Jump to content

Re: Removal of PUP. Optional.Babylon.A


Recommended Posts

1. Please see the attached Farbar Scan Tool files.

2. Please also see the below scan results.

3. I have several times quarantined and then deleted these suspected files; but they still keep appearing on the next Malware scan.

3. I do not have Babylon or any other malicous programs that show up in the Windows Control Panel Programs section.

 

Please advise of the next step to remove these.

 

Thanks!
Ron

 

 

 

Malwarebytes Anti-Malware
www.malwarebytes.org

Scan Date: 4/30/2014
Scan Time: 2:00:01 PM
Logfile:
Administrator: Yes

Version: 2.00.1.1004
Malware Database: v2014.04.30.08
Rootkit Database: v2014.03.27.01
License: Premium
Malware Protection: Enabled
Malicious Website Protection: Enabled
Chameleon: Disabled

OS: Windows 7 Service Pack 1
CPU: x64
File System: NTFS
User: Buick GN

Scan Type: Hyper Scan
Result: Completed
Objects Scanned: 276118
Time Elapsed: 1 min, 45 sec

Memory: Enabled
Startup: Enabled
Filesystem: Disabled
Archives: Enabled
Rootkits: Disabled
Shuriken: Enabled
PUP: Enabled
PUM: Enabled

Processes: 0
(No malicious items detected)

Modules: 0
(No malicious items detected)

Registry Keys: 0
(No malicious items detected)

Registry Values: 0
(No malicious items detected)

Registry Data: 0
(No malicious items detected)

Folders: 0
(No malicious items detected)

Files: 4
PUP.Optional.Babylon.A, C:\Users\Buick GN\AppData\Roaming\Mozilla\Firefox\Profiles\w4b7ebcv.default\prefs.js, Good: (), Bad: (user_pref("extensions.BabylonToolbar.cntry", "US");), Replaced,[c8b88ca4afcc5dd98eed253cea1af30d]
PUP.Optional.Babylon.A, C:\Users\Buick GN\AppData\Roaming\Mozilla\Firefox\Profiles\w4b7ebcv.default\prefs.js, Good: (), Bad: (user_pref("extensions.BabylonToolbar.firstRun", false);), Replaced,[ccb4cb654d2e79bdea91c59c7e8631cf]
PUP.Optional.Babylon.A, C:\Users\Buick GN\AppData\Roaming\Mozilla\Firefox\Profiles\w4b7ebcv.default\prefs.js, Good: (), Bad: (user_pref("extensions.BabylonToolbar.hdrMd5", "312252591AE3363CCE13A84C627BF2C6");), Replaced,[6c14042ce09b96a04c2f5b06ce36eb15]
PUP.Optional.Babylon.A, C:\Users\Buick GN\AppData\Roaming\Mozilla\Firefox\Profiles\w4b7ebcv.default\prefs.js, Good: (), Bad: (user_pref("extensions.BabylonToolbar.lastActv", "22");), Replaced,[fd83cd6364173303b9c2d8895fa517e9]

Physical Sectors: 0
(No malicious items detected)


(end)

Addition.txt

FRST.txt

Link to post
Share on other sites

Welcome to the forum.

Please create a new system restore point before continuing.

also..........

bwebb7v.jpgDownload Delfix from Here and save it to your desktop.

  • Place a check mark in front of .......
  • Create registry backup <---only!
  • Uncheck the rest!
  • Click the Run button.

    Close the tool out when it's done....we'll use it later.

    Now...........

    Please download AdwCleaner from HERE or HERE to your desktop.
    • Double click on AdwCleaner.exe to run the tool.
      Vista/Windows 7/8 users right-click and select Run As Administrator
    • Click on the Scan button.
    • AdwCleaner will begin...be patient as the scan may take some time to complete.
    • When it's done you'll see: Pending: Please uncheck elements you don't want removed.
    • Now click on the Report button...a logfile (AdwCleaner[R0].txt) will open in Notepad for review.
    • Look over the log especially under Files/Folders for any program you want to save.
    • If there's a program you may want to save, just uncheck it from AdwCleaner.
    • If you're not sure, post the log for review. (all items found are adware/spyware/foistware)
    • If you're ready to clean it all up.....click the Clean button.
    • After rebooting, a logfile report (AdwCleaner[s0].txt) will open automatically.
    • Copy and paste the contents of that logfile in your next reply.
    • A copy of that logfile will also be saved in the C:\AdwCleaner folder.
    • Items that are deleted are moved to the Quarantine Folder: C:\AdwCleaner\Quarantine
    • To restore an item that has been deleted:
    • Go to Tools > Quarantine Manager > check what you want restored > now click on Restore.
    Then:

    Run another scan with FRST.exe (Please make sure the Addition Box is checked).

    Post or attach the logs.

    MrC
Link to post
Share on other sites

Clean out temp files:

Download TFC from here and save it to your desktop.

http://oldtimer.geekstogo.com/TFC.exe

http://www.bleepingcomputer.com/download/tfc/dl/92/

Close any open programs and Internet browsers.

Double click TFC.exe to run it on XP (for Vista and Windows 7 right click and choose "Run as administrator") and once it opens click on the Start button on the lower left of the program to allow it to begin cleaning.

Please be patient as clearing out temp files may take a while.

Once it completes you may be prompted to restart your computer, please do so.

Once it's finished you may delete TFC.exe from your desktop or save it for later use for the cleaning of temporary files.

Then:

Download the attached fixlist.txt to the same folder as FRST.exe.

Run FRST.exe and click Fix only once and wait

The tool will create a log (Fixlog.txt) in the folder, please post it to your reply.

Last:

Update and run a Threat Scan with Malwarebytes.

Let me know how it is, MrC

Link to post
Share on other sites

Good.....

Lets check your computers security before you go and we have a little cleanup to do also:

Download Security Check by screen317 from HERE or HERE.

  • Save it to your Desktop.
  • Double click SecurityCheck.exe and follow the onscreen instructions inside of the black box.
  • If you get Unsupported operating system. Aborting now, just reboot and try again.
  • A Notepad document should open automatically called checkup.txt.
  • Please Post the contents of that document.
  • Do Not Attach It!!!
MrC
Link to post
Share on other sites

  • Root Admin

Glad we could help. :)

If you need this topic reopened, please send a Private Message to any one of the moderating team members. Please include a link to this thread with your request. This applies only to the originator of this thread.

Other members who need assistance please start your own topic in a new thread. Thanks!

Link to post
Share on other sites

Guest
This topic is now closed to further replies.
  • Recently Browsing   0 members

    • No registered users viewing this page.
Back to top
×
×
  • Create New...

Important Information

This site uses cookies - We have placed cookies on your device to help make this website better. You can adjust your cookie settings, otherwise we'll assume you're okay to continue.