babylontoolbar.dll

Babylon Toolbar

Babylon BHO

This is part of the Babylon web browser toolbar and extension that will modify the browser's default search provider, DNS, and home page functions. The module babylontoolbar.dll has been detected as adware by 5 anti-malware scanners. It is installed within the context of Internet Explore as a BHO (Browser Helper Object) under the name ‘Babylon toolbar helper’. This will display context specific advertisements in the browser as well as attempt to modify the browser's search provider.
Publisher:
Babylon BHO

Product:
Babylon Toolbar

Version:
1.6.9.0

MD5:
0f429ee965e10d61b13e9a265ec9edab

SHA-1:
350d871e6b6ce5bbd923b7b100a7949662651e42

SHA-256:
5b954f5656fe6e8e49aedd8badfaad962fc2bdc1a379e4342dc7127b0a252f9d

Scanner detections:
5 / 68

Status:
Adware

Analysis date:
4/25/2024 7:38:39 PM UTC  (today)

Scan engine
Detection
Engine version

AVG
Skodna.Generic
2015.0.3578

Boost by Reason
Optional.BHO.BabylonBHO.O
188163

ESET NOD32
Win32/Toolbar.Escort (variant)
8.9360

Reason Heuristics
PUP.BHO.BabylonBHO.O
14.2.25.3

SUPERAntiSpyware
PUP.BabylonToolbar
10813

File size:
258 KB (264,192 bytes)

Product version:
1.6.9.0

Copyright:
(c) Babylon Ltd. All rights reserved.

File type:
Dynamic link library (Win32 DLL)

Language:
Hebrew (Israel)

Common path:
C:\Program Files\babylontoolbar\babylontoolbar\1.6.9.12\bh\babylontoolbar.dll

Registration
CLSIDs:
{2EECD738-5844-4a99-B4B6-146BF802613B}, {97F2FF5B-260C-4ccf-834A-2DDA4E29E39E}

ProgIDs:
bbylntlbr.bbylntlbrHlpr.1, escort.escortIEPane.1

COM registered:
Yes

File PE Metadata
Compilation timestamp:
8/23/2012 10:15:12 AM

OS version:
5.1

OS bitness:
Win32

Subsystem:
Windows GUI

Linker version:
10.0

CTPH (ssdeep):
6144:gPVC8vNto2nHcLPz074roHTgvRYmNxxs90/:CC81to2nHiVroHTgpYmNxd

Entry address:
0x1AE20

Entry point:
8B, FF, 55, 8B, EC, 83, 7D, 0C, 01, 75, 05, E8, 0C, 79, 00, 00, FF, 75, 08, 8B, 4D, 10, 8B, 55, 0C, E8, EC, FE, FF, FF, 59, 5D, C2, 0C, 00, CC, CC, CC, CC, CC, CC, CC, CC, CC, CC, CC, CC, CC, 55, 8B, EC, 57, 56, 8B, 75, 0C, 8B, 4D, 10, 8B, 7D, 08, 8B, C1, 8B, D1, 03, C6, 3B, FE, 76, 08, 3B, F8, 0F, 82, A0, 01, 00, 00, 81, F9, 80, 00, 00, 00, 72, 1C, 83, 3D, 00, DE, 03, 10, 00, 74, 13, 57, 56, 83, E7, 0F, 83, E6, 0F, 3B, FE, 5E, 5F, 75, 05, E9, 22, 7B, 00, 00, F7, C7, 03, 00, 00, 00, 75, 14, C1, E9, 02, 83...
 
[+]

Code size:
177.5 KB (181,760 bytes)

Internet Explorer BHO
Display name:
Babylon toolbar helper

CLSID:
{2EECD738-5844-4a99-B4B6-146BF802613B}


Remove babylontoolbar.dll - Powered by Reason Core Security