babylontoolbar.dll

Babylon Toolbar

Babylon BHO

This is part of the Babylon web browser toolbar and extension that will modify the browser's default search provider, DNS, and home page functions. The module babylontoolbar.dll has been detected as adware by 4 anti-malware scanners. It is installed within the context of Internet Explore as a BHO (Browser Helper Object) under the name ‘Babylon toolbar helper’. This will display context specific advertisements in the browser as well as attempt to modify the browser's search provider.
Publisher:
Babylon BHO

Product:
Babylon Toolbar

Version:
1.7.1.0

MD5:
99a66186fbd63c0c1bac49b37a8641a5

SHA-1:
bf105294eaa8e802bab7c2be8a8ce74e50db0a56

SHA-256:
9c4af6b229aac8bfa9a0a89b83532d87524b11676b5ced5c8540bc8f610f40b6

Scanner detections:
4 / 68

Status:
Adware

Analysis date:
4/26/2024 8:33:44 AM UTC  (today)

Scan engine
Detection
Engine version

ESET NOD32
Win32/Toolbar.Escort.A potentially unwanted application
7.0.302.0

IKARUS anti.virus
PUA.Toolbar.Escort
t3scan.1.6.1.0

Reason Heuristics
PUP.Toolbar.BabylonBHO.O
14.8.12.3

SUPERAntiSpyware
PUP.BabylonToolbar
10427

File size:
235 KB (240,640 bytes)

Product version:
1.7.1.0

Copyright:
(c) Babylon Ltd. All rights reserved.

File type:
Dynamic link library (Win32 DLL)

Language:
Hebrew (Israel)

Common path:
C:\Program Files\babylontoolbar\babylontoolbar\1.7.1.3\bh\babylontoolbar.dll

File PE Metadata
Compilation timestamp:
9/4/2012 6:45:39 PM

OS version:
5.1

OS bitness:
Win32

Subsystem:
Windows GUI

Linker version:
10.0

CTPH (ssdeep):
6144:IMD3mDeoP/PGUTPE6pW0d1xjuynhxvpTBN:J3mqoP/PGUTPEi1xjuynhxHN

Entry address:
0x17251

Entry point:
8B, FF, 55, 8B, EC, 83, 7D, 0C, 01, 75, 05, E8, BB, 75, 00, 00, FF, 75, 08, 8B, 4D, 10, 8B, 55, 0C, E8, EC, FE, FF, FF, 59, 5D, C2, 0C, 00, CC, CC, CC, CC, CC, CC, CC, CC, CC, CC, CC, CC, 55, 8B, EC, 57, 56, 8B, 75, 0C, 8B, 4D, 10, 8B, 7D, 08, 8B, C1, 8B, D1, 03, C6, 3B, FE, 76, 08, 3B, F8, 0F, 82, A0, 01, 00, 00, 81, F9, 80, 00, 00, 00, 72, 1C, 83, 3D, 00, 8C, 03, 10, 00, 74, 13, 57, 56, 83, E7, 0F, 83, E6, 0F, 3B, FE, 5E, 5F, 75, 05, E9, D2, 77, 00, 00, F7, C7, 03, 00, 00, 00, 75, 14, C1, E9, 02, 83, E2...
 
[+]

Entropy:
6.2498

Code size:
159 KB (162,816 bytes)

Internet Explorer BHO
Display name:
Babylon toolbar helper

CLSID:
{2EECD738-5844-4a99-B4B6-146BF802613B}


Remove babylontoolbar.dll - Powered by Reason Core Security