Infected with Babylon Toolbar from file found at MakorGeeks

Discussion in 'Malware Help - MG (A Specialist Will Reply)' started by Texan, Sep 19, 2012.

  1. Texan

    Texan Private First Class

    I recently downloaded iDevice Manager 1.5.0.1 here:
    http://majorgeeks.com/iDevice_Manager_d5833.html

    I saw that it had 3rd party components so I aborted the installation but still got the Babylon Toolbar and now it's my homepage on every browser I have as well and it's now in my search engine list:
    [​IMG]

    It's been a nightmare to get rid of. I've used SuperAntispyware, Malwarebytes and Spybot Search&Destroy.
    I have also searched "babylon" using RegEdit and am still infected.

    I noticed that virustotal last found 3 malware hits but when reanalyzed it now finds 4. Maybe the developers added more?
    https://www.virustotal.com/file/f7e...25c79453a8d54c8b2f6c3a0c/analysis/1348068437/

    I will continue to try to remove this but thought you should know so you could take a look at the file.
    Also I would appreciate any advice getting rid of it.
     
  2. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    Yes this program is offered for free and has embedded in offers for both Incredibar Toolbar and then Babylon Toolbar. Both of these however can be bypassed by unselecting them. The first screen you see is the below for Incredibar:

    IDevice1_IB.jpg

    You can unslect the check boxes and click next which gives the below notice

    IDevice2_IB.jpg
    Here you can just click cancel. Now you will get the Babylon notice:
    IDevice3_BT.jpg
    Again you can click cancel and it will move on to install iDevice and the necessary .NET Framework v4.
    IDevice4_BT.jpg

    No toolbars are install when you do this.

    I will still reference this thread to Tim and Jim since Babylon Toolbar is proving to be a very annoying program that does not seem to easily uninstall as stated in their license agreement >> http://www.babylon.com/toolbar

    See the below section and see if it helps
     
  3. Texan

    Texan Private First Class

    Thanks for the response. I am pretty good at EULAs and opting out of third party software. I may have simply X'ed out of the installation but I NEVER agreed to any third party software.
    I uninstalled the toolbar. I also removed the Firefox extension. I ran the 3 anti-malware programs I mentioned. (All found Babylon and could not remove them.)
    I also ran RegEdit after all of that and removed about 12 entries and Babylon still exists on my system.

    I appreciate you bringing this thread to the attention of Tim and Jim because something fishy is going on with this installer and I have removed malicious malware easier than this Babylon nightmare.

    Thanks again!
     
  4. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    I'm sorry but I tested it and the only way it installs is if you do not unselect the defaulted checked items and if you do not click cancel as noted.

    I spoke with Tim about this and he stated that the toolbars are clearly indicated as optional and the can be unselected as I have noted. If we were to remove every single download that included an optional toolbar, more than 50% of all free software would be gone. And note this would also mean the most free antivirus programs would be gone too and even some pay ones like Norton since it forces Ask on all users of their products.

    If you still have an issue with Babylon on Firefox, the easiest way to remove it may be to do the below ( I don't know what version of Windows you have so I will assume Win 7 or Vista 64 bit ).



    We are going to be uninstalling your old version of FireFox and installing the new version. So do the below to save bookmarks:
    • Run FireFox and click Bookmarks.
    • Then select Organize Bootmarks.
    • Then on the next window click File and then select Export. Save the bookmarks.html file to your Desktop for later use in importing.
    Now download and save the installer for the current version of FireFox but DO NOT install it yet. Get it here: Mozilla Firefox 15.0.1 Final

    You will need exit FireFox now and use Internet Explorer to continue with the below until we reinstall FireFox.

    Start by uninstalling FireFox and then reboot. Do not skip the reboot.

    After reboot, delete the below folders:
    C:\Program Files (x86)\Mozilla Firefox
    C:\users\UserAccount\AppData\Roaming\Mozilla\Firefox

    where UserAccount is the actual user account name being used.

    Now reinstall FireFox from the file previously downloaded.
    Import your bookmarks file. (similar process to exporting).
     
  5. Texan

    Texan Private First Class

    Thanks. I will try it when I get home!!!
     
  6. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    Okay, let me know if it fixes the issue with Firefox.
     

MajorGeeks.Com Menu

Downloads All In One Tweaks \ Android \ Anti-Malware \ Anti-Virus \ Appearance \ Backup \ Browsers \ CD\DVD\Blu-Ray \ Covert Ops \ Drive Utilities \ Drivers \ Graphics \ Internet Tools \ Multimedia \ Networking \ Office Tools \ PC Games \ System Tools \ Mac/Apple/Ipad Downloads

Other News: Top Downloads \ News (Tech) \ Off Base (Other Websites News) \ Way Off Base (Offbeat Stories and Pics)

Social: Facebook \ YouTube \ Twitter \ Tumblr \ Pintrest \ RSS Feeds