BleepingComputer.com: Using LSP-Fix to remove O10 Entries in HijackThis

Jump to content

How to use the self-help guides

This forum contains self-help guides on removing common malware and viruses. These guides can be advanced so please use them at your own risk.

If after following the self-help guide, or you can not find an appropriate guide, then you can receive step-by-step instructions directly from one of our experts by following the instructions in this topic:

Preparation Guide For Use Before Using Malware Removal Tools and Requesting Help
Page 1 of 1
  • You cannot start a new topic
  • This topic is locked

Using LSP-Fix to remove O10 Entries in HijackThis Self-Help Guide

#1 User is offline   Grinler 

  • Bleep Bleep!
  • PipPipPipPipPipPip
  • Find Topics
  • Group: Admin
  • Posts: 36,602
  • Joined: 24-January 04
  • Gender:Male
  • Location:USA

Posted 04 October 2004 - 11:35 AM

This self-help guide will walk you through using LSP-Fix to remove unwanted LSPs


Warnings:

Removing LSPs can cause your computers Internet connection to no longer work. If you follow these instructions carefully, you should not have a problem. If you feel that you are not comfortable doing this on your own, then please ask for help in our forums.

What are LSPs:

LSPs are programs that are attached to the networking protocols on Windows XP and 2000 computers. When a unwanted LSP connects to this chain, it has the ability to manipulate any data that passes through it manipulating it to their own desires. It is important to note that not all LSPs are bad, so it is important to do research as to whether or not the LSP you are going to remove is indeed unwanted. We will provide all the tools necessary, though, so that you can determine this.


Tools Needed for this fix:

Related Tutorials:

Symptoms in a HijackThis Log:

O10 - Unknown file in Winsock LSP: c:\windows\system32\cdlsp.dll
O10 - Unknown file in Winsock LSP: c:\windows\system32\lspak.dll




Instructions:

Checking to see if you have an LSP installed:

The first step in removing an LSP is to determine if one actually exists on your computer:
  1. Download HijackThis and extract it to c:\hijackthis.

  2. Navigate to the c:\hijackthis directory and double-click on HijackThis

  3. When the program starts, double-click on the HijackThis icon and then click on the Scan button.


    1. If you see any entries that start with O10, then you have an LSP installed on your machine. Write down the entry as it is shown for reference later. DO NOT FIX THESE ENTIES IN HIJACKTHIS.

    2. If there are no O10 entries, then you do not have an LSP installed on your machine and should not continue reading this tutorial

  4. Exit HijackThis


Identifying whether or not the LSP is unwanted or not:

If you did have a O10 entry in the HijackThis log, then we must determine if they are a legitimate entry or unwanted. To do this we reference an excellent compilation of known LSPs:
  1. Open your web browser and go to the following site: http://www.castlecops.com/LSPs.html
  2. Look through this list for the filename found when examining the HijackThis log. For example if the O10 entry found in the HijackThis log was:

    O10 - Unknown file in Winsock LSP: c:\windows\system32\lspak.dll

    You would look for the filename lspak.dll in the list on this web siteand would find that it is part of the malware Virtumundo. We therefore want to remove it.



Removing the LSP:


Now that we know the LSP is not wanted on our computer, we will remove it following these instructions:
  1. Download LSPFix from:

    LSP-Fix Download Link

  2. Once LSP-Fix is downloaded, extract the file to c:\lspfix.

  3. Close all windows on your computer.

  4. Navigate to c:\lspfix and run the lspfix.exe program.

  5. Put a checkmark in the I know what I'm doing checkbox.

  6. Now move all instances of the file that we determined was bad in the previous steps into the remove section by clicking on the button that points to the right (>>). Make sure that you ONLY move the particular file we identified previously and no other files as it can cause problems with your computer afterwards.

  7. Press the finish button.

  8. Then Reboot.
The LSP should now no longer be on your computer


This is a self-help guide. Use at your own risk.



BleepingComputer.com can not be held responsible for problems that may occur by using this information. If you would like help with any of these fixes, you can post a HijackThis log in our HijackThis Logs and Analysis forum.

If you have any questions about this self-help guide then please post those questions in our AntiVirus, Firewall and Privacy Products and Protection Methods forum and someone will help you.


Share this topic:


Page 1 of 1
  • You cannot start a new topic
  • This topic is locked

1 User(s) are reading this topic
0 members, 1 guests, 0 anonymous users