Blekko Redirect

Blekko Redirect Description


The Blekko Redirect is one of various attacks that Blekko.com-promoting browser hijackers use to increase revenue for the affiliated company’s bottom line. Blekko Redirects may set your homepage to Blekko.com or redirect you to Blekko.com after you attempt to use a different website, and either of these symptoms should be noted as a symptom of malicious software. Many Blekko Redirect attacks are caused by the Blekko website’s search toolbar, which is sometimes bundled with unrelated applications. Paying close attention to the details of installation processes and avoiding installing unnecessary add-ons can help to keep Blekko Redirect attacks away from your browser, and Blekko Redirects should always be treated with anti-malware software whenever necessary.

When Freedom from Spam Turns into a Blekko Redirect Dilemma


Blekko Redirects are just one of means of multiple attacks that are used by Blekko.com’s corresponding toolbar and related browser hijackers. These attacks are used to inflate Blekko.com’s traffic and may also block your ability to access other sites, especially competing search engines. SpywareRemove.com malware research team notes that common methods of infection by Blekko redirecting PC threats include:
  • Drive-by-downloads by affiliated sites of Blekko.com that install the ‘Spam Free Search Bar’ add-on without your permission.
  • Bundled installations with instant messaging programs and other social networking applications.
    Download SpyHunter Spyware Scanner
    In this case, you may see an opt-in or opt-out box that will allow you to install the original program without also getting an unwanted helping of a Blekko Redirect-causing toolbar.

Even though Blekko.com markets itself as a site with a heavy emphasis on safety for the visitor, SpywareRemove.com malware experts are forced to advise against installing any software or browser add-on that may cause Blekko Redirect attacks until the company cleans up its act. Many components of browser hijackers for Blekko Redirect can often be identified by the text string ‘Blekkotb’.

The Ultimate Result of Placing Your Trust in Blekko’s Hands


Blekko Redirect attacks may either lock your homepage to Blekko.com or redirect you to Blekko.com once you try to use a completely different search engine. Sadly, this is just the tip of the iceberg, as Blekko Redirect-related PC threats have also been observed to:
  • Launch pop-ups, potentially with malicious content.
  • Make unwanted additions to your bookmarks/favorites.
  • Promote scamware products.
  • Alter website content by adding links to keywords. This content can appear on sites that don’t normally display such links in their text.

Blekko Redirect-based PC threats have been seen in both 2012 and the preceding year, and SpywareRemove.com malware experts encourage you to disinfect your PC with appropriate software if you’ve had any run-ins with a Blekko Redirecting toolbar or other Blekko-promoting form of browser hijacker.

Blekko Redirect Automatic Detection Tool (Recommended)


Is your PC infected with Blekko Redirect? To safely & quickly detect Blekko Redirect, we highly recommend you run the malware scanner listed below.



Technical Details

File System Modifications

Tutorials: If you wish to learn how to remove malware components manually, you can read the tutorials on how to find malware, kill unwanted processes, remove malicious DLLs and delete other harmful files. Always be sure to back up your PC before making any changes.
  • The following files were created in the system:
    # File Name
    1 %AppData%\blekkotb\dtx.ini
    2 %AppData%\blekkotb\guid.dat
    3 %AppData%\blekkotb\log.txt
    4 %AppData%\blekkotb\messages\messageTypes.xml
    5 %AppData%\blekkotb\widgets_cache\category_cache.xml
    6 %AppData%\blekkotb\widgets_cache\widget_cache.xml
    7 %AppData%\blekkotb\preferences.dat
    8 %AppData%\blekkotb\stats.dat
    9 %Temp%\blekko-manifest.xml
    10 %ProgramFiles%\blekkotb\manifest.xml
    11 %Temp%\nsk3.tmp\nsProcess.dll
    12 %Temp%\nsk3.tmp\UAC.dll
    13 %Temp%\nsk3.tmp\xml.dll
    14 %Temp%\nsz7.tmp
    15 %ProgramFiles%\blekkotb\auxi\blekkoAu.dll
    16 %ProgramFiles%\blekkotb\auxi\config.xml
    17 %ProgramFiles%\blekkotb\blekkoDx.dll
    18 %ProgramFiles%\blekkotb\blekkotb.dll
    19 %ProgramFiles%\blekkotb\chrome\content\custom.js
    20 %ProgramFiles%\blekkotb\chrome\content\lib\about.xml
    21 %ProgramFiles%\blekkotb\chrome\content\lib\dtxpanel.xul
    22 %ProgramFiles%\blekkotb\chrome\content\lib\dtxpaneltransparent.xul
    23 %ProgramFiles%\blekkotb\chrome\content\lib\dtxpanelwin.xul
    24 %ProgramFiles%\blekkotb\chrome\content\lib\dtxprefwin.xul
    25 %ProgramFiles%\blekkotb\chrome\content\lib\dtxtransparentwin.xul
    26 %ProgramFiles%\blekkotb\chrome\content\lib\dtxwin.xul
    27 %ProgramFiles%\blekkotb\chrome\content\lib\emailnotifierproviders.xml
    28 %ProgramFiles%\blekkotb\chrome\content\lib\external.js
    29 %ProgramFiles%\blekkotb\chrome\content\lib\neterror.xhtml
    30 %ProgramFiles%\blekkotb\chrome\content\lib\rsspreview.html
    31 %ProgramFiles%\blekkotb\chrome\content\lib\rsswin.xml
    32 %ProgramFiles%\blekkotb\chrome\content\lib\rsswin.xsl
    33 %ProgramFiles%\blekkotb\chrome\content\modules\datastore.jsm
    34 %ProgramFiles%\blekkotb\chrome\content\modules\nsDragAndDrop.js
    35 %ProgramFiles%\blekkotb\chrome\content\newtab\images\btn_search.gif
    36 %ProgramFiles%\blekkotb\chrome\content\newtab\images\bullet.gif
    37 %ProgramFiles%\blekkotb\chrome\content\newtab\images\field_bg.gif
    38 %ProgramFiles%\blekkotb\chrome\content\newtab\images\powered_by_yahoo.gif
    39 %ProgramFiles%\blekkotb\chrome\content\newtab\newtab.html
    40 %ProgramFiles%\blekkotb\chrome\content\preferences.xml
    41 %ProgramFiles%\blekkotb\chrome\content\toolbar.htm
    42 %ProgramFiles%\blekkotb\chrome\content\toolbar.xul
    43 %ProgramFiles%\blekkotb\chrome\content\widgets\net.vmn.www.BlekkoMap\css\dialog.css
    44 %ProgramFiles%\blekkotb\chrome\content\widgets\net.vmn.www.YouTube_v2\css\dialog.css
    45 %ProgramFiles%\blekkotb\chrome\content\widgets\net.vmn.www.BlekkoMap\images\arrow-grey.png
    46 %ProgramFiles%\blekkotb\chrome\content\widgets\net.vmn.www.Coupons_v2\images\arrow-grey.png
    47 %ProgramFiles%\blekkotb\chrome\content\widgets\net.vmn.www.MyStartFacebook\images\arrow-grey.png
    48 %ProgramFiles%\blekkotb\chrome\content\widgets\net.vmn.www.YouTube_v2\images\arrow-grey.png
    49 %ProgramFiles%\blekkotb\chrome\content\widgets\net.vmn.www.BlekkoMap\images\arrows_grey-left.gif
    50 %ProgramFiles%\blekkotb\chrome\content\widgets\net.vmn.www.Coupons_v2\images\arrows_grey-left.gif
    51 %ProgramFiles%\blekkotb\chrome\content\widgets\net.vmn.www.MyStartFacebook\images\arrows_grey-left.gif
    52 %ProgramFiles%\blekkotb\chrome\content\widgets\net.vmn.www.YouTube_v2\images\arrows_grey-left.gif
    53 %ProgramFiles%\blekkotb\chrome\content\widgets\net.vmn.www.BlekkoMap\images\arrows_grey-right.gif
    54 %ProgramFiles%\blekkotb\chrome\content\widgets\net.vmn.www.Coupons_v2\images\arrows_grey-right.gif
    55 %ProgramFiles%\blekkotb\chrome\content\widgets\net.vmn.www.MyStartFacebook\images\arrows_grey-right.gif
    56 %ProgramFiles%\blekkotb\chrome\content\widgets\net.vmn.www.YouTube_v2\images\arrows_grey-right.gif
    57 %ProgramFiles%\blekkotb\chrome\content\widgets\net.vmn.www.BlekkoMap\images\bg.gif
    58 %ProgramFiles%\blekkotb\chrome\content\widgets\net.vmn.www.BlekkoMap\images\btn-search-over.png
    59 %ProgramFiles%\blekkotb\chrome\content\widgets\net.vmn.www.YouTube_v2\images\btn-search-over.png
    60 %ProgramFiles%\blekkotb\chrome\content\widgets\net.vmn.www.BlekkoMap\images\btn-search.png
    61 %ProgramFiles%\blekkotb\chrome\content\widgets\net.vmn.www.YouTube_v2\images\btn-search.png
    62 %ProgramFiles%\blekkotb\chrome\content\widgets\net.vmn.www.BlekkoMap\images\throbber.gif
    63 %ProgramFiles%\blekkotb\chrome\content\widgets\net.vmn.www.MyStartFacebook\images\throbber.gif
    64 %ProgramFiles%\blekkotb\chrome\content\widgets\net.vmn.www.YouTube_v2\images\throbber.gif
    65 %ProgramFiles%\blekkotb\chrome\content\widgets\net.vmn.www.BlekkoMap\index.html
    66 %ProgramFiles%\blekkotb\chrome\content\widgets\net.vmn.www.BlekkoMap\skin\css\dialog.css
    67 %ProgramFiles%\blekkotb\chrome\content\widgets\net.vmn.www.BlekkoMap\skin\images\1x1_transparent.png
    68 %ProgramFiles%\blekkotb\chrome\content\widgets\net.vmn.www.BlekkoMap\skin\images\bg.gif
    69 %ProgramFiles%\blekkotb\chrome\content\widgets\net.vmn.www.BlekkoMap\skin\images\btn-search.png
    70 %ProgramFiles%\blekkotb\chrome\content\widgets\net.vmn.www.BlekkoMap\skin\images\btn-wide-close-over.png
    71 %ProgramFiles%\blekkotb\chrome\content\widgets\net.vmn.www.BlekkoMap\skin\images\btn-wide-close.png
    72 %ProgramFiles%\blekkotb\chrome\content\widgets\net.vmn.www.BlekkoMap\skin\images\btn_close_x.gif
    73 %ProgramFiles%\blekkotb\chrome\content\widgets\net.vmn.www.BlekkoMap\skin\images\default.png
    74 %ProgramFiles%\blekkotb\chrome\content\widgets\net.vmn.www.BlekkoMap\skin\images\transparent.gif
    75 %ProgramFiles%\blekkotb\chrome\content\widgets\net.vmn.www.Coupons_v2\skin\images\transparent.gif
    76 %ProgramFiles%\blekkotb\chrome\content\widgets\net.vmn.www.MyStartFacebook\skin\images\transparent.gif
    77 %ProgramFiles%\blekkotb\chrome\content\widgets\net.vmn.www.Twitter\skin\images\transparent.gif
    78 %ProgramFiles%\blekkotb\chrome\content\widgets\net.vmn.www.YouTube_v2\skin\images\transparent.gif
    79 %ProgramFiles%\blekkotb\chrome\skin\lib\panels\default\images\transparent.gif
    80 %ProgramFiles%\blekkotb\chrome\content\widgets\net.vmn.www.BlekkoMap\skin\images\win-btm-left.png
    81 %ProgramFiles%\blekkotb\chrome\content\widgets\net.vmn.www.BlekkoMap\skin\images\win-btm-mdl.png
    82 %ProgramFiles%\blekkotb\chrome\content\widgets\net.vmn.www.BlekkoMap\skin\images\win-btm-right-resize.png
    83 %ProgramFiles%\blekkotb\chrome\content\widgets\net.vmn.www.BlekkoMap\skin\images\win-btm-right.png
    84 %ProgramFiles%\blekkotb\chrome\content\widgets\net.vmn.www.BlekkoMap\skin\main.html
    85 %ProgramFiles%\blekkotb\chrome\content\widgets\net.vmn.www.BlekkoMap\skin\scripts\defscript.js
    86 %ProgramFiles%\blekkotb\chrome\content\widgets\net.vmn.www.BlekkoMap\tb_icon.png
    87 %ProgramFiles%\blekkotb\chrome\content\widgets\net.vmn.www.BlekkoMap\widget.js
    88 %ProgramFiles%\blekkotb\chrome\content\widgets\net.vmn.www.BlekkoMap\widget.xml
    89 %ProgramFiles%\blekkotb\chrome\content\widgets\net.vmn.www.BlekkoMap\widget_version.txt
    90 %ProgramFiles%\blekkotb\chrome\content\widgets\net.vmn.www.YouTube_v2\widget_version.txt
    91 %ProgramFiles%\blekkotb\chrome\content\widgets\net.vmn.www.Coupons_v2\.project
    92 %ProgramFiles%\blekkotb\chrome\content\widgets\net.vmn.www.Coupons_v2\alert_coupon.css
    93 %ProgramFiles%\blekkotb\chrome\content\widgets\net.vmn.www.Coupons_v2\arrow-next-off.png
    94 %ProgramFiles%\blekkotb\chrome\content\widgets\net.vmn.www.Coupons_v2\arrow-next.png
    95 %ProgramFiles%\blekkotb\chrome\content\widgets\net.vmn.www.Coupons_v2\btn-next-blue.png
    96 %ProgramFiles%\blekkotb\chrome\content\widgets\net.vmn.www.Coupons_v2\arrow-previous-off.png
    97 %ProgramFiles%\blekkotb\chrome\content\widgets\net.vmn.www.Coupons_v2\arrow-previous.png
    98 %ProgramFiles%\blekkotb\chrome\content\widgets\net.vmn.www.Coupons_v2\btn-previous-blue.png
    99 %ProgramFiles%\blekkotb\chrome\content\widgets\net.vmn.www.Coupons_v2\bg-coupon-blue.png
    100 %ProgramFiles%\blekkotb\chrome\content\widgets\net.vmn.www.Coupons_v2\bg-save.png
    101 %ProgramFiles%\blekkotb\chrome\content\widgets\net.vmn.www.Coupons_v2\blank_image.png
    102 %ProgramFiles%\blekkotb\chrome\content\widgets\net.vmn.www.Coupons_v2\border-radius.htc
    103 %ProgramFiles%\blekkotb\chrome\content\widgets\net.vmn.www.Coupons_v2\btn-getcoupon.png
    104 %ProgramFiles%\blekkotb\chrome\content\widgets\net.vmn.www.Coupons_v2\btn-wide-close-over.png
    105 %ProgramFiles%\blekkotb\chrome\content\widgets\net.vmn.www.Coupons_v2\skin\images\btn-wide-close-over.png
    106 %ProgramFiles%\blekkotb\chrome\content\widgets\net.vmn.www.MyStartFacebook\skin\images\btn-wide-close-over.png
    107 %ProgramFiles%\blekkotb\chrome\content\widgets\net.vmn.www.Twitter\skin\images\btn-wide-close-over.png
    108 %ProgramFiles%\blekkotb\chrome\content\widgets\net.vmn.www.YouTube_v2\skin\images\btn-wide-close-over.png
    109 %ProgramFiles%\blekkotb\chrome\skin\lib\panels\default\images\btn-wide-close-over.png
    110 %ProgramFiles%\blekkotb\chrome\content\widgets\net.vmn.www.Coupons_v2\btn-wide-close.png
    111 %ProgramFiles%\blekkotb\chrome\content\widgets\net.vmn.www.Coupons_v2\skin\images\btn-wide-close.png
    112 %ProgramFiles%\blekkotb\chrome\content\widgets\net.vmn.www.MyStartFacebook\skin\images\btn-wide-close.png
    113 %ProgramFiles%\blekkotb\chrome\content\widgets\net.vmn.www.Twitter\skin\images\btn-wide-close.png
    114 %ProgramFiles%\blekkotb\chrome\content\widgets\net.vmn.www.YouTube_v2\skin\images\btn-wide-close.png
    115 %ProgramFiles%\blekkotb\chrome\skin\lib\panels\default\images\btn-wide-close.png
    116 %ProgramFiles%\blekkotb\chrome\content\widgets\net.vmn.www.Coupons_v2\checked.png
    117 %ProgramFiles%\blekkotb\chrome\content\widgets\net.vmn.www.Coupons_v2\coupon-activated.png
    118 %ProgramFiles%\blekkotb\chrome\content\widgets\net.vmn.www.Coupons_v2\images\coupon-activated.png
    119 %ProgramFiles%\blekkotb\chrome\content\widgets\net.vmn.www.Coupons_v2\couponTooltip.js
    120 %ProgramFiles%\blekkotb\chrome\content\widgets\net.vmn.www.Coupons_v2\css\appversion.css
    121 %ProgramFiles%\blekkotb\chrome\content\widgets\net.vmn.www.Coupons_v2\css\dialog.css
    122 %ProgramFiles%\blekkotb\chrome\content\widgets\net.vmn.www.Coupons_v2\css\IE7Styles.css
    123 %ProgramFiles%\blekkotb\chrome\content\widgets\net.vmn.www.Coupons_v2\ico-coupon-hover.png
    124 %ProgramFiles%\blekkotb\chrome\content\widgets\net.vmn.www.Coupons_v2\ico-coupon.png
    125 %ProgramFiles%\blekkotb\chrome\content\widgets\net.vmn.www.Coupons_v2\ico-dollar.png
    126 %ProgramFiles%\blekkotb\chrome\content\widgets\net.vmn.www.Coupons_v2\skin\images\default.png
    127 %ProgramFiles%\blekkotb\chrome\content\widgets\net.vmn.www.Coupons_v2\tb_icon.png
    128 %ProgramFiles%\blekkotb\chrome\content\widgets\net.vmn.www.Coupons_v2\images\bg_top.png
    129 %ProgramFiles%\blekkotb\chrome\content\widgets\net.vmn.www.Coupons_v2\images\btn-back.png
    130 %ProgramFiles%\blekkotb\chrome\content\widgets\net.vmn.www.Coupons_v2\images\btn-getcoupon.png
    131 %ProgramFiles%\blekkotb\chrome\content\widgets\net.vmn.www.Coupons_v2\images\btn-search.png
    132 %ProgramFiles%\blekkotb\chrome\content\widgets\net.vmn.www.Coupons_v2\images\delete.png
    133 %ProgramFiles%\blekkotb\chrome\content\widgets\net.vmn.www.MyStartFacebook\images\delete.png
    134 %ProgramFiles%\blekkotb\chrome\content\widgets\net.vmn.www.Coupons_v2\images\loader.gif
    135 %ProgramFiles%\blekkotb\chrome\content\widgets\net.vmn.www.Coupons_v2\images\save.png
Posted: June 4, 2012 | By
Share:
Follow Me on Pinterest More More
Threat Level: 5/10
1 Star2 Stars3 Stars4 Stars5 Stars (1 votes, average: 2.00 out of 5)
Loading ... Loading ...
Rate this article:

Leave a Reply

What is 8 + 9 ?
Please leave these two fields as-is:
IMPORTANT! To be able to proceed, you need to solve the following simple math (so we know that you are a human) :-)