Adware. Browser Helper Object Hijacker. ILookup is an IE toolbar which adds a search box and link buttons, bookmarks to the Favorites menu (mostly affiliate links) and hijacks both your home page and your Search sidebar. May track your browsing habits and report this info to a central ad server.

">


I-Lookup


· Overview ·
· Origins ·
· Distribution ·
· Operation ·
· Risks ·
· Detection and Removal ·
· Research ·



Overview

Summary:

Adware. Browser Helper Object Hijacker. ILookup is an IE toolbar which adds a search box and link buttons, bookmarks to the Favorites menu (mostly affiliate links) and hijacks both your home page and your Search sidebar. May track your browsing habits and report this info to a central ad server.

Alias:

ILookup, i-Lookup/GlobalWebSearch, SearchBus (for I-Lookup/Sbus)

Category:

Hijacker: Any software that resets your browser's settings to point to other sites. Hijacks may reroute your info and address requests through an unseen site, capturing that info. In such hijacks, your browser may behave normally, but be slower.

Adware: Software that displays popup/popunder ads when the primary user interface is not visible or which do not appear to be assocaited with the product.

Browser Helper Object: (BHO). A component that Internet Explorer will load whenever it starts, shares IE's memory context, can perform any action on the available windows and modules. A BHO can detect events, create windows to display additional information on a viewed page, monitor messages and actions. Microsoft calls it "a spy we send to infiltrate the browser's land." BHOs are not stopped by personal firewalls, because they are seen by the firewall as your browser itself. Some exploits of this technology search all pages you view in IE and replace banner advertisements with other ads. Some monitor and report on your actions. Some change your home page.

Toolbar: A group of buttons which perform common tasks. A toolbar for Internet Explorer is nomally located below the menu bar at the top of the form. Toolbars may be created by Browser Helper Objects.

Variants:

  • I-Lookup.Abeb
  • I-Lookup.Absnro
  • I-Lookup.Bmeb
  • I-Lookup.Chgrgs
  • I-Lookup.Drbr
  • I-Lookup.GWS
  • I-Lookup.Ineb
  • I-Lookup.Sbus
  • I-Lookup.Waeb
  • I-Lookup.WinDec32
  • ILookup/Chgrgs uses the file chgrgs.dll.
  • Similar Pests:

    Hijacker · Adware · Browser Helper Object · Toolbar

    Origins

    Group:

    iClicks Internet Inc.

    Vendor:

    iClicks Internet Inc.

    By This Group:

    I-Lookup.Abeb ·

    Mailing Address:

    Suite 1001, 1166 Alberni Street, Vancouver BC Canada V6E 3Z3

    Phone:

    (604) 602-1766

    URL:

    iClicks Internet Inc. Operates the sites http://www.i-lookup.com/ http://www.globalwebsearch.com/ The site http://www.eaffiliateinc.com/ may be affiliated with this group.

    Date of Origin:

    Variants from December, 2002 to July, 2004

    Distribution

    Distribution:

    Drive-by Download from sites such as http://www.bigmeatycocks.com. "Success" in a drive-by download will require IE 6 with security settings set to "low". Both scripts and an ActiveX accomplish the installation and subsequent operation. No click on anything on the page will be required, no warning will be given, and nothing will be displayed during the installation of ILookup. Upon reload of IE, you will have a toolbar that is not visible, and contains no text

    Visiting http://www.i-lookup.com will deliver popups such as those shown below. A click anywhere on the window will install ILookup.

    Prevalence:

  • I-Lookup: 46.6%
  • I-Lookup.Abeb: 0.1%
  • I-Lookup.Bmeb: 0.6%
  • I-Lookup.Chgrgs: 0.1%
  • I-Lookup.Drbr: 0.1%
  • I-Lookup.GWS: 2.9%
  • I-Lookup.Ineb: 0.2%
  • I-Lookup.Sbus: 0.1%
  • More Info

    Clot Factor:

  • I-Lookup: 6
  • The "Clot Factor" is a measure of how much a pest "gums up" a machine by adding registry entries, files, and directories. As more objects are placed in a machine, manual removal becomes more difficult and more error-prone.

    Growth:

  • I-Lookup: Insufficient data to report growth
  • I-Lookup.Bmeb: Insufficient data to report growth
  • Operation

    Advertising:

    Yes.

    Storage Required:

  • I-Lookup: at least 17 KB
  • I-Lookup.Abeb: at least 133 KB
  • I-Lookup.Bmeb: at least 229 KB
  • I-Lookup.GWS: at least 257 KB
  • I-Lookup.Sbus: at least 121 KB
  • Browser Performance:

    Likely to slow performance of Internet Explorer.

    Risks

    Privacy Issues:

    No.

    Security Issues:

    No.

    Stability Issues:

    Yes. May cause error messages of the type "Explorer has caused an error in ineb.dll...", when using both Internet Explorer and the Windows Explorer.

    Detection and Removal

    Automatic Removal:

    PestPatrol detects this.

    PestPatrol removes this.



    Manual Removal:

    Open the 'Downloaded Program Files' folder in the Windows folder. Right-click the 'I-Lookup.com Toolbar' object (Ineb variant), or the 'GlobalWebSearch.com' object (Gws variant). Click 'Remove'.

    Next, open a DOS command prompt window (Start->Programs->Accessories) and enter the following commands.

    For the Ineb variant:

    cd "%WinDir%\System"
    regsvr32 /u Ineb.dll

    for Gws:

    cd "%WinDir%\System"
    regsvr32 /u GWS.dll


    For Chgrgs:

    cd "%WinDir%\System"
    regsvr32 /u Chgrgs.dll

    Use Internet Options | Programs | Reset Web Settings to get the normal search sidebar back, reset your homepage, and delete the extra bookmarks added to the Favorites menu. Use regedit to delete HKEY_CURRENT_USER\Software\ineb.

    Stop Running Processes:

    Kill these running processes with Task Manager:

    Remove AutoRun Reference:

    Go To the key HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Run.
    If you find the value HKEY_CURRENT_USER\software\microsoft\windows\currentversion\run\fqtzkbge, delete it and reboot the machine immediately.



    Unregister DLLs:

    Unregister these DLLs with Regsvr32, then reboot:

    Clean Registry:

    Remove these registry items (if present) with RegEdit:

    Remove Files:

    Remove these files (if present) with Windows Explorer:

    Remove Directories:

    Remove these directories (if present) with Windows Explorer:

    Restore Settings:

    After following the instructions above, you will still need to restore your original settings and prevent this from happening again. Here''s how.

    Research

    File Analyses:

    More Info:

  • AllTheWeb, AltaVista, AOL Search, Ask Jeeves, Google, HotBot, Lycos, LookSmart, MSN, Yahoo!
  • Research By:

  • Andrew Clover
  • PestPatrol's Pest Research Center
  • Last Revised:

    April 03, 2005