sweetpacks will not go away, embedded in the "internet" hotkey?

cubby1223

Lifer
May 24, 2004
13,518
42
86
I was working with a laptop today, ran a ton of scans, anti-virus, malwarebytes, combofix, tdsskiller, hijackthis, etc. etc. and one behavior is not being picked up on by any of them.

It's an HP laptop and it has an "internet" hotkey on the F5 key. So when you hit the F5 key, your default browser opens up to your homepage. Now here's the twist - when Google Chrome is already open, hitting the F5 key now loads the sweetpacks website into the browser window. I can't even figure out the proper keywords to search google for this issue. I've run through the registry and removed all references to sweetpacks. I've run through the program files directory and removed any abnormal directories left undetected by above scans. I've manually set all default search engines to google.

The only thing I could effectively do was add sweetpacks(dot)com to the hosts file and prevent the browsers from translating the address correctly.

Beyond this one behavior, there is nothing else unusual about the system. Has anyone seem this? Thanks.
 

cubby1223

Lifer
May 24, 2004
13,518
42
86
Is it set as the browser's home page(in Chrome settings)?

No, I made sure to update Chrome's homepage to google.com. When Chrome is closed, the hotkey opens Chrome and it's normal startpage is displayed. It's when the hotkey is pressed while Chrome is open, it redirects to sweetpacks.

I didn't try it because I didn't want to mess up the settings they had in the browser, but I wonder if a complete wipe of Chrome & the profile, and a fresh new install would have corrected it. That'll be my first experiment when I get the laptop again tomorrow.
 

Fardringle

Diamond Member
Oct 23, 2000
9,200
765
126
Right-click on the browser shortcut, then choose Properties. Make sure the "target" is only the path to the browser exe file itself and doesn't have the sweetpacks URL tied in at the end. I've seen that several times recently.