PC Support Guide:  Parasites > Hijacker >

I-Lookup

Previous pageReturn to chapter overviewNext page

Hijacker

 

Click2FindNow and I-Lookup are homepage hijacking programs that change the IE homepage and search pages resulting in many pop-up ads. They will also add bookmarks to the Favorites menu in IE and in most cases a toolbar as well. Both sites are run by a company called Aztec Marketing SA in San Jose, Costa Rica. I-Lookup also may set the homepage to globalwebsearch.com in some versions. All appear to be installed by an ActiveX download.

 

As with Click2FindNow, I-Lookup.com has its own uninstaller on its site buried in a FAQ. Visit the link below to download and run the I-Lookup.com uninstaller.

http://www.i-lookup.com/uninstall.exe

 

newer variation of their toolbar

http://www.i-lookup.com/uninstall2.exe

 

Manual Removal Instructions

Here are manual instructions to the best of my knowledge for uninstalling the different variants of I-Lookup.com

 

Remove the Active X component (may have to be done in Windows Safe Mode)
Double-click on the "Downloaded Program Files" folder in the Windows folder
Right click on
I-Lookup.com Bar or toolbar (Abeb and Ineb variants)
GlobalWebSearch.com Bar (Gws and Chgrgs variants)
GlobalToolbar.com (Drbr variant)
Search Bar (Bmeb variant)
SearchBus.com (Sbus variant)
Click on Remove and delete the file

 

Open a Dos prompt
For Windows 95/98/ME, click on Start, Run, and Type COMMAND and Click OK
For Windows XP/2000, click on Start, Run, and Type CMD and Click Ok

 

Unregister the offending DLL file by typing the following lines at the DOS Prompt (pressing Enter after each line)

 

Abeb variant

cd "%WinDir%\System"

regsvr32 /u abeb.dll

 

Bmeb variant

cd "%WinDir%\System"

regsvr32 /u bmeb.dll

 

Chgrgs variant

cd "%WinDir%\System"

regsvr32 /u chgrgs.dll

 

Drbr variant

cd "%WinDir%\System"

regsvr32 /u drbr.dll

 

Gws variant

cd "%WinDir%\System"

regsvr32 /u gws.dll

 

Ineb variant

cd "%WinDir%\System"

regsvr32 /u ineb.dll

 

Sbus variant

cd "%WinDir%\System"

regsvr32 /u sbus.dll

 

Type EXIT and Press Enter to close the DOS prompt

 

Reset Web Settings in Internet Explorer (homepage and search page)
In Internet Explorer, click on Tools, Internet Options
Click on the Programs tab
Click on Reset Web Settings

 

Remove Registry Entries
Click on Start, Run, and type REGEDIT and click OK
Click the pluses(+) next to
HKey_Current_User
Software
Right Click on the Ineb folder and click Delete

 

Lastly, use a spyware removal program (like SpyBot S&D) to clean up any bits and pieces left from the infection.

 


Previous page - Chapter overview - Next page

 


Page url: http://www.tje.net/PCSupport/index.html?i_lookup.htm
Page content was last updated: 10/6/2008



Website designed and created by TJ Elias - Houston, Texas
090424 * Copyright(c) 1996-2009 TJ Elias