions\gighmmpiobklfepjocnamgkkbiglidom\2.18_0\uiscripts\blacklisting\blacklistui.js c:\users\Jared\AppData\Local\Google\Chrome\User Data\Default\Extensions\gighmmpiobklfepjocnamgkkbiglidom\2.18_0\uiscripts\blacklisting\clickwatcher.js c:\users\Jared\AppData\Local\Google\Chrome\User Data\Default\Extensions\gighmmpiobklfepjocnamgkkbiglidom\2.18_0\uiscripts\blacklisting\elementchain.js c:\users\Jared\AppData\Local\Google\Chrome\User Data\Default\Extensions\gighmmpiobklfepjocnamgkkbiglidom\2.18_0\uiscripts\blacklisting\overlay.js c:\users\Jared\AppData\Local\Google\Chrome\User Data\Default\Extensions\gighmmpiobklfepjocnamgkkbiglidom\2.18_0\uiscripts\blacklisting\rightclick_hook.js c:\users\Jared\AppData\Local\Google\Chrome\User Data\Default\Extensions\gighmmpiobklfepjocnamgkkbiglidom\2.18_0\uiscripts\load_jquery_ui.js c:\users\Jared\AppData\Local\Google\Chrome\User Data\Default\Extensions\gighmmpiobklfepjocnamgkkbiglidom\2.18_0\uiscripts\send_content_to_back.js c:\users\Jared\AppData\Local\Google\Chrome\User Data\Default\Extensions\gighmmpiobklfepjocnamgkkbiglidom\2.18_0\uiscripts\top_open_blacklist_ui.js c:\users\Jared\AppData\Local\Google\Chrome\User Data\Default\Extensions\gighmmpiobklfepjocnamgkkbiglidom\2.18_0\uiscripts\top_open_whitelist_ui.js c:\users\Jared\AppData\Local\Google\Chrome\User Data\Default\Extensions\gighmmpiobklfepjocnamgkkbiglidom\2.18_0\ytchannel.js c:\users\Jared\AppData\Local\Google\Chrome\User Data\Default\Local Storage\chrome-extension_gighmmpiobklfepjocnamgkkbiglidom_0.localstorage c:\users\Jared\AppData\Local\Google\Chrome\User Data\Default\Preferences c:\windows\system32\spsys.log . . ((((((((((((((((((((((((( Files Created from 2015-01-18 to 2015-02-18 ))))))))))))))))))))))))))))))) . . 2015-02-18 23:50 . 2015-02-18 23:50 -------- d-----w- c:\users\Default\AppData\Local\temp 2015-02-18 22:13 . 2015-02-18 22:13 39464 ----a-w- c:\programdata\Microsoft\Microsoft Antimalware\Definition Updates\{FEBD94C8-3E13-4C6B-98F5-47D546740E24}\MpKsl889ff405.sys 2015-02-17 18:11 . 2015-01-29 09:49 9041640 ----a-w- c:\programdata\Microsoft\Microsoft Antimalware\Definition Updates\{FEBD94C8-3E13-4C6B-98F5-47D546740E24}\mpengine.dll 2015-02-16 00:37 . 2014-12-01 19:01 9054624 ----a-w- c:\programdata\Microsoft\Microsoft Antimalware\Definition Updates\Backup\mpengine.dll 2015-02-13 10:08 . 2015-02-13 10:08 43152 ----a-w- c:\windows\avastSS.scr 2015-02-13 09:53 . 2015-02-13 10:00 -------- d-----w- c:\programdata\AVAST Software 2015-02-13 04:32 . 2015-02-04 00:27 908840 ----a-w- c:\programdata\Microsoft\Microsoft Antimalware\Definition Updates\NISBackup\gapaengine.dll 2015-02-13 04:32 . 2015-02-04 00:27 908840 ----a-w- c:\programdata\Microsoft\Microsoft Antimalware\Definition Updates\{B0775937-AE0C-4546-88DF-3093FC19E589}\gapaengine.dll 2015-02-12 06:46 . 2015-02-12 06:46 35992 ----a-w- c:\windows\system32\drivers\hitmanpro37.sys 2015-02-05 12:16 . 2014-12-31 11:13 249488 ------w- c:\windows\system32\MpSigStub.exe 2015-02-04 20:57 . 2015-02-05 12:15 -------- d-----w- c:\program files\PokerStars 2015-02-04 03:53 . 2015-02-04 04:07 -------- d-----w- c:\programdata\HitmanPro 2015-02-04 00:22 . 2015-02-18 22:44 -------- d-----w- c:\program files\Microsoft Security Client 2015-02-01 06:52 . 2015-02-01 06:52 -------- d-----w- c:\programdata\CSIS 2015-01-30 22:00 . 2014-12-14 20:13 9054624 ----a-w- c:\programdata\Microsoft\Windows Defender\Definition Updates\{FA28A1DE-BE9D-4AA6-A0CA-8152716A2E03}\mpengine.dll 2015-01-30 13:37 . 2015-01-30 13:37 -------- d-----w- c:\programdata\magicJack 2015-01-30 07:04 . 2015-02-18 22:20 35064 ----a-w- c:\windows\system32\drivers\TrueSight.sys 2015-01-30 07:04 . 2015-01-30 07:04 -------- d-----w- c:\programdata\RogueKiller 2015-01-30 07:02 . 2015-01-31 09:09 -------- d-----w- c:\programdata\Malwarebytes Anti-Exploit 2015-01-30 06:53 . 2015-02-18 16:54 163504 ----a-w- c:\programdata\Microsoft\Windows\Sqm\Manifest\Sqm10145.bin 2015-01-30 06:49 . 2015-01-30 06:49 -------- d-----w- c:\programdata\Malwarebytes 2015-01-30 06:49 . 2015-01-30 06:55 -------- d-----w- c:\programdata\Malwarebytes' Anti-Malware (portable) 2015-01-30 06:49 . 2015-01-30 06:49 119512 ----a-w- c:\windows\system32\drivers\MBAMSwissArmy.sys 2015-01-30 06:48 . 2015-01-30 06:48 82648 ----a-w- c:\windows\system32\drivers\mbamchameleon.sys 2015-01-30 06:44 . 2012-08-23 14:44 14848 ----a-w- c:\windows\system32\drivers\rdpvideominiport.sys 2015-01-30 06:44 . 2012-08-23 13:52 12800 ----a-w- c:\windows\system32\RdpGroupPolicyExtension.dll 2015-01-30 06:44 . 2012-08-23 14:48 221184 ----a-w- c:\windows\system32\rdpudd.dll 2015-01-30 06:44 . 2012-08-23 11:12 192000 ----a-w- c:\windows\system32\rdpendp_winip.dll 2015-01-30 06:44 . 2012-08-23 10:08 2739712 ----a-w- c:\windows\system32\rdpcorets.dll 2015-01-30 06:42 . 2014-07-02 19:42 4389848 ----a-w- c:\windows\system32\nvcpl.dll 2015-01-30 06:42 . 2014-07-02 19:42 3063256 ----a-w- c:\windows\system32\nvsvc.dll 2015-01-30 06:42 . 2014-07-02 19:42 670552 ----a-w- c:\windows\system32\nvvsvc.exe 2015-01-30 06:42 . 2014-07-02 19:42 62936 ----a-w- c:\windows\system32\nvshext.dll 2015-01-30 06:42 . 2014-07-02 19:42 377288 ----a-w- c:\windows\system32\nvmctray.dll 2015-01-30 06:42 . 2014-07-02 19:42 2556360 ----a-w- c:\windows\system32\nvsvcr.dll 2015-01-30 06:42 . 2014-08-19 14:16 61728 ----a-w- c:\windows\system32\OpenCL.dll 2015-01-30 06:42 . 2015-01-30 06:43 -------- d-----w- c:\programdata\NVIDIA Corporation 2015-01-30 06:29 . 2014-12-13 03:33 115712 ----a-w- c:\windows\system32\ieUnatt.exe 2015-01-29 10:53 . 2015-02-04 03:42 -------- d-----w- c:\programdata\Skype 2015-01-29 10:28 . 2015-01-29 10:30 -------- d-----w- c:\program files\Google 2015-01-29 10:04 . 2012-02-11 05:37 317440 ----a-w- c:\windows\system32\spoolsv.exe 2015-01-29 02:38 . 2014-06-27 01:45 2285056 ----a-w- c:\windows\system32\msmpeg2vdec.dll 2015-01-29 02:37 . 2011-03-11 05:39 143744 ----a-w- c:\windows\system32\drivers\nvstor.sys 2015-01-29 02:37 . 2011-03-11 05:39 117120 ----a-w- c:\windows\system32\drivers\nvraid.sys 2015-01-29 02:37 . 2011-03-11 05:38 80256 ----a-w- c:\windows\system32\drivers\amdsata.sys 2015-01-29 02:37 . 2011-03-11 05:38 22400 ----a-w- c:\windows\system32\drivers\amdxata.sys 2015-01-29 02:37 . 2011-03-11 05:33 1699328 ----a-w- c:\windows\system32\esent.dll 2015-01-29 02:37 . 2011-03-11 05:31 74240 ----a-w- c:\windows\system32\fsutil.exe 2015-01-29 02:37 . 2013-11-23 18:26 417792 ----a-w- c:\windows\system32\WMPhoto.dll 2015-01-29 02:37 . 2014-11-22 01:48 667648 ----a-w- c:\windows\system32\MsSpellCheckingFacility.exe 2015-01-29 02:36 . 2014-06-24 02:59 1987584 ----a-w- c:\windows\system32\d3d10warp.dll 2015-01-29 02:36 . 2011-02-25 05:30 2616320 ----a-w- c:\windows\explorer.exe 2015-01-29 02:36 . 2014-07-09 01:29 6144 ----a-w- c:\windows\system32\KBDYAK.DLL 2015-01-29 02:36 . 2014-07-09 01:29 6144 ----a-w- c:\windows\system32\KBDBASH.DLL 2015-01-29 02:36 . 2013-11-26 08:16 3419136 ----a-w- c:\windows\system32\d2d1.dll 2015-01-28 04:49 . 2015-02-04 05:03 -------- d-----w- c:\windows\Panther 2015-01-27 21:25 . 2015-01-27 21:25 -------- d-s---w- c:\windows\system32\CompatTel 2015-01-27 21:25 . 2015-01-27 21:25 -------- d-----w- c:\windows\system32\appraiser 2015-01-27 19:01 . 2014-10-18 01:33 3209728 ----a-w- c:\windows\system32\mf.dll 2015-01-27 19:01 . 2014-07-07 01:40 103424 ----a-w- c:\windows\system32\mfps.dll 2015-01-27 19:01 . 2014-07-07 01:39 50176 ----a-w- c:\windows\system32\rrinstaller.exe 2015-01-27 19:01 . 2014-07-07 01:39 23040 ----a-w- c:\windows\system32\mfpmp.exe 2015-01-27 19:01 . 2014-07-07 01:37 2048 ----a-w- c:\windows\system32\mferror.dll 2015-01-27 16:28 . 2014-11-11 02:44 1230336 ----a-w- c:\windows\system32\WindowsCodecs.dll 2015-01-27 16:27 . 2013-04-09 23:34 1247744 ----a-w- c:\windows\system32\DWrite.dll 2015-01-27 15:55 . 2010-08-09 14:33 11164 ----a-w- c:\windows\system32\drivers\nvphy.bin 2015-01-27 15:55 . 2015-02-18 22:47 -------- d-----w- c:\program files\NVIDIA Corporation 2015-01-27 15:33 . 2015-01-27 15:35 -------- d-----w- c:\windows\system32\MRT 2015-01-27 14:53 . 2012-07-26 02:33 66560 ----a-w- c:\windows\system32\drivers\WUDFPf.sys 2015-01-27 14:53 . 2012-07-26 02:32 155136 ----a-w- c:\windows\system32\drivers\WUDFRd.sys 2015-01-27 14:53 . 2012-07-26 03:21 196608 ----a-w- c:\windows\system32\WUDFHost.exe 2015-01-27 14:53 . 2012-07-26 03:20 73216 ----a-w- c:\windows\system32\WUDFSvc.dll 2015-01-27 14:53 . 2012-07-26 03:20 613888 ----a-w- c:\windows\system32\WUDFx.dll 2015-01-27 14:53 . 2012-07-26 03:20 38912 ----a-w- c:\windows\system32\WUDFCoinstaller.dll 2015-01-27 14:53 . 2012-07-26 03:20 172032 ----a-w- c:\windows\system32\WUDFPlatform.dll 2015-01-27 14:51 . 2012-03-01 05:46 19824 ----a-w- c:\windows\system32\drivers\fs_rec.sys 2015-01-27 14:51 . 2012-03-01 05:29 5120 ----a-w- c:\windows\system32\wmi.dll 2015-01-27 14:41 . 2015-01-27 14:41 -------- d-----w- c:\windows\Migration 2015-01-27 14:41 . 2015-01-27 14:41 -------- d-----w- c:\program files\Microsoft.NET 2015-01-27 14:38 . 2013-05-10 04:56 12625408 ----a-w- c:\windows\system32\wmploc.DLL 2015-01-27 14:38 . 2013-05-10 03:48 164864 ----a-w- c:\program files\Windows Media Player\wmplayer.exe 2015-01-27 14:29 . 2015-01-27 14:29 231424 ----a-w- c:\windows\system32\mswsock.dll 2015-01-27 14:29 . 2015-01-27 14:29 49152 ----a-w- c:\windows\system32\taskhost.exe 2015-01-27 14:26 . 2015-01-27 14:26 1505280 ----a-w- c:\windows\system32\d3d11.dll 2015-01-27 14:23 . 2014-12-04 04:38 337920 ----a-w- c:\windows\system32\generaltel.dll 2015-01-27 14:23 . 2014-12-04 04:38 610304 ----a-w- c:\windows\system32\invagent.dll 2015-01-27 14:23 . 2014-12-04 04:38 315392 ----a-w- c:\windows\system32\devinv.dll 2015-01-27 14:23 . 2014-12-04 04:38 159744 ----a-w- c:\windows\system32\aepic.dll 2015-01-27 14:23 . 2014-12-04 04:34 873984 ----a-w- c:\windows\system32\aeinv.dll 2015-01-27 14:23 . 2014-12-01 23:28 1160872 ----a-w- c:\windows\system32\aitstatic.exe 2015-01-27 14:23 . 2014-12-04 04:38 202752 ----a-w- c:\windows\system32\aepdu.dll 2015-01-27 14:21 . 2012-10-09 17:40 44032 ----a-w- c:\windows\system32\dhcpcsvc6.dll 2015-01-27 14:20 . 2013-10-05 19:57 1168384 ----a-w- c:\windows\system32\crypt32.dll 2015-01-27 14:19 . 2014-02-04 02:07 149440 ----a-w- c:\windows\system32\drivers\storport.sys 2015-01-27 14:18 . 2010-12-23 05:54 850944 ----a-w- c:\windows\system32\sbe.dll 2015-01-27 14:09 . 2014-10-14 01:56 136632 ----a-w- c:\windows\system32\drivers\ksecpkg.sys 2015-01-27 14:09 . 2014-10-14 01:50 1059840 ----a-w- c:\windows\system32\lsasrv.dll 2015-01-27 14:09 . 2013-07-04 12:16 369848 ----a-w- c:\windows\system32\drivers\cng.sys 2015-01-27 14:09 . 2014-10-14 01:50 523776 ----a-w- c:\windows\system32\termsrv.dll 2015-01-27 14:09 . 2014-10-14 01:47 146432 ----a-w- c:\windows\system32\msaudite.dll 2015-01-27 14:09 . 2014-10-14 01:46 681984 ----a-w- c:\windows\system32\adtschema.dll 2015-01-27 14:09 . 2014-04-12 02:15 67520 ----a-w- c:\windows\system32\drivers\ksecdd.sys 2015-01-27 14:09 . 2014-04-12 02:12 15872 ----a-w- c:\windows\system32\sspisrv.dll 2015-01-27 14:09 . 2014-04-12 02:12 100352 ----a-w- c:\windows\system32\sspicli.dll 2015-01-27 14:09 . 2014-04-12 02:12 22016 ----a-w- c:\windows\system32\secur32.dll 2015-01-27 14:09 . 2014-04-12 02:11 22528 ----a-w- c:\windows\system32\lsass.exe 2015-01-27 14:09 . 2013-02-27 04:49 47104 ----a-w- c:\windows\system32\appinfo.dll 2015-01-27 14:07 . 2014-10-03 01:45 248832 ----a-w- c:\windows\system32\WSManMigrationPlugin.dll 2015-01-27 14:07 . 2014-10-03 01:45 214016 ----a-w- c:\windows\system32\WsmWmiPl.dll 2015-01-27 14:07 . 2014-10-03 01:45 1177088 ----a-w- c:\windows\system32\WsmSvc.dll 2015-01-27 14:07 . 2014-10-03 01:45 145920 ----a-w- c:\windows\system32\WsmAuto.dll 2015-01-27 14:07 . 2014-10-03 01:44 198656 ----a-w- c:\windows\system32\WSManHTTPConfig.exe 2015-01-27 13:20 . 2014-05-14 16:23 45536 ----a-w- c:\windows\system32\wups2.dll 2015-01-27 13:20 . 2014-05-14 16:23 54240 ----a-w- c:\windows\system32\wuauclt.exe 2015-01-27 13:20 . 2014-05-14 16:23 1973728 ----a-w- c:\windows\system32\wuaueng.dll 2015-01-27 13:20 . 2014-05-14 16:17 2425856 ----a-w- c:\windows\system32\wucltux.dll 2015-01-27 13:20 . 2014-05-14 16:23 36320 ----a-w- c:\windows\system32\wups.dll 2015-01-27 13:20 . 2014-05-14 16:23 581600 ----a-w- c:\windows\system32\wuapi.dll 2015-01-27 13:20 . 2014-05-14 16:17 92672 ----a-w- c:\windows\system32\wudriver.dll 2015-01-27 13:20 . 2014-05-14 01:23 179656 ----a-w- c:\windows\system32\wuwebv.dll 2015-01-27 13:20 . 2014-05-14 01:17 33792 ----a-w- c:\windows\system32\wuapp.exe 2015-01-27 13:13 . 2015-02-04 03:42 -------- d-sh--w- c:\windows\Installer 2015-01-27 12:58 . 2015-02-13 04:21 -------- d-----w- c:\users\Jared 2015-01-27 12:58 . 2015-01-27 12:58 -------- d-----w- C:\Recovery . . . (((((((((((((((((((((((((((((((((((((((( Find3M Report )))))))))))))))))))))))))))))))))))))))))))))))))))) . . . ((((((((((((((((((((((((((((((((((((( Reg Loading Points )))))))))))))))))))))))))))))))))))))))))))))))))) . . *Note* empty entries & legit default entries are not shown REGEDIT4 . [HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\policies\system] "ConsentPromptBehaviorAdmin"= 5 (0x5) "ConsentPromptBehaviorUser"= 3 (0x3) "EnableUIADesktopToggle"= 0 (0x0) "SoftwareSASGeneration"= 1 (0x1) . [HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\MsMpSvc] @="Service" . [HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\cdloader] 2014-07-04 16:55 51592 ----a-w- c:\users\Jared\AppData\Roaming\mjusbsp\cdloader2.exe . --- Other Services/Drivers In Memory --- . *NewlyCreated* - MGNWRDBQ *NewlyCreated* - MPKSL889FF405 *NewlyCreated* - NTKFZGEB *Deregistered* - aswHwid *Deregistered* - aswNdisFlt *Deregistered* - aswStm *Deregistered* - mgnwrdbq *Deregistered* - ntkfzgeb *Deregistered* - TrueSight . [HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\svchost] LocalServiceAndNoImpersonation REG_MULTI_SZ SSDPSRV upnphost SCardSvr TBS fdrespub AppIDSvc QWAVE wcncsvc SensrSvc . [HKEY_LOCAL_MACHINE\software\microsoft\active setup\installed components\{8A69D345-D564-463c-AFF1-A69D9E530F96}] 2015-02-04 00:20 1086280 ----a-w- c:\program files\Google\Chrome\Application\40.0.2214.94\Installer\chrmstp.exe . . ------- Supplementary Scan ------- . TCP: DhcpNameServer = 192.168.1.1 . - - - - ORPHANS REMOVED - - - - . ShellIconOverlayIdentifiers-{472083B0-C522-11CF-8763-00608CC02F24} - (no file) AddRemove-CCleaner - c:\program files\CCleaner\uninst.exe AddRemove-NVIDIA Drivers - c:\program files\NVIDIA Corporation\Uninstall\nvuninst.exe AddRemove-NVIDIAStereo - c:\program files\NVIDIA Corporation\3D Vision\nvStInst.exe AddRemove-{B2FE1952-0186-46C3-BAEC-A80AA35AC5B8}_Display.3DVision - c:\program files\NVIDIA Corporation\Installer2\installer.{E7E9AFFA-3599-48FE-80C4-88F1DE6C121C}\NVI2.DLL AddRemove-{B2FE1952-0186-46C3-BAEC-A80AA35AC5B8}_Display.Driver - c:\program files\NVIDIA Corporation\Installer2\installer.{E7E9AFFA-3599-48FE-80C4-88F1DE6C121C}\NVI2.DLL AddRemove-{B2FE1952-0186-46C3-BAEC-A80AA35AC5B8}_Display.Update - c:\program files\NVIDIA Corporation\Installer2\installer.{E7E9AFFA-3599-48FE-80C4-88F1DE6C121C}\NVI2.DLL . . . --------------------- LOCKED REGISTRY KEYS --------------------- . [HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\PCW\Security] @Denied: (Full) (Everyone) . Completion time: 2015-02-19 07:51:20 ComboFix-quarantined-files.txt 2015-02-18 23:51 . Pre-Run: 138,164,621,312 bytes free Post-Run: 138,139,095,040 bytes free . - - End Of File - - 821940A5FCE9D2036E181A23F40CE032 A36C5E4F47E84449FF07ED3517B43A31