Babylon Search removal

  25-01-2013 12:54am
    Hi everyone,

    So basically the problem is this. Somehow babylon has set itself up as my default opening page and search engine.

    Now to save time here is how my removal attempts went so far:
    I changed the homepage back to google aswell as the default search engine.These are the current settings but babylon is still coming up.

    I went to search for it in the command line, couldnt find it, tried in the system files and tried to go to add/uninstall programs, wasnt there.

    In at my wits end here as every time i try to search online everyone is telling me what ive already done.

    Help please,

    Thank you in advance.



    run adwcleaner and post the log from it

    I'm in the same boat. Have that f***ing thing for the past week. I have'nt found it overly obtrusive, but I'm not sure where it came from. Have MSE as my anti-virus.

    ASJ112 wrote: »
    run adwcleaner and post the log from it

    # AdwCleaner v2.108 - Logfile created 01/25/2013 at 00:13:01
    # Updated 24/01/2013 by Xplode
    # Operating system : Windows 7 Home Premium Service Pack 1 (64 bits)
    # User : John - JOHN-HP
    # Boot Mode : Normal
    # Running from : C:\Users\John\Downloads\AdwCleaner.exe
    # Option [Search]

    ***** [Services] *****

    ***** [Files / Folders] *****

    Folder Found : C:\Program Files (x86)\Conduit
    Folder Found : C:\Program Files (x86)\uTorrentControl_v2
    Folder Found : C:\Users\John\AppData\Local\Conduit
    Folder Found : C:\Users\John\AppData\LocalLow\Conduit
    Folder Found : C:\Users\John\AppData\LocalLow\uTorrentControl_v2
    Folder Found : C:\Users\John\AppData\Roaming\OpenCandy

    ***** [Registry] *****

    Key Found : HKCU\Software\AppDataLow\Software\Conduit
    Key Found : HKCU\Software\AppDataLow\Software\ConduitSearchScopes
    Key Found : HKCU\Software\AppDataLow\Software\SmartBar
    Key Found : HKCU\Software\AppDataLow\Software\uTorrentControl_v2
    Key Found : HKCU\Software\AppDataLow\Toolbar
    Key Found : HKCU\Software\Conduit
    Key Found : HKCU\Software\Microsoft\Windows\CurrentVersion\Ext\Settings\{7473B6BD-4691-4744-A82B-7854EB3D70B6}
    Key Found : HKCU\Software\Microsoft\Windows\CurrentVersion\Ext\Stats\{7473B6BD-4691-4744-A82B-7854EB3D70B6}
    Key Found : HKCU\Software\SmartBar
    Key Found : HKCU\Software\Microsoft\Internet Explorer\SearchScopes\{006EE092-9658-4FD6-BD8E-A21A348E59F5}
    Key Found : HKLM\Software\AVG Secure Search
    Key Found : HKLM\SOFTWARE\Classes\Toolbar.CT3220468
    Key Found : HKLM\Software\Conduit
    Key Found : HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Ext\PreApproved\{537F4F0B-3542-4C7D-A3E5-CF121482696C}
    Key Found : HKLM\Software\uTorrentControl_v2
    Key Found : HKLM\SOFTWARE\Wow6432Node\Classes\CLSID\{3C471948-F874-49F5-B338-4F214A2EE0B1}
    Key Found : HKLM\SOFTWARE\Wow6432Node\Classes\CLSID\{537F4F0B-3542-4C7D-A3E5-CF121482696C}
    Key Found : HKLM\SOFTWARE\Wow6432Node\Classes\CLSID\{7473B6BD-4691-4744-A82B-7854EB3D70B6}
    Key Found : HKLM\SOFTWARE\Wow6432Node\Classes\CLSID\{AE07101B-46D4-4A98-AF68-0333EA26E113}
    Key Found : HKLM\SOFTWARE\Wow6432Node\Microsoft\Internet Explorer\Low Rights\ElevationPolicy\{C6566505-3FBB-42BA-B8CF-DC0CB8A1C224}
    Key Found : HKLM\SOFTWARE\Wow6432Node\Microsoft\Internet Explorer\Low Rights\ElevationPolicy\{EDFA7625-36E7-4EBF-A68B-E15D0CC87B5C}
    Key Found : HKLM\SOFTWARE\Wow6432Node\Microsoft\Internet Explorer\SearchScopes\{006EE092-9658-4FD6-BD8E-A21A348E59F5}
    Key Found : HKLM\SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{7473B6BD-4691-4744-A82B-7854EB3D70B6}
    Key Found : HKLM\SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\Uninstall\uTorrentControl_v2 Toolbar
    Key Found : HKLM\SOFTWARE\Classes\CLSID\{AE07101B-46D4-4A98-AF68-0333EA26E113}
    Key Found : HKU\S-1-5-21-2728233375-3445593543-799856114-1000\Software\Microsoft\Internet Explorer\SearchScopes\{006EE092-9658-4FD6-BD8E-A21A348E59F5}
    Value Found : HKCU\Software\Microsoft\Internet Explorer\Toolbar\WebBrowser [{7473B6BD-4691-4744-A82B-7854EB3D70B6}]
    Value Found : HKLM\SOFTWARE\Microsoft\Internet Explorer\URLSearchHooks [{7473B6BD-4691-4744-A82B-7854EB3D70B6}]
    Value Found : HKLM\SOFTWARE\Wow6432Node\Microsoft\Internet Explorer\Toolbar [{7473B6BD-4691-4744-A82B-7854EB3D70B6}]
    Value Found : HKLM\SOFTWARE\Wow6432Node\Microsoft\Internet Explorer\Toolbar [{AE07101B-46D4-4A98-AF68-0333EA26E113}]
    Value Found : HKLM\SOFTWARE\Microsoft\Internet Explorer\Toolbar [{AE07101B-46D4-4A98-AF68-0333EA26E113}]

    ***** [Internet Browsers] *****

    -\\ Internet Explorer v9.0.8112.16457

    [HKCU\Software\Microsoft\Internet Explorer\Main - Search Page] = hxxp://{searchTerms}
    [HKCU\Software\Microsoft\Internet Explorer\Main - Start Page] = hxxp://
    [HKCU\Software\Microsoft\Internet Explorer\Main - Search Bar] = hxxp://{searchTerms}
    [HKCU\Software\Microsoft\Internet Explorer\Search - Default_Search_URL] = hxxp://{searchTerms}
    [HKCU\Software\Microsoft\Internet Explorer\Search - SearchAssistant] = hxxp://{searchTerms}

    -\\ Google Chrome v24.0.1312.56

    File : C:\Users\John\AppData\Local\Google\Chrome\User Data\Default\Preferences

    Found [l.11] : homepage = "hxxp://",
    Found [l.1729] : homepage = "hxxp://",


    AdwCleaner[R1].txt - [5178 octets] - [25/01/2013 00:13:01]

    ########## EOF - C:\AdwCleaner[R1].txt - [5238 octets] ##########

    let adwcleaner delete what it found. if babylon is still there do this

    Download OTL to your Desktop
    • Double click on the icon to run it. Make sure all other windows are closed and to let it run uninterrupted.
    • Click the Quick Scan button. Do not change any settings. The scan wont take long.
    • When the scan completes, it will open two notepad windows. OTL.Txt and Extras.Txt. These are saved in the same location as OTL.
    • Please copy (Edit->Select All, Edit->Copy) the contents of these files here

    ASJ112 wrote:
    let adwcleaner delete what it found. if babylon is still there do this

    Download OTL to your Desktop
    • Double click on the icon to run it. Make sure all other windows are closed and to let it run uninterrupted.
    • Click the Quick Scan button. Do not change any settings. The scan wont take long.
    • When the scan completes, it will open two notepad windows. OTL.Txt and Extras.Txt. These are saved in the same location as OTL.
    • Please copy (Edit->Select All, Edit->Copy) the contents of these files here

    ASJ, you sir are a savior of the frustrated man! Adw did its job, babylon is gone for good! and i have a new tool to play with if necessary. Thank you again good sir!

    Good to hear, Kristopherus feel free to follow the advice above and let me know how it goes.

    Good to hear, Kristopherus feel free to follow the advice above and let me know how it goes.

    Im afraid its back, i dont know how. I ran the adw scan again and nothing is coming up. I ran the OTL scan and nothing is showing up either. What gives?

    I inboxed you both reports

    Snow joke wrote:
    Im afraid its back, i dont know how. I ran the adw scan again and nothing is coming up. I ran the OTL scan and nothing is showing up either. What gives?

    I inboxed you both reports

    Guess max is 15k characters

    It's easier for me to read the logs here

    open OTL copy and paste this into the custom scan/fixes box

    IE - HKCU\..\SearchScopes\{0C3CFA15-150B-45F9-9149-A1BAA639F565}: "URL" =
    O32 - AutoRun File - [2003/01/30 05:26:41 | 000,118,852 | R--- | M] () - G:\Autorun.exe -- [ CDFS ]
    O32 - AutoRun File - [2003/01/30 07:39:41 | 000,000,044 | R--- | M] () - G:\Autorun.inf -- [ CDFS ]
    O33 - MountPoints2\{a4319a1f-49f7-11e2-9d58-a0b3cc860cd1}\Shell - "" = AutoRun
    O33 - MountPoints2\{a4319a1f-49f7-11e2-9d58-a0b3cc860cd1}\Shell\AutoRun\command - "" = G:\Autorun.exe -- [2003/01/30 05:26:41 | 000,118,852 | R--- | M] ()

    ipconfig /flushdns /c
    C:\Program Files\Babylon
    C:\Program Files\Mozilla Firefox\searchplugins\babylon.xml
    C:\Program Files\Mozilla Firefox\extensions\

    click run fix post the log it gives.

    then download malwarebytes, update it, run a quick scan and post that log here

    ASJ112 wrote:
    Good to hear, Kristopherus feel free to follow the advice above and let me know how it goes.

    Thanks very much, AS. Got rid of it.

    hey people

    that has worked for me once:

    • Uninstall the Babylon in Programs and Features.
    • Check if the babylon Toolbar is still there in Tools>Manage Add-ons>Toolbars and extentions, if it still there, disable that(select and hit disable button)
    • Remove the Babylon homepage(Tools>Internet Options> general>Homepage(change it or use blank).
    • Check if the babylon is raising up when we open a new tab in the same window( Click on add tab in the Internet explorer)
    • if it is comming up:
    • Take a Regestry Backup and follow the steps:
    • Windows+R on desktop> Type Regedit and hit ok button> Select computers> hit Ctrl+F> Type Babylon in the search box and hit "Find Next" button.
    • That brings up the Babylon regestry control just Delete it(Hit Del and Enter),Search again(Just hit F3) and delete all the babylon controls.
    • Repeat the above step untill search says: "Finished Searching through the Regestry" when you hit F3.
    • Click ok button.
    • Restart the computer(Optional)

    Let me know if it worked !
