Chrome addon can't be removed

For a few months now at very random intervals avast pops up and says I have a Chrome addon called “Whois This!” and I have searched and searched and searched all over the internet, through all of my files and with no success have I found anything about it. I would like to completely remove it so that I don’t have to keep having avast remove the file. I have searched all of my programs and uninstalled everything that is it could possibly be a part of and reinstalled looking for automated software installs that a lot of programs sneak in now and still haven’t found anything. I have uninstalled chrome and deleted all of it’s files and when I reinstall it just comes back. If anyone has had an issue with this addon help would be greatly appreciated.

Instructions https://forum.avast.com/index.php?topic=53253.0
Attach Malwarebytes and Farbar Recovery Scan Tool logs … 3 logs total

See below the box you write in … Attachments and other options

when done a malware expert will assist you

Attached are all three logs

This should kill it

CAUTION : This fix is only valid for this specific machine, using it on another may break your computer

Open notepad and copy/paste the text in the quotebox below into it:

CreateRestorePoint: ShellIconOverlayIdentifiers: [GDriveSharedOverlay] -> {81539FE6-33C7-4CE7-90C7-1C7B8F2F2D44} => No File Startup: C:\Users\Conrad\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\GameVox.lnk [2015-02-06] ShortcutTarget: GameVox.lnk -> C:\Program Files (x86)\GameVox\GameVox.exe (No File) HKLM\SOFTWARE\Policies\Microsoft\Internet Explorer: Restriction <======= ATTENTION CHR StartupUrls: Default -> "hxxp://us.yhs4.search.yahoo.com/yhs/web?hspart=iry&hsimp=yhs-fullyhosted_003&type=wny_ir_15_17&param1=1&param2=f%3D7%26b%3DChrome%26cc%3Dus%26pa%3DWinYahoo%26cd%3D2XzuyEtN2Y1L1Qzu0FtDyE0D0AtByE0DtByBzz0C0FzyyE0AtN0D0Tzu0StCtBtDyBtN1L2XzutAtFtCtDtFyEtFtDtN1L1CzutN1L1G1B1V1N2Y1L1Qzu2StB0C0FtD0C0EtDyEtGtA0EtByEtGtCtB0F0FtGyC0FyE0AtGtCzztA0DyE0DyE0A0AyC0CtC2QtN1M1F1B2Z1V1N2Y1L1Qzu2SyCyD0DyE0CyEtAzytG0EzzyEyEtGyE0AtCtCtG0BzyyDzytGyC0AyE0E0EyEyByEtAtAtDzz2QtN0A0LzuyEtN1B2Z1V1T1S1NzuyBtBtC%26cr%3D1852543692%26a%3Dwny_ir_15_17%26os%3DWindows 7 Home Premium","hxxp://us.yhs4.search.yahoo.com/yhs/web?hspart=iry&hsimp=yhs-fullyhosted_003&type=wny_ir_15_17&param1=1&param2=f%3D7%26b%3DChrome%26cc%3Dus%26pa%3DWinYahoo%26cd%3D2XzuyEtN2Y1L1Qzu0FtDyE0D0AtByE0DtByBzz0C0FzyyE0AtN0D0Tzu0StCtBtDyBtN1L2XzutAtFtCtDtFtBtFtDtN1L1CzutN1L1G1B1V1N2Y1L1Qzu2SyCyB0C0F0FtDyByDtG0EyDyBzztGyByC0EyDtGzztBtDyEtGtA0CyC0EtC0CyCtA0E0F0DtA2QtN1M1F1B2Z1V1N2Y1L1Qzu2StBtAzy0A0A0BtAzztGyEzy0E0AtGyE0ByByBtGzz0B0A0CtG0Fzy0F0F0AyCyEyDzztA0D0E2QtN0A0LzuyEtN1B2Z1V1T1S1NzuyBtBtA%26cr%3D1161121011%26a%3Dwny_ir_15_17%26os%3DWindows 7 Home Premium" CHR Extension: (Whois this!!) - C:\Users\Conrad\AppData\Local\Google\Chrome\User Data\Default\Extensions\kikjpgpbpnapbimplfcbcbakjacpgceb [2015-09-20] CustomCLSID: HKU\S-1-5-21-493614254-1807550893-1391507204-1001_Classes\CLSID\{1423F872-3F7F-4E57-B621-8B1A9D49B448}\InprocServer32 -> C:\Users\Conrad\AppData\Local\Google\Update\1.3.27.5\psuser_64.dll No File CustomCLSID: HKU\S-1-5-21-493614254-1807550893-1391507204-1001_Classes\CLSID\{5C8C2A98-6133-4EBA-BBCC-34D9EA01FC2E}\InprocServer32 -> C:\Users\Conrad\AppData\Local\Google\Update\1.3.28.1\psuser_64.dll No File CustomCLSID: HKU\S-1-5-21-493614254-1807550893-1391507204-1001_Classes\CLSID\{78550997-5DEF-4A8A-BAF9-D5774E87AC98}\InprocServer32 -> C:\Users\Conrad\AppData\Local\Google\Update\1.3.28.13\psuser_64.dll No File CustomCLSID: HKU\S-1-5-21-493614254-1807550893-1391507204-1001_Classes\CLSID\{C3BC25C0-FCD3-4F01-AFDD-41373F017C9A}\InprocServer32 -> C:\Users\Conrad\AppData\Local\Google\Update\1.3.26.9\psuser_64.dll No File Task: {9D2AABC2-5542-4B4B-BEDE-99E6EAB4C3C0} - System32\Tasks\{56EE28A9-8729-4BA4-B43A-3237D81781B8} => pcalua.exe -a C:\Users\Conrad\Downloads\setup.exe -d C:\Users\Conrad\Downloads Task: {CC5251D1-FE12-4B85-8778-A0A13D804FAA} - System32\Tasks\{F5BC1D83-2F0E-4AF8-9B6E-68FCA6304D7C} => pcalua.exe -a "C:\Users\Conrad\Downloads\setup (1).exe" -d C:\Users\Conrad\Downloads RemoveProxy: EmptyTemp: CMD: bitsadmin /reset /allusers

Save this as fixlist.txt, in the same location as FRST.exe

https://dl.dropboxusercontent.com/u/73555776/FRSTfix.JPG

Run FRST and press Fix
On completion a log will be generated please post that

THEN

Please download AdwCleaner by Xplode onto your desktop.

[*]Close all open programs and internet browsers.
[*]Double click on AdwCleaner.exe to run the tool.
[*]Click on Scan.
[*]After the scan is complete click on “Clean”
[*]Confirm each time with Ok.
[*]Your computer will be rebooted automatically. A text file will open after the restart.
[*]Please post the content of that logfile with your next answer.
[*]You can find the logfile at C:\AdwCleaner[S0].txt as well.

I apologize it took some time, was sent out of town for a few days suddenly.

Attached are the two files.

How is the computer behaving now ?

Well I did all of that right before bed last night. Turned the computer on this morning and avast popped up wanting to remove the addon.

Attached a screen cap of avast. I wont remove it for the time being to see if you want me to run a scan prior to doing so.

Let me guess you have Chrome set to synch… Every time you start Chrome it will download it again

So could you turn off synch and then run a fresh FRST scan

Done

CAUTION : This fix is only valid for this specific machine, using it on another may break your computer

Open notepad and copy/paste the text in the quotebox below into it:

CreateRestorePoint: CHR StartupUrls: Default -> "hxxp://us.yhs4.search.yahoo.com/yhs/web?hspart=iry&hsimp=yhs-fullyhosted_003&type=wny_ir_15_17&param1=1&param2=f%3D7%26b%3DChrome%26cc%3Dus%26pa%3DWinYahoo%26cd%3D2XzuyEtN2Y1L1Qzu0FtDyE0D0AtByE0DtByBzz0C0FzyyE0AtN0D0Tzu0StCtBtDyBtN1L2XzutAtFtCtDtFyEtFtDtN1L1CzutN1L1G1B1V1N2Y1L1Qzu2StB0C0FtD0C0EtDyEtGtA0EtByEtGtCtB0F0FtGyC0FyE0AtGtCzztA0DyE0DyE0A0AyC0CtC2QtN1M1F1B2Z1V1N2Y1L1Qzu2SyCyD0DyE0CyEtAzytG0EzzyEyEtGyE0AtCtCtG0BzyyDzytGyC0AyE0E0EyEyByEtAtAtDzz2QtN0A0LzuyEtN1B2Z1V1T1S1NzuyBtBtC%26cr%3D1852543692%26a%3Dwny_ir_15_17%26os%3DWindows 7 Home Premium","hxxp://us.yhs4.search.yahoo.com/yhs/web?hspart=iry&hsimp=yhs-fullyhosted_003&type=wny_ir_15_17&param1=1&param2=f%3D7%26b%3DChrome%26cc%3Dus%26pa%3DWinYahoo%26cd%3D2XzuyEtN2Y1L1Qzu0FtDyE0D0AtByE0DtByBzz0C0FzyyE0AtN0D0Tzu0StCtBtDyBtN1L2XzutAtFtCtDtFtBtFtDtN1L1CzutN1L1G1B1V1N2Y1L1Qzu2SyCyB0C0F0FtDyByDtG0EyDyBzztGyByC0EyDtGzztBtDyEtGtA0CyC0EtC0CyCtA0E0F0DtA2QtN1M1F1B2Z1V1N2Y1L1Qzu2StBtAzy0A0A0BtAzztGyEzy0E0AtGyE0ByByBtGzz0B0A0CtG0Fzy0F0F0AyCyEyDzztA0D0E2QtN0A0LzuyEtN1B2Z1V1T1S1NzuyBtBtA%26cr%3D1161121011%26a%3Dwny_ir_15_17%26os%3DWindows 7 Home Premium" RemoveProxy: EmptyTemp: CMD: bitsadmin /reset /allusers

Save this as fixlist.txt, in the same location as FRST.exe

https://dl.dropboxusercontent.com/u/73555776/FRSTfix.JPG

Run FRST and press Fix
On completion a log will be generated please post that

THEN

Please download Junkware Removal Tool to your desktop.

[]Right-mouse click JRT.exe and select “Run as Administrator” the tool will open and start scanning your system
[
]please be patient as this can take a while to complete depending on your system’s specifications
[]On completion, a log (JRT.txt) is saved to your desktop and will automatically open.
[
]post the contents of JRT.txt into your next message.

Done

How is the computer now ?

After a restart the addon hasn’t popped back up. Will let you know if something changes. I’ll be going out of town for a month so it may be some time.