Hijacker
Click2FindNow and I-Lookup are homepage hijacking programs that change the IE homepage and search pages resulting in many pop-up ads. They will also add bookmarks to the Favorites menu in IE and in most cases a toolbar as well. Both sites are run by a company called Aztec Marketing SA in San Jose, Costa Rica. I-Lookup also may set the homepage to globalwebsearch.com in some versions. All appear to be installed by an ActiveX download.
As with Click2FindNow, I-Lookup.com has its own uninstaller on its site buried in a FAQ. Visit the link below to download and run the I-Lookup.com uninstaller.
http://www.i-lookup.com/uninstall.exe
newer variation of their toolbar
http://www.i-lookup.com/uninstall2.exe
Manual Removal Instructions
Here are manual instructions to the best of my knowledge for uninstalling the different variants of I-Lookup.com
| • | Remove the Active X component (may have to be done in Windows Safe Mode) |
| • | Double-click on the "Downloaded Program Files" folder in the Windows folder |
| • | Right click on |
| • | I-Lookup.com Bar or toolbar (Abeb and Ineb variants) |
| • | GlobalWebSearch.com Bar (Gws and Chgrgs variants) |
| • | GlobalToolbar.com (Drbr variant) |
| • | Search Bar (Bmeb variant) |
| • | SearchBus.com (Sbus variant) |
| • | Click on Remove and delete the file |
| • | Open a Dos prompt |
| • | For Windows 95/98/ME, click on Start, Run, and Type COMMAND and Click OK |
| • | For Windows XP/2000, click on Start, Run, and Type CMD and Click Ok |
| • | Unregister the offending DLL file by typing the following lines at the DOS Prompt (pressing Enter after each line) |
Abeb variant
cd "%WinDir%\System"
regsvr32 /u abeb.dll
Bmeb variant
cd "%WinDir%\System"
regsvr32 /u bmeb.dll
Chgrgs variant
cd "%WinDir%\System"
regsvr32 /u chgrgs.dll
Drbr variant
cd "%WinDir%\System"
regsvr32 /u drbr.dll
Gws variant
cd "%WinDir%\System"
regsvr32 /u gws.dll
Ineb variant
cd "%WinDir%\System"
regsvr32 /u ineb.dll
Sbus variant
cd "%WinDir%\System"
regsvr32 /u sbus.dll
Type EXIT and Press Enter to close the DOS prompt
| • | Reset Web Settings in Internet Explorer (homepage and search page) |
| • | In Internet Explorer, click on Tools, Internet Options |
| • | Click on the Programs tab |
| • | Click on Reset Web Settings |
| • | Remove Registry Entries |
| • | Click on Start, Run, and type REGEDIT and click OK |
| • | Click the pluses(+) next to |
| • | HKey_Current_User |
| • | Software |
| • | Right Click on the Ineb folder and click Delete |
Lastly, use a spyware removal program (like SpyBot S&D) to clean up any bits and pieces left from the infection.
Page url:
http://www.tje.net/PCSupport/index.html?i_lookup.htm
Page content was last updated: 10/6/2008
|
|