babylontoolbar.dll

Babylon Toolbar

Babylon BHO

This is part of the Babylon web browser toolbar and extension that will modify the browser's default search provider, DNS, and home page functions. The module babylontoolbar.dll has been detected as adware by 5 anti-malware scanners. It is installed within the context of Internet Explore as a BHO (Browser Helper Object) under the name ‘Babylon toolbar helper’. This will display context specific advertisements in the browser as well as attempt to modify the browser's search provider.
Publisher:
Babylon BHO

Product:
Babylon Toolbar

Version:
1.8.3.0

MD5:
0e5e4bee59f016db6f8b281f2f34a706

SHA-1:
ead1ee01c0ff5c843913f4aca179569077d3b069

SHA-256:
f85834893853c11b10425403a6938675446692445695b5f87c39a6a762e9851c

Scanner detections:
5 / 68

Status:
Adware

Analysis date:
4/25/2024 8:40:30 PM UTC  (today)

Scan engine
Detection
Engine version

Boost by Reason
Optional.BHO.BabylonBHO.O
188163

ESET NOD32
Win32/Toolbar.Escort (variant)
7.8853

Reason Heuristics
PUP.BHO.BabylonBHO.O
14.3.2.14

SUPERAntiSpyware
PUP.BabylonToolbar
10897

XVirus List
Win.Detected
2.3.31

File size:
236.5 KB (242,176 bytes)

Product version:
1.8.3.0

Copyright:
(c) Babylon Ltd. All rights reserved.

File type:
Dynamic link library (Win32 DLL)

Language:
Hebrew (Israel)

Common path:
C:\Program Files\babylontoolbar\babylontoolbar\1.8.3.8\bh\babylontoolbar.dll

File PE Metadata
Compilation timestamp:
10/14/2012 9:01:16 PM

OS version:
5.1

OS bitness:
Win32

Subsystem:
Windows GUI

Linker version:
10.0

CTPH (ssdeep):
6144:3BPnwn+4RVxLLPwISM7lK45+t8lvvXjn2M:BnwnRVxLLPwISN45+tGvP

Entry address:
0x1764D

Entry point:
8B, FF, 55, 8B, EC, 83, 7D, 0C, 01, 75, 05, E8, AF, 76, 00, 00, FF, 75, 08, 8B, 4D, 10, 8B, 55, 0C, E8, EC, FE, FF, FF, 59, 5D, C2, 0C, 00, 55, 8B, EC, 57, 56, 8B, 75, 0C, 8B, 4D, 10, 8B, 7D, 08, 8B, C1, 8B, D1, 03, C6, 3B, FE, 76, 08, 3B, F8, 0F, 82, A0, 01, 00, 00, 81, F9, 80, 00, 00, 00, 72, 1C, 83, 3D, 00, 9C, 03, 10, 00, 74, 13, 57, 56, 83, E7, 0F, 83, E6, 0F, 3B, FE, 5E, 5F, 75, 05, E9, D2, 78, 00, 00, F7, C7, 03, 00, 00, 00, 75, 14, C1, E9, 02, 83, E2, 03, 83, F9, 08, 72, 29, F3, A5, FF, 24, 95, E0...
 
[+]

Entropy:
6.2505

Code size:
160.5 KB (164,352 bytes)

Internet Explorer BHO
Display name:
Babylon toolbar helper

CLSID:
{2EECD738-5844-4a99-B4B6-146BF802613B}


Remove babylontoolbar.dll - Powered by Reason Core Security