A Bad Case of the Babylon's

User avatar
BobH
UraniumLounger
Posts: 9295
Joined: 13 Feb 2010, 01:27
Location: Deep in the Heart of Texas

A Bad Case of the Babylon's

Post by BobH »

I checked my email a bit ago and read messages from sources I trust and from whom I've received clean email in the past. One of them was from my brother who, at near 80, is not savvy when it comes to computers. He can surf and send emails but he doesn't really understand much about what happens behind the curtain. I suspect that it was the email from him that gave me the case of the Babylon's (Babylon search engine and toolbar installing themselves).

It's possible that the crapola came from one of the 3 or 4 other emails I opened; so, the question is, "How does malware attach itself to email and install itself in your browser? Or is this one of the mysteries that I must attain the 33rd degree to discover? However it happened, it got past MSE.

Another issue appeared after I did my best to clean up add-ons and programs installed on the computer to rid myself of babylon and restarted Firefox. After logging in to each of 3 or 4 forums I visit regularly, I got a drop down from the address bar asking me if I wanted to have Fx save my passwords. Is this yet another babylon or is there and Fx setting that the malware exploited?

TIA
Bob's yer Uncle
(1/2)(1+√5)
Dell Intel Core i5 Laptop, 3570K,1.60 GHz, 8 GB RAM, Windows 11 64-bit, LibreOffice,and other bits and bobs

User avatar
HansV
Administrator
Posts: 78535
Joined: 16 Jan 2010, 00:14
Status: Microsoft MVP
Location: Wageningen, The Netherlands

Re: A Bad Case of the Babylon's

Post by HansV »

Did you open an attachment in one of those e-mails?

The question about passwords may well be a legitimate one that reappeared because removing the toolbar reset some Firefox options.
Best wishes,
Hans

User avatar
Roderunner
5StarLounger
Posts: 1021
Joined: 23 Jan 2011, 01:52
Location: Witness Protection Program.

Re: A Bad Case of the Babylon's

Post by Roderunner »

Bob, AFAIA, MSE doesn't scan Emails but Avast does.
Windows 11 Home 22H2

Regards,
George.

User avatar
HansV
Administrator
Posts: 78535
Joined: 16 Jan 2010, 00:14
Status: Microsoft MVP
Location: Wageningen, The Netherlands

Re: A Bad Case of the Babylon's

Post by HansV »

Microsoft Security Essentials by default scans e-mail attachments when you open them or save them to disk.
MSE.png
You do not have the required permissions to view the files attached to this post.
Best wishes,
Hans

User avatar
BobH
UraniumLounger
Posts: 9295
Joined: 13 Feb 2010, 01:27
Location: Deep in the Heart of Texas

Re: A Bad Case of the Babylon's

Post by BobH »

I don't recall opening an attachment but I do recall clicking a link.

I seem to have rid the machine of Babylon (at least from outward appearance; haven't looked into the Registry), and I think I figured out that the Tools|Options|Security box for Remember Passwords for Sites got checked by whatever the bad wind was. I took care of that and the drop down option from the address bar seems to have gone away.

Thanks for your help!
Bob's yer Uncle
(1/2)(1+√5)
Dell Intel Core i5 Laptop, 3570K,1.60 GHz, 8 GB RAM, Windows 11 64-bit, LibreOffice,and other bits and bobs

User avatar
BobH
UraniumLounger
Posts: 9295
Joined: 13 Feb 2010, 01:27
Location: Deep in the Heart of Texas

Re: A Bad Case of the Babylon's

Post by BobH »

FWIW:
To remove Babylon search engine and toolbar, I first used CP to Add/Remove programs. There was an entry there for both the toolbar and the search engine, both of which I removed.

Second, I went to Firefox Tools|Add-ons and removed everything that had Babylon in its name. I think there were 2 entries, but I'm not certain of that. I deleted them, not disabled them.

The search engine persisted displacing my search engine of choice. I discovered by searching the web that there are Firefox configuration entries inserted by Babylon. It was suggested that about:config be opened and "babylon" entered into the search bar to discover those entries. There were about 60 of them which I right clicked and reset.

If the mess returns, I'll report back.
Bob's yer Uncle
(1/2)(1+√5)
Dell Intel Core i5 Laptop, 3570K,1.60 GHz, 8 GB RAM, Windows 11 64-bit, LibreOffice,and other bits and bobs