Windows Defender detects Win32/Babylon

Discussion in 'Malware Help (A Specialist Will Reply)' started by sdroger79, Aug 16, 2010.

  1. sdroger79

    sdroger79 Private E-2

    Hello, windows defender is detecting Win32/Basbylon still even after following the removal process. Attached are the logs.

    Please not there is not log for combofix or rootrepeal because of 64bit Window 7.

    This started about 3 days ago. Notifications have increased in frequency despite attempts to remove using the full cleaning procedure here and before that, ariva antivir and ariva removal tool, and windows defender.

    Here is the actually error from windows defender.

    Category:
    Adware

    Description:
    This program displays pop-up advertisements.

    Advice:
    Permit this detected item only if you trust the program or the software publisher.

    Resources:
    containerfile:
    c:\users\roger\local settings\application data\Babylon\Setup\MyBabylonFF.exe

    file:
    c:\users\roger\local settings\application data\Babylon\Setup\MyBabylonFF.exe->(wise0023)

    folder:
    c:\users\roger\local settings\application data\Babylon\

    View more information about this item online

    Please advise. thanks!
     

    Attached Files:

  2. Kestrel13!

    Kestrel13! Super Malware Fighter - Major Dilemma Staff Member

    Hi there and welcome. I am currently reviewing your logs and will get back to you with a set of instructions in the next post I make to you.
     
  3. Kestrel13!

    Kestrel13! Super Malware Fighter - Major Dilemma Staff Member

    I am not seeing any evidence of the babylon folder existing, however, we will include to delete the folder windows defender is reporting, in the script.

    Please disable all anti-virus and anti-spyware programs while we do the following (re-enable when you are finished):

    Run C:\MGtools\analyse.exe by double clicking on it (Note: if using Vista, don't double click, use right click and select Run As Administrator). This is really HijackThis (select Do a system scan only) and select the following lines but DO NOT CLICK FIX until you exit all browser sessions including the one you are reading in right now:
    After clicking Fix exit HJT.

    Download and run OTM.

    Download OTM by Old Timer and save it to your Desktop.


    Code:
    :Files
    c:\users\roger\local settings\application data\Babylon
    C:\Windows\E2CBF3FEA24F40DFB25D8C9E05F0CD63.TMP
    C:\Windows\SysWOW64\f9t.dat
    
    :Commands
    [emptytemp]
    [Reboot]
    • Return to OTM, right click in the Paste List of Files/Folders to Move window (under the yellow bar) and choose Paste.
    • Push the large http://farm3.static.flickr.com/2782/4174320048_f01c448b32_o.png button.
    • OTM may ask to reboot the machine. Please do so if asked.
    • Copy everything in the Results window (under the green bar), and paste it in your next reply.

    NOTE: If you are unable to copy/paste from this window (as will be the case if the machine was rebooted), open Notepad (Start->All Programs->Accessories->Notepad), click File->Open, in the File Name box enter *.log and press the Enter key, navigate to the C:\_OTM\MovedFiles folder, and open the newest .log file present, and copy/paste the contents of that document back here in your next post.

    Run Ccleaner.

    Now run the C:\MGtools\GetLogs.bat file by double clicking on it. Then attach the new C:\MGlogs.zip file that will be created by running this.

    Let me know how things are running for you. Is windows defender still focussing it's attention on the Babylon folder? Here is some information on it.

    Win32/Babylon
     
  4. sdroger79

    sdroger79 Private E-2

    Hi,

    Attached are the logs. Win Defender is still focusing on Win32/Babylon.

    Yeah i had found that description you linked to as well. I am familiar with Babylon translation software. What has me a little concerned is there is not trace of Babylon on this machine (that I can tell) and I am 100% positive i have never installed babylon on this machine. I have used it on another computer of mine but not on this one.

    Also about a day after I started getting the Babylon errors windows defender started giving me other errors too. I didn't write down the names of those unfortunately. I tried to find the info in event viewer but couldn't seem to find where Windows Defender logs events?

    What do you think?
     

    Attached Files:

  5. Kestrel13!

    Kestrel13! Super Malware Fighter - Major Dilemma Staff Member

    Hmmm, weird huh?

    Now download Registry Search (see the link titled RegSearch Download Link )

    • Extract the files from Regsearch.zip into a folder.
    • Doubleclick regsearch.exe to start the program.
    • See the top 3 boxes under the Enter search strings (case independent) and click Ok... option, enter the below bold string (use copy and paste)

    • MyBabylon
    • Then click "OK".
    • Notepad will be opened with text in it (the file named RegSearch.txt will be saved in the program's folder as well).
    • Attach this RegSearch.txt file.
     
  6. Kestrel13!

    Kestrel13! Super Malware Fighter - Major Dilemma Staff Member

    Also, just an after thought, try emptying the quarantined files from windows defender. Still getting reports for babylon? (I can't see it even being in quarantine if it wasn't installed in the first place though, but worth trying)
     
  7. sdroger79

    sdroger79 Private E-2

    hmmm... here is the log.

    I cannot empty the quarantine because it is empty. When I tell windows defender to clean the entry it says it successfully removes it but it doesn't stop displaying the error nor does it add anything to the quarantine list.
     

    Attached Files:

  8. sdroger79

    sdroger79 Private E-2

    hmmm... here is the log.

    I cannot empty the quarantine because it is empty. When I tell windows defender to clean the entry it says it successfully removes it but it doesn't stop displaying the error nor does it add anything to the quarantine list.

    UPDATE
    Just for the hell of it i searched for just Babylon and it did find one registry entry...

    ; HKEY_LOCAL_MACHINE HKEY_USERS


    [HKEY_USERS\S-1-5-21-3653466889-1932623074-3592449014-1001\Software\Microsoft\Windows NT\CurrentVersion\AppCompatFlags\Compatibility Assistant\Persisted]
    "C:\\Users\\Roger\\AppData\\Local\\Temp\\nsp8488.tmp\\babylon_setup.exe"=dword:00000001

    ; End Of The Log...
     
  9. Kestrel13!

    Kestrel13! Super Malware Fighter - Major Dilemma Staff Member

    Well this *is* strange.

    Considering that I am not seeing anything in your logs to reflect the fact that those files/folders exist, I am a bit annoyed with Windows Defender.

    I have been looking at this:

    How to Disable Windows Defender


    But that of course is not really the answer, I would like to figure out why it's reporting it and how to stop it without disabling the program.

    I will enquire about this for you.

    Give Ccleaner a run in the meantime.
     
  10. sdroger79

    sdroger79 Private E-2

    should i try and remove the reg entry that i just found for babylon_setup.exe

    [HKEY_USERS\S-1-5-21-3653466889-1932623074-3592449014-1001\Software\Microsoft\Windows NT\CurrentVersion\AppCompatFlags\Compatibility Assistant\Persisted]
    "C:\\Users\\Roger\\AppData\\Local\\Temp\\nsp8488.tmp\\babylon_setup.exe"=dword:00000001
     
  11. sdroger79

    sdroger79 Private E-2

    sorry to double post. in addition to the info i just posted in the post below. I have also found files that seem to correlate to the files windows defender is reporting in the following directory "C:\Users\Roger\AppData\Local\Babylon."
     
  12. Kestrel13!

    Kestrel13! Super Malware Fighter - Major Dilemma Staff Member

    Yes, let''s give it a go and hope it's the end of it. LOL



    Code:
    :files
    C:\Users\Roger\AppData\Local\Temp\nsp8488.tmp
    C:\Users\Roger\AppData\Local\Temp\nsp8488.tmp\babylon_setup.exe
    C:\Users\Roger\AppData\Local\Babylon
    
    :reg
    [HKEY_USERS\S-1-5-21-3653466889-1932623074-3592449014-1001\Software\Microsoft\Windows NT\CurrentVersion\AppCompatFlags\Compatibility Assistant\Persisted]
    "C:\\Users\\Roger\\AppData\\Local\\Temp\\nsp8488.tmp\\babylon_setup.exe"=-
    
    :Commands
    [emptytemp]
    [Reboot]
    • Return to OTM, right click in the Paste List of Files/Folders to Move window (under the yellow bar) and choose Paste.
    • Push the large http://farm3.static.flickr.com/2782/4174320048_f01c448b32_o.png button.
    • OTM may ask to reboot the machine. Please do so if asked.
    • Copy everything in the Results window (under the green bar), and paste it in your next reply.

    NOTE: If you are unable to copy/paste from this window (as will be the case if the machine was rebooted), open Notepad (Start->All Programs->Accessories->Notepad), click File->Open, in the File Name box enter *.log and press the Enter key, navigate to the C:\_OTM\MovedFiles folder, and open the newest .log file present, and copy/paste the contents of that document back here in your next post.
     
    Last edited: Aug 17, 2010
  13. sdroger79

    sdroger79 Private E-2

    Yes! Fixed. Many Thanks!
     
  14. Kestrel13!

    Kestrel13! Super Malware Fighter - Major Dilemma Staff Member

    You found the reg entry ;)

    I guess with just seraching for babylon and not "my babylon"

    Glad it's sorted :-D

    If you are not having any other malware problems, it is time to do our final steps:
    1. We recommend you keep SUPERAntiSpyware and Malwarebytes Anti-Malware for scanning/removal of malware. Unless you purchase them, they provide no protection. They do not use any significant amount of resources ( except a little disk space ) until you run a scan.
    2. If we had you use ComboFix, uninstall ComboFix (This uninstall will only work as written if you installed ComboFix on your Desktop like we requested.)
      • Click START then RUN and enter the below into the run box and then click OK. Note the quotes are required
      • "%userprofile%\Desktop\combofix" /uninstall
        • Notes: The space between the combofix" and the /uninstall, it must be there.
        • This will uninstall ComboFix and also reset hidden files and folders settings back to Windows defaults.
    3. Go back to step 6 of the READ ME and renable your Disk Emulation software with Defogger if you had disabled it.
    4. Any other miscellaneous tools we may have had you install or download can be uninstalled and deleted.
    5. If we had you download any registry patches like fixme.reg or fixWLK.reg (or any others), you can delete these files now.
    6. If running Vista, it is time to make sure you have reenabled UAC by double clicking on the C:\MGtools\enableUAC.reg file and allowing it to be added to the registry.
    7. Go to add/remove programs and uninstall HijackThis.
    8. Goto the C:\MGtools folder and find the MGclean.bat file. Double click on this file to run this cleanup program that will remove files and folders
      related to MGtools and some other items from our cleaning procedures.
    9. If you are running Win 7, Vista, Windows XP or Windows ME, do the below:
      • Refer to the cleaning procedures pointed to by step 7 of the READ ME
        for your Window version and see the instructions to Disable System Restore which will flush your Restore Points.
      • Then reboot and Enable System Restore to create a new clean Restore Point.
    10. After doing the above, you should work thru the below link:
     

MajorGeeks.Com Menu

Downloads All In One Tweaks \ Android \ Anti-Malware \ Anti-Virus \ Appearance \ Backup \ Browsers \ CD\DVD\Blu-Ray \ Covert Ops \ Drive Utilities \ Drivers \ Graphics \ Internet Tools \ Multimedia \ Networking \ Office Tools \ PC Games \ System Tools \ Mac/Apple/Ipad Downloads

Other News: Top Downloads \ News (Tech) \ Off Base (Other Websites News) \ Way Off Base (Offbeat Stories and Pics)

Social: Facebook \ YouTube \ Twitter \ Tumblr \ Pintrest \ RSS Feeds