A forum for reverse engineering, OS internals and malware analysis 

Forum for analysis and discussion about malware.
 #5038  by EP_X0FF
 Sun Feb 13, 2011 1:44 pm
This is sort of software which appears to be legitimate (see Babylon.com, executables even digitally signed) but it behaves and distributes like typical malware. Some time ago I reversed small VB crypted downloader which was internally named "Babylon downloader" and had several links to download other components of Babylon translator. As for it's purpose - it full of bugs and does not working, uninstaller procedure causing app crash. After "uninstalling" user needs to do additional steps to completely remove components such as "Toolbar".

For more info see http://en.wikipedia.org/wiki/Babylon_(program)