PUA

PUA:Win32/BabylonToolbar removal instruction

Malware Removal

The PUA:Win32/BabylonToolbar is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What PUA:Win32/BabylonToolbar virus can do?

  • Sample contains Overlay data
  • Reads data out of its own binary image
  • Authenticode signature is invalid

How to determine PUA:Win32/BabylonToolbar?


File Info:

name: 1E02D6AA4A1994487191.mlw
path: /opt/CAPEv2/storage/binaries/fb6b1171776554a808c62f4045f5167603f70bf7611de64311ece0624b365397
crc32: 937027E5
md5: 1e02d6aa4a199448719113ae3926afb2
sha1: f1eff6451ced129c0e5c0a510955f234a01158a0
sha256: fb6b1171776554a808c62f4045f5167603f70bf7611de64311ece0624b365397
sha512: 7d0f1416beb8c141ee992fe594111042309690c00741dff8f9f31b4652ed6a96b57532780e3169391440076d7ace63966fab526a076adcdc7f7ab389b4d0ff98
ssdeep: 24576:eLMeYSiGTpTLDxxwqQcqOj5eyHox6ZGmAuXE7ZBlbT:+PbVvwqQpoLHontDrlbT
type: PE32 executable (GUI) Intel 80386, for MS Windows
tlsh: T1C235231333E1E96AC1190B70A7DBD7B62772F3E22319874B7B0443AB5C252096F21E95
sha3_384: 62be51b334cee63e4bd5185850c65b27bef7e305f6a3e49fe7f475813cb315287fc08ad284b14eb3c985b629186cb5dd
ep_bytes: 81ec8001000053555633db57895c2418
timestamp: 2009-12-05 22:50:41

Version Info:

0: [No Data]

PUA:Win32/BabylonToolbar also known as:

LionicRiskware.Win32.Babylon.1!c
Elasticmalicious (high confidence)
CAT-QuickHealAdWare.ToolBar
MalwarebytesGeneric.Malware.AI.DDS
CrowdStrikewin/grayware_confidence_100% (W)
ArcabitAdware.Generic
VirITTrojan.Win32.StartPage1.OCT
SymantecPUA.Downloader
ESET-NOD32a variant of Win32/Toolbar.Babylon.E potentially unwanted
CynetMalicious (score: 100)
Kasperskynot-a-virus:WebToolbar.Win32.Babylon.bcb
NANO-AntivirusRiskware.Win32.Babylon.craswq
SUPERAntiSpywareAdware.Multi/Variant
EmsisoftApplication.Toolbar (A)
F-SecureProgram.APPL/Toolbar.Babylon.10785
DrWebAdware.Toolbar.493
TrendMicroPUA.Win32.Babylon.GA
WebrootW32.Adware.Gen
VaristW32/Babylon.HOBW-7746
AviraAPPL/Toolbar.Babylon.10785
Antiy-AVLRiskWare[WebToolbar]/Win32.Babylon
XcitiumApplicUnwnt@#17dvgmrmdfork
MicrosoftPUA:Win32/BabylonToolbar
ViRobotRiskTool.Unlocker.1078591
ZoneAlarmnot-a-virus:WebToolbar.Win32.Babylon.bcb
GDataWin32.Application.Agent.0YJLRD
GoogleDetected
AhnLab-V3PUP/Win.Drop
Cylanceunsafe
TrendMicro-HouseCallPUA.Win32.Babylon.GA
RisingAdware.Babylon!1.B3CC (CLASSIC)
YandexTrojan.Igent.bYph23.1
IkarusPUA.Optional.ToolBar
ZonerTrojan.Win32.55558
DeepInstinctMALICIOUS

How to remove PUA:Win32/BabylonToolbar?

PUA:Win32/BabylonToolbar removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment