Monday, July 21, 2008

lannet.exe

This spyware is really annoying, I spent almost full days to diagnose the problems. The first symptom is quiet annoying, you will get a slow browsing issue, and in the end you won't be able to browse at all, except for some Microsoft sites. I don't know why we can browse some Microsoft sites, while the other is completely impossible. It seems that this spyware/malware is messing the winsock of Windows, making all browsers can not browse:

In IE 6 you will get an error message "Internet Explorer could not find the site"; in IE 7 you will get nearly the same message saying it couldn't open or find the site and strangely the address will change into "http:///" with triple slash; and in Firefox the browser is not showing anything at all, not even showing any sign of browsing.

What I did to remove the threat was simply removing the "lannet.exe" entry in the registry. And it seems that it's removing the problem. It will be best if we also scan the computer using the updated antivirus software.