babmaint.exe

Babylon Ltd.

This is the maintenance task (EPUpdater) installed with a Babylon branded web browser toolbar (search adware). The scheduled task will check to make sure that the installed browser extensions for Chorme, Firefox and IE are installed as well as the home page and search provider are set to the Babylon partner site. The application babmaint.exe by Babylon has been detected as adware by 1 anti-malware scanner with very strong indications that the file is a potential threat. This will display context specific advertisements in the browser as well as attempt to modify the browser's search provider.
Publisher:
Babylon Ltd.  (signed and verified)

MD5:
a13bf8430be603a39d4f222238fd2d39

SHA-1:
35a81450fc24573f3cb293d196b45051d1e6640f

Scanner detections:
1 / 68

Status:
Adware

Note:
Our current pool of anti-malware engines have not currently detected this file, however based on our own detection heuristics we feel that this file is unwanted.

Analysis date:
5/15/2024 9:03:14 AM UTC  (today)

Scan engine
Detection
Engine version

Reason Heuristics
PUP.Babylon (M)
17.3.7.19

File size:
277.9 KB (284,607 bytes)

File type:
Executable application (Win32 EXE)

Common path:
C:\Documents and Settings\{user}\Application data\babmaint.exe

Digital Signature
Signed by:

Authority:
Thawte, Inc.

Valid from:
2/26/2012 8:00:00 PM

Valid to:
3/8/2014 7:59:59 PM

Subject:
CN=Babylon Ltd., O=Babylon Ltd., L=Or-Yehuda, S=Or-Yehuda, C=IL

Issuer:
CN=Thawte Code Signing CA - G2, O="Thawte, Inc.", C=US

Serial number:
48C39FBA62460E24E169054FE518E0AF

File PE Metadata
Compilation timestamp:
2/9/2013 5:55:19 PM

OS version:
5.0

OS bitness:
Win32

Subsystem:
Windows GUI

Linker version:
9.0

Entry address:
0x796C

Entry point:
BB, 43, D5, 6D, 1C, 93, E9, 20, 01, 00, 00, 33, D9, 3C, 38, E4, 68, 3C, 38, 0C, 90, BD, BC, BC, 3C, BC, BC, 84, BC, BC, BC, 1B, ED, F2, ED, EC, ED, F5, F3, F2, BC, BC, BC, 30, 1D, 36, 21, 1E, 1D, 29, 1D, EA, 20, 28, 28, BC, BC, BC, BC, 18, BC, BC, BC, 02, 2E, 21, 21, 08, 25, 1E, 2E, 1D, 2E, 35, BC, FF, 2E, 21, 1D, 30, 21, 00, 25, 2E, 21, 1F, 30, 2B, 2E, 35, FD, BC, BC, BC, BC, 03, 21, 30, 13, 25, 2A, 20, 2B, 33, 2F, 00, 25, 2E, 21, 1F, 30, 2B, 2E, 35, FD, BC, BC, BC, BC, 03, 21, 30, 09, 2B, 20, 31, 28, 21...
 
[+]

Code size:
78.5 KB (80,384 bytes)

Remove babmaint.exe - Powered by Reason Core Security