Threat Database Browser Hijackers Babylon Search/Toolbar

Babylon Search/Toolbar

By CagedTech in Browser Hijackers

Threat Scorecard

Ranking: 707
Threat Level: 50 % (Medium)
Infected Computers: 280,086
First Seen: October 6, 2010
Last Seen: December 5, 2024
OS(es) Affected: Windows

Aliases

2 security vendors flagged this file as malicious.

Anti-Virus Software Detection
CAT-QuickHeal (Suspicious) - DNAScan
NOD32 probably a variant of Win32/Toolbar.Babylon

SpyHunter Detects & Remove Babylon Search/Toolbar

File System Details

Babylon Search/Toolbar may create the following file(s):
# File Name MD5 Detections
1. BabMaint.exe.vir f64487396ab10165dc80bc15cf854d31 6,389
2. Setup.exe 66b95612ec087ab7840b3c3b707210b6 2,164
3. enhancedNT.dll f8e797036593ac1ede14c79852e9bc2b 1,083
4. NTRedirect.dll a934ff2a498261ba8c18a7a5ce06cb05 952
5. BabMaint.exe.vir e7831e33c81eb10a8f7ba3b608383724 547
6. enhancedNT.dll bb829f5bf7b2ac3bb9d21eca9ebf730a 500
7. enhancedNT.dll.vir e015a11d6002c3498cd92b2cdff64433 137
8. MSGRRU32.dll 6ca07b1d5b99da831d1a44319734fd7c 85
9. AdSubawareRes.dll 8bc26c11d7a06032158876c5604f1296 40
10. BabMaint.exe f94795b3245214d931fc3d7fb5327213 27
11. BabMaint.exe 8a036a0c87533284e1a53a54f8a6204e 22
12. cfgNetM.dll 42f9e833a6b2563e2846ab5dbb41a4d4 19
13. BabMaint.exe a1352cbcd6555d0d92589bc9aa1e73af 15
14. BabMaint.exe 755784964001b1d919c924b58b343cbf 11
15. BabMaint.exe 4dbee88fc025677757c20ff2c9a6c0f2 10
16. BabMaint.exe 108aeb24fed7cb4199925986f7244673 8
17. BabMaint.exe 473e742ce34d4fe3c531b07de334666b 7
18. AgentBabSolution.exe 5a60826873e342a0f9a1c24ffc2b7a39 6
19. CtrlBabSolution.exe 4664d963f2985799031db2fbfb362989 6
20. StartBabSolution.exe e71f3ae803ef34c7df9bc20450d8799e 6
21. BabMaint.exe 96629e985a4f9f57053ba05540a28da6 5
22. BabMaint.exe 770596f3c57a87808cd35d1e7e216db7 5
23. BabMaint.exe ad4f4f4d2181d123af4b8e182e0eaf86 5
24. BabMaint.exe 6bedee062a7e21bed1c0997730d02627 4
25. BabMaint.exe a62d16d2dedf981827cd711121a61cae 4
26. BabMaint.exe 35bd3d05e84aed384eb73529142ada3e 4
27. BabMaint.exe 06d556e90a9c0650a2c901721543fed5 4
28. BabMaint.exe 3ce3d4981da7be69fa138a1d81037bf5 2
29. frobanue.dll ab23bd030204e97933d4c794a312082d 2
30. BabMaint.exe aa82a8d778af30fa968e6ba72fc841f6 2
More files

Registry Details

Babylon Search/Toolbar may create the following registry entry or registry entries:
CLSID
{0ECDF796-C2DC-4d79-A620-CCE0C0A66CC9}
{2EECD738-5844-4a99-B4B6-146BF802613B}
{BDB69379-802F-4eaf-B541-F8DE92DD98DB}
Regexp file mask
%APPDATA%\BabMaint.exe
%PROGRAMFILES%\Mozilla Firefox\searchplugins\babylon.xml
%PROGRAMFILES(x86)%\Mozilla Firefox\searchplugins\babylon.xml
SOFTWARE\BabSolution
Software\BabylonToolbar
Software\Microsoft\Internet Explorer\DOMStorage\babylon.com
Software\Microsoft\Internet Explorer\SearchScopes\{0ECDF796-C2DC-4d79-A620-CCE0C0A66CC9}
SOFTWARE\Microsoft\Tracing\MyBabylonTB_RASAPI32
SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tree\EPUpdater
Software\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{2EECD738-5844-4a99-B4B6-146BF802613B}
SOFTWARE\Wow6432Node\Babylon
SOFTWARE\Wow6432Node\babylontoolbar
SOFTWARE\Wow6432Node\Microsoft\Tracing\MyBabylonTB_RASAPI32
SOFTWARE\Wow6432Node\Microsoft\Tracing\MyBabylonTB_RASMANCS
Software\Wow6432Node\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{2EECD738-5844-4a99-B4B6-146BF802613B}
Run keys
NTRedirect

Directories

Babylon Search/Toolbar may create the following directory or directories:

%APPDATA%\BabSolution
%PROGRAMFILES%\Babylon Toolbar
%PROGRAMFILES%\BabylonToolbar
%PROGRAMFILES(x86)%\Babylon Toolbar
%PROGRAMFILES(x86)%\BabylonToolbar
%TEMP%\mt_ffx\BabylonToolbar
%USERPROFILE%\AppData\LocalLow\BabylonToolbar

URLs

Babylon Search/Toolbar may call the following URLs:

BabylonToolbar
http://isearch.babylon.com/?q=

Trending

Most Viewed

Loading...