Case of the Facebook Chat Phone–The Homepage That Wouldn’t Go Away

My wife downloaded a program promoted through Facebook advertised as “Facebook Phone Chat” The software now removed I couldn’t analyse it for malicious content, however it did leave some trademarks. It set the home page to

http://search.chatphonesearch.com/

On IE9 this was removed no problem. However on Google Chrome it was a bit more tough.

The home page settings appeared to be set to Google

image

Switching this to http://www.bing.com reloading Chrome, then back to http://www.google.com.au seemed to fix this issue. (Bing you are getting better all the time but until we see full functionality here in Australia you’ll have to wait as the default homepage)

However now new tabs were still opening with the chatphonesearch page.

Looking through all the config options/settings pages I could not find the setting for home page.

I set a filter to include events where Process is chrome.exe

I saw the following redirect HTML

image

And it contained the code

image

I checked Google Extensions and all were disabled (I had done this in previous troubleshooting steps)

image

So I just deleted the folder

image

 

Now I got this error:

image

So then looking at files opened by ProcMon I notice the Preferences file. I open it in notepad. Ah found the bad little thing.

image

Actually it had spread itself throughout the Preferences file in multiple places. Deleting the file then..

image

All gone, no more issue. (note latest Google Chrome lets you configure new tab through user interface)

About chentiangemalc

specializes in end-user computing technologies. disclaimer 1) use at your own risk. test any solution in your environment. if you do not understand the impact/consequences of what you're doing please stop, and ask advice from somebody who does. 2) views are my own at the time of posting and do not necessarily represent my current view or the view of my employer and family members/relatives. 3) over the years Microsoft/Citrix/VMWare have given me a few free shirts, pens, paper notebooks/etc. despite these gifts i will try to remain unbiased.
This entry was posted in Internet Explorer, ProcMon, Troubleshooting and tagged . Bookmark the permalink.

Leave a Reply

Fill in your details below or click an icon to log in:

WordPress.com Logo

You are commenting using your WordPress.com account. Log Out / Change )

Twitter picture

You are commenting using your Twitter account. Log Out / Change )

Facebook photo

You are commenting using your Facebook account. Log Out / Change )

Google+ photo

You are commenting using your Google+ account. Log Out / Change )

Connecting to %s