The Wiert Corner – irregular stream of stuff

Jeroen W. Pluimers on .NET, C#, Delphi, databases, and personal interests

  • My badges

  • Twitter Updates

  • My Flickr Stream

  • Pages

  • All categories

  • Enter your email address to subscribe to this blog and receive notifications of new posts by email.

    Join 4,152 other subscribers

Chrome Google search URLs changed into a webhp redirect; no rootkit; Avast! and eggheadcafe seem involved; reproducible on one machine. What happened?

Posted by jpluimers on 2012/02/16

Somewhere the last couple of days, Google or Google Chrome has changed the default search URL.

I thought I had a webhp rootkit issue, possibly related to Avast, but it wasn’t (I posted at the Avast forums, and later replied the issue had solved itself, but I still wonder about the real cause).

What happened was that some page I had open in Google Chrome (all other web browsers were fine) forced the redirect.

I can only reproduce this on one system (that has both Avast! Antivirus installed, and Chrome open with the page http://www.eggheadcafe.com/searchform.aspx?search=Cross+Join+Excel) but not on other machines.

So far, it took me about a day of work (quarantining the machine, investigating if it was a virus, rootkit or otherwise, trying to verify this is a one off), and I still feel I don’t have the complete answer yet.

I still wonder if others have seen similar issues.

This is how it redirected

The defaults have a truckload of junk around them, but come down to the URLs below (lmgtfy is the search phrase)

It used to be of this form (which now again works, after I closed all Google Chrome pages)

The redirect made it into a longer webhp form:

The fun thing is, that if you enter the form

then you will end at the Google Search home page with the search phrase pre-filled in.
Now that is a pretty nifty “let me Google that for you” :)

–jeroen

via: Google.

Leave a Reply

Fill in your details below or click an icon to log in:

WordPress.com Logo

You are commenting using your WordPress.com account. Log Out /  Change )

Twitter picture

You are commenting using your Twitter account. Log Out /  Change )

Facebook photo

You are commenting using your Facebook account. Log Out /  Change )

Connecting to %s

This site uses Akismet to reduce spam. Learn how your comment data is processed.

 
%d bloggers like this: