Home Malware Programs Browser Hijackers Babylon Search/Toolbar

Babylon Search/Toolbar

Posted: October 6, 2010

Threat Metric

Ranking: 678
Threat Level: 5/10
Infected PCs: 657,388
First Seen: October 6, 2010
Last Seen: March 10, 2025
OS(es) Affected: Windows

The Babylon Toolbar is a search engine and translation utility, all rolled up into a single browser-based toolbar. While this description may make Babylon Toolbar sound benign, malware researchers have had the misfortune of noting that Babylon Toolbar includes characteristics that are commonly assigned to browsers, adware and Potentially Unwanted Programs (PUPs). Babylon Toolbar may attempt to avoid deletion by normal methods, changes your search engine settings to promote its own websites and may install itself without your permission. If normal removal methods for browser plugins fail to delete all of the Babylon Toolbar's components, you may also wish to consider deleting Babylon Toolbar with an anti-malware program (along with avoiding suspicious software downloads to dodge a Babylon Toolbar attack entirely).

How Babylon Toolbar Gets Good Publicity for Bad Habits

Babylon Toolbar is promoted at babylon.com as a multipurpose translator and search utility, and you may find Babylon Toolbar included in the installers of unrelated programs – including relatively reputable ones. The most prominent source of accidental Babylon Toolbar installations is general freeware/shareware websites, although Babylon Toolbar may also be bundled in P2P torrenting clients and other software-downloading utilities. Although Babylon Toolbar ostensibly requires your consent prior to its installation, malware experts have taken note of a preponderance of Babylon Toolbar-infected victims who aren't able to recall ever installing Babylon Toolbar in the first place.

Along with its iffy installation practices, Babylon Toolbar also changes your browser's search engine to one of its own sites. SpywareRemove.com malware analysts have found that both isearch.babylon.com and search.babylon.com have been used for this purpose, and Babylon Toolbar's settings changes may prevent you from using alternative search sites. You should attempt to remove the Babylon Toolbar before you try to change these settings back for your browser – lest you experience Babylon Toolbar doing it for you.

Bringing the Babylon Toolbar Tumbling Down

While Babylon Toolbar and its home site are often rated as low-level PC threats, SpywareRemove.com malware researchers note that keeping Babylon Toolbar on your PC or having contact with babylon.com can't be considered harmful or security risks. However, since most people will look askance to being unable to control their own web browser, it's usually recommended that you try to remove Babylon Toolbar unless you're certain that you want its services.

Because Babylon Toolbar has been known to make standard deletion methods needlessly difficult, SpywareRemove.com malware research team recommends using anti-malware software to expedite Babylon Toolbar's banishment from your browser. Babylon Toolbar has been noted for its cross-browser compatibility, and users of everything from Firefox to Internet Explorer to Chrome shouldn't feel safe from an unwanted Babylon Toolbar installer just because of the brand of browser they prefer.

Unusually for adware and as a mark of its relatively professional design, Babylon Toolbar does include compatibility for Mac-based PCs as well as Windows OSes, which makes Babylon Toolbar a potential nuisance for Apple fans, as well.

Aliases

(Suspicious) - DNAScan [CAT-QuickHeal]probably a variant of Win32/Toolbar.Babylon [NOD32]

Use SpyHunter to Detect and Remove PC Threats

If you are concerned that malware or PC threats similar to Babylon Search/Toolbar may have infected your computer, we recommend you start an in-depth system scan with SpyHunter. SpyHunter is an advanced malware protection and remediation application that offers subscribers a comprehensive method for protecting PCs from malware, in addition to providing one-on-one technical support service.

* See Free Trial offer below. EULA and Privacy/Cookie Policy.

Why can't I open any program including SpyHunter? You may have a malware file running in memory that kills any programs that you try to launch on your PC. Tip: Download SpyHunter from a clean computer, copy it to a USB thumb drive, DVD or CD, then install it on the infected PC and run SpyHunter's malware scanner.

Technical Details

File System Modifications

Tutorials: If you wish to learn how to remove malware components manually, you can read the tutorials on how to find malware, kill unwanted processes, remove malicious DLLs and delete other harmful files. Always be sure to back up your PC before making any changes.

The following files were created in the system:



G:\DISCO G\Babylon 9 full + crack\Babylon 9 crack\Babylon.exe File name: Babylon.exe
Size: 3.27 MB (3270072 bytes)
MD5: 5c1ba00a9384b30addea45890814ed2a
Detection count: 5,167
File type: Executable File
Mime Type: unknown/exe
Path: G:\DISCO G\Babylon 9 full + crack\Babylon 9 crack\Babylon.exe
Group: Malware file
Last Updated: August 25, 2024
F:\Users\<username>\AppData\Local\Babylon\Setup\Setup.exe File name: Setup.exe
Size: 1.69 MB (1694832 bytes)
MD5: 66b95612ec087ab7840b3c3b707210b6
Detection count: 5,068
File type: Executable File
Mime Type: unknown/exe
Path: F:\Users\<username>\AppData\Local\Babylon\Setup\Setup.exe
Group: Malware file
Last Updated: August 8, 2024
E:\System Volume Information\_restore{991F3952-AC9B-4ECC-BB98-CAB55920F24E}\RP126\A0028596.exe File name: A0028596.exe
Size: 286.72 KB (286720 bytes)
MD5: 000a83380536df86efe77d020d812f96
Detection count: 4,776
File type: Executable File
Mime Type: unknown/exe
Path: E:\System Volume Information\_restore{991F3952-AC9B-4ECC-BB98-CAB55920F24E}\RP126\A0028596.exe
Group: Malware file
Last Updated: March 4, 2025
D:\System Volume Information\_restore{1517891E-9F8A-45ED-BAA8-DAF6BC57C630}\RP22\A0005709.exe File name: A0005709.exe
Size: 369.66 KB (369664 bytes)
MD5: fd168568d2e6237d9518c1f7c6ba54b5
Detection count: 4,745
File type: Executable File
Mime Type: unknown/exe
Path: D:\System Volume Information\_restore{1517891E-9F8A-45ED-BAA8-DAF6BC57C630}\RP22\A0005709.exe
Group: Malware file
Last Updated: September 12, 2024
D:\System Volume Information\_restore{1517891E-9F8A-45ED-BAA8-DAF6BC57C630}\RP22\A0005705.dll File name: A0005705.dll
Size: 264.19 KB (264192 bytes)
MD5: 6fa16e1d6e2bd1dcd1186f38fe47cdac
Detection count: 4,736
File type: Dynamic link library
Mime Type: unknown/dll
Path: D:\System Volume Information\_restore{1517891E-9F8A-45ED-BAA8-DAF6BC57C630}\RP22\A0005705.dll
Group: Malware file
Last Updated: September 13, 2024
%SYSTEMDRIVE%\AdwCleaner\Quarantine\C\Program Files\BabylonToolbar\BabylonToolbar\1.8.0.7\bh\BabylonToolbar.dll.vir File name: BabylonToolbar.dll.vir
Size: 247.8 KB (247808 bytes)
MD5: 15649e30f8fc5cf90d2469a48429ca01
Detection count: 4,160
Mime Type: unknown/vir
Path: %SYSTEMDRIVE%\AdwCleaner\Quarantine\C\Program Files\BabylonToolbar\BabylonToolbar\1.8.0.7\bh\BabylonToolbar.dll.vir
Group: Malware file
Last Updated: February 21, 2023
F:\BRAZ BACKUP 2013\Braz\AppData\Local\Temp\is701137889\MyBabylonTB.exe File name: MyBabylonTB.exe
Size: 786.58 KB (786584 bytes)
MD5: ac3129819faa20a776239f48e57d2b35
Detection count: 3,398
File type: Executable File
Mime Type: unknown/exe
Path: F:\BRAZ BACKUP 2013\Braz\AppData\Local\Temp\is701137889\MyBabylonTB.exe
Group: Malware file
Last Updated: February 9, 2025
C:\Users\<username>\AppData\Local\Temp\CDCD85F1-BAB0-7891-85DC-7936863F7C0D\Latest\NTRedirect.dll File name: NTRedirect.dll
Size: 121.85 KB (121856 bytes)
MD5: a934ff2a498261ba8c18a7a5ce06cb05
Detection count: 2,230
File type: Dynamic link library
Mime Type: unknown/dll
Path: C:\Users\<username>\AppData\Local\Temp\CDCD85F1-BAB0-7891-85DC-7936863F7C0D\Latest\NTRedirect.dll
Group: Malware file
Last Updated: June 18, 2024
C:\Users\<username>\AppData\Local\BabylonToolbar.exe File name: BabylonToolbar.exe
Size: 794.7 KB (794704 bytes)
MD5: ddee6f5527ddd4a8b3e143c1f340eace
Detection count: 1,963
File type: Executable File
Mime Type: unknown/exe
Path: C:\Users\<username>\AppData\Local\BabylonToolbar.exe
Group: Malware file
Last Updated: March 13, 2023
%SYSTEMDRIVE%\AdwCleaner\Quarantine\C\Users\<username>\AppData\Roaming\BabSolution\Shared\BabMaint.exe.vir File name: BabMaint.exe.vir
Size: 11.12 KB (11120 bytes)
MD5: e7831e33c81eb10a8f7ba3b608383724
Detection count: 1,281
Mime Type: unknown/vir
Path: %SYSTEMDRIVE%\AdwCleaner\Quarantine\C\Users\<username>\AppData\Roaming\BabSolution\Shared\BabMaint.exe.vir
Group: Malware file
Last Updated: September 23, 2024
C:\Users\<username>\AppData\Roaming\BabSolution\Shared\enhancedNT.dll File name: enhancedNT.dll
Size: 187.98 KB (187984 bytes)
MD5: bb829f5bf7b2ac3bb9d21eca9ebf730a
Detection count: 1,171
File type: Dynamic link library
Mime Type: unknown/dll
Path: C:\Users\<username>\AppData\Roaming\BabSolution\Shared\enhancedNT.dll
Group: Malware file
Last Updated: April 3, 2024
%SYSTEMDRIVE%\Documents and Settings\Administrator\Local Settings\Application Data\Torch\User Data\Default\Extensions\eooncjejnppfjjklapaamhcdmjbilmde\1.2_0\BabMaint.x File name: BabMaint.x
Size: 4.09 KB (4096 bytes)
MD5: 7500b7cdf541616d2d64e83b7f8ec896
Detection count: 440
Mime Type: unknown/x
Path: %SYSTEMDRIVE%\Documents and Settings\Administrator\Local Settings\Application Data\Torch\User Data\Default\Extensions\eooncjejnppfjjklapaamhcdmjbilmde\1.2_0\BabMaint.x
Group: Malware file
Last Updated: September 1, 2024
F:\AdwCleaner\Quarantine\C\Documents and Settings\Plácido Guardiola\Datos de programa\BabSolution\Shared\enhancedNT.dll.vir File name: enhancedNT.dll.vir
Size: 187.98 KB (187984 bytes)
MD5: e015a11d6002c3498cd92b2cdff64433
Detection count: 321
Mime Type: unknown/vir
Path: F:\AdwCleaner\Quarantine\C\Documents and Settings\Plácido Guardiola\Datos de programa\BabSolution\Shared\enhancedNT.dll.vir
Group: Malware file
Last Updated: February 25, 2024
%LOCALAPPDATA%\BabSolution\AdSubawareRes.dll File name: AdSubawareRes.dll
Size: 819.2 KB (819200 bytes)
MD5: 8bc26c11d7a06032158876c5604f1296
Detection count: 94
File type: Dynamic link library
Mime Type: unknown/dll
Path: %LOCALAPPDATA%\BabSolution
Group: Malware file
Last Updated: March 6, 2014
%APPDATA%\BabSolution\Shared\BabMaint.exe File name: BabMaint.exe
Size: 10.24 KB (10240 bytes)
MD5: 8a036a0c87533284e1a53a54f8a6204e
Detection count: 52
File type: Executable File
Mime Type: unknown/exe
Path: %APPDATA%\BabSolution\Shared
Group: Malware file
Last Updated: March 6, 2014
%LOCALAPPDATA%\BabSolution\cfgNetM.dll File name: cfgNetM.dll
Size: 19.96 KB (19968 bytes)
MD5: 42f9e833a6b2563e2846ab5dbb41a4d4
Detection count: 44
File type: Dynamic link library
Mime Type: unknown/dll
Path: %LOCALAPPDATA%\BabSolution
Group: Malware file
Last Updated: March 6, 2014
%APPDATA%\BabSolution\AgentBabSolution.exe File name: AgentBabSolution.exe
Size: 345.08 KB (345088 bytes)
MD5: 5a60826873e342a0f9a1c24ffc2b7a39
Detection count: 14
File type: Executable File
Mime Type: unknown/exe
Path: %APPDATA%\BabSolution
Group: Malware file
Last Updated: March 6, 2014
%APPDATA%\BabSolution\CtrlBabSolution.exe File name: CtrlBabSolution.exe
Size: 345.08 KB (345088 bytes)
MD5: 4664d963f2985799031db2fbfb362989
Detection count: 14
File type: Executable File
Mime Type: unknown/exe
Path: %APPDATA%\BabSolution
Group: Malware file
Last Updated: March 6, 2014
%APPDATA%\BabSolution\StartBabSolution.exe File name: StartBabSolution.exe
Size: 302.25 KB (302257 bytes)
MD5: e71f3ae803ef34c7df9bc20450d8799e
Detection count: 14
File type: Executable File
Mime Type: unknown/exe
Path: %APPDATA%\BabSolution
Group: Malware file
Last Updated: March 6, 2014
%LOCALAPPDATA%\BabSolution\uwauewta.dll File name: uwauewta.dll
Size: 652.28 KB (652288 bytes)
MD5: 67e32d31f9e7abe4ac7bf1e0038c53df
Detection count: 5
File type: Dynamic link library
Mime Type: unknown/dll
Path: %LOCALAPPDATA%\BabSolution
Group: Malware file
Last Updated: August 1, 2013
%USERPROFILE%\Local Settings\Application Data\BabSolution\wutpcsyu.dll File name: wutpcsyu.dll
Size: 842.24 KB (842240 bytes)
MD5: 2b3f62cbaee826a99f115d31230383ce
Detection count: 5
File type: Dynamic link library
Mime Type: unknown/dll
Path: %USERPROFILE%\Local Settings\Application Data\BabSolution
Group: Malware file
Last Updated: August 1, 2013
%LOCALAPPDATA%\BabSolution\frobanue.dll File name: frobanue.dll
Size: 475.13 KB (475136 bytes)
MD5: ab23bd030204e97933d4c794a312082d
Detection count: 5
File type: Dynamic link library
Mime Type: unknown/dll
Path: %LOCALAPPDATA%\BabSolution
Group: Malware file
Last Updated: August 1, 2013

More files

Registry Modifications

The following newly produced Registry Values are:

CLSID{0ECDF796-C2DC-4d79-A620-CCE0C0A66CC9}{2EECD738-5844-4a99-B4B6-146BF802613B}{BDB69379-802F-4eaf-B541-F8DE92DD98DB}Regexp file mask%APPDATA%\BabMaint.exe%PROGRAMFILES%\Mozilla Firefox\searchplugins\babylon.xml%PROGRAMFILES(x86)%\Mozilla Firefox\searchplugins\babylon.xmlHKEY..\..\..\..{RegistryKeys}SOFTWARE\BabSolutionSoftware\BabylonToolbarSoftware\Microsoft\Internet Explorer\DOMStorage\babylon.comSoftware\Microsoft\Internet Explorer\SearchScopes\{0ECDF796-C2DC-4d79-A620-CCE0C0A66CC9}SOFTWARE\Microsoft\Tracing\MyBabylonTB_RASAPI32SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tree\EPUpdaterSoftware\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{2EECD738-5844-4a99-B4B6-146BF802613B}SOFTWARE\Wow6432Node\BabylonSOFTWARE\Wow6432Node\babylontoolbarSOFTWARE\Wow6432Node\Microsoft\Tracing\MyBabylonTB_RASAPI32SOFTWARE\Wow6432Node\Microsoft\Tracing\MyBabylonTB_RASMANCSSoftware\Wow6432Node\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{2EECD738-5844-4a99-B4B6-146BF802613B}Run keysNTRedirectHKEY_LOCAL_MACHINE\Software\[APPLICATION]\Microsoft\Windows\CurrentVersion\Uninstall..{Uninstaller}BabylonToolbar

Additional Information

The following directories were created:
%APPDATA%\BabSolution%PROGRAMFILES%\Babylon Toolbar%PROGRAMFILES%\BabylonToolbar%PROGRAMFILES(x86)%\Babylon Toolbar%PROGRAMFILES(x86)%\BabylonToolbar%TEMP%\mt_ffx\BabylonToolbar%USERPROFILE%\AppData\LocalLow\BabylonToolbar
The following URL's were detected:
BabylonToolbarisearch.babylon.com
Loading...
Spywareremove.com uses cookies to provide you with a better browsing experience and analyze how users navigate and utilize the Site. By using this Site or clicking on "OK", you consent to the use of cookies. Learn more.