Overview |
Summary: |
Adware. Browser Helper Object Hijacker. ILookup is an IE toolbar which adds a search box and link buttons, bookmarks to the Favorites menu (mostly affiliate links) and hijacks both your home page and your Search sidebar. May track your browsing habits and report this info to a central ad server. |
Alias: |
ILookup, i-Lookup/GlobalWebSearch, SearchBus (for I-Lookup/Sbus) |
Category: |
Hijacker: Any software that resets your browser's settings to point to other sites. Hijacks may reroute your info and address requests through an unseen site, capturing that info. In such hijacks, your browser may behave normally, but be slower.
Adware: Software that displays popup/popunder ads when the primary user interface is not visible or which do not appear to be assocaited with the product. Browser Helper Object: (BHO). A component that Internet Explorer will load whenever it starts, shares IE's memory context, can perform any action on the available windows and modules. A BHO can detect events, create windows to display additional information on a viewed page, monitor messages and actions. Microsoft calls it "a spy we send to infiltrate the browser's land." BHOs are not stopped by personal firewalls, because they are seen by the firewall as your browser itself. Some exploits of this technology search all pages you view in IE and replace banner advertisements with other ads. Some monitor and report on your actions. Some change your home page. Toolbar: A group of buttons which perform common tasks. A toolbar for Internet Explorer is nomally located below the menu bar at the top of the form. Toolbars may be created by Browser Helper Objects. |
Variants: |
I-Lookup.AbebI-Lookup.AbsnroI-Lookup.BmebI-Lookup.ChgrgsI-Lookup.DrbrI-Lookup.GWSI-Lookup.InebI-Lookup.SbusI-Lookup.WaebI-Lookup.WinDec32ILookup/Chgrgs uses the file chgrgs.dll. |
Similar Pests: |
Hijacker · Adware · Browser Helper Object · Toolbar |
Origins |
Group: |
iClicks Internet Inc. |
Vendor: |
iClicks Internet Inc. |
By This Group: |
I-Lookup.Abeb · |
Mailing Address: |
Suite 1001, 1166 Alberni Street, Vancouver BC Canada V6E 3Z3 |
Phone: |
(604) 602-1766 |
URL: |
iClicks Internet Inc. Operates the sites http://www.i-lookup.com/ http://www.globalwebsearch.com/ The site http://www.eaffiliateinc.com/ may be affiliated with this group. |
Date of Origin: |
Variants from December, 2002 to July, 2004 |
Distribution |
Distribution: |
Drive-by Download from sites such as http://www.bigmeatycocks.com.
"Success" in a drive-by download will require
IE 6 with security settings set to "low".
Both scripts and an ActiveX accomplish the installation
and subsequent operation. No click on anything on the
page will be required, no warning will be given, and
nothing will be displayed during the installation of
ILookup. Upon reload of IE, you will have a toolbar
that is not visible, and contains no text
Visiting http://www.i-lookup.com
will deliver popups such as those shown below. A click
anywhere on the window will install ILookup.








|
Prevalence: |
I-Lookup: 46.6%I-Lookup.Abeb: 0.1%I-Lookup.Bmeb: 0.6%I-Lookup.Chgrgs: 0.1%I-Lookup.Drbr: 0.1%I-Lookup.GWS: 2.9%I-Lookup.Ineb: 0.2%I-Lookup.Sbus: 0.1%
More Info |
Clot Factor: |
I-Lookup: 6
The "Clot Factor" is a measure of how much a pest "gums up" a machine by adding registry entries, files, and directories. As more objects are placed in a machine, manual removal becomes more difficult and more error-prone. |
Growth: |
I-Lookup: Insufficient data to report growthI-Lookup.Bmeb: Insufficient data to report growth |
Operation |
Advertising: |
Yes. |
Storage Required: |
I-Lookup: at least 17 KBI-Lookup.Abeb: at least 133 KBI-Lookup.Bmeb: at least 229 KBI-Lookup.GWS: at least 257 KBI-Lookup.Sbus: at least 121 KB |
Browser Performance: |
Likely to slow performance of Internet Explorer. |
Risks |
Privacy Issues: |
No. |
Security Issues: |
No. |
Stability Issues: |
Yes. May cause error messages of the type "Explorer has caused an error in ineb.dll...", when using both Internet Explorer and the Windows Explorer. |
Detection and Removal |
Automatic Removal: |
PestPatrol detects this.
PestPatrol removes this.
|
Manual Removal: |
Open the 'Downloaded Program Files' folder in the Windows
folder. Right-click the 'I-Lookup.com Toolbar' object
(Ineb variant), or the 'GlobalWebSearch.com' object
(Gws variant). Click 'Remove'.
Next, open a DOS command prompt window (Start->Programs->Accessories)
and enter the following commands.
For the Ineb variant:
cd "%WinDir%\System"
regsvr32 /u Ineb.dll
for Gws:
cd "%WinDir%\System"
regsvr32 /u GWS.dll
For Chgrgs:
cd "%WinDir%\System"
regsvr32 /u Chgrgs.dll
Use Internet Options | Programs | Reset Web Settings
to get the normal search sidebar back, reset your homepage,
and delete the extra bookmarks added to the Favorites
menu. Use regedit to delete HKEY_CURRENT_USER\Software\ineb.
|
|
Stop Running Processes:
Kill these running processes with Task Manager:
|
|
Remove AutoRun Reference:
Go To the key HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Run.
If you find the value HKEY_CURRENT_USER\software\microsoft\windows\currentversion\run\fqtzkbge, delete it and reboot the machine immediately.
|
|
Unregister DLLs:
Unregister these DLLs with Regsvr32, then reboot:
|
|
Clean Registry:
Remove these registry items (if present) with RegEdit:
|
|
Remove Files:
Remove these files (if present) with Windows Explorer:
|
|
Remove Directories:
Remove these directories (if present) with Windows Explorer:
|
|
Restore Settings:
After following the instructions above, you will still need to restore your original settings and prevent this from happening again. Here''s how.
|
Research |
File Analyses: |
|
More Info: |
AllTheWeb, AltaVista, AOL Search, Ask Jeeves, Google, HotBot, Lycos, LookSmart, MSN, Yahoo! |
Research By: |
Andrew CloverPestPatrol's Pest Research Center |
Last Revised: |
April 03, 2005 |