Wondershare appservices virus or just a pain in the neck I want it gone

Goodness knows where I got it from, it would only have been a legit site. Apparently it’s been on my PC for months, I only found out yesterday as it was hogging 96% of ram on my Windows 8.1 PC. I’ve spent all day trying to find out how to remove it, without success. It does not appear in progs and apps so it cannot be un-installed from there. I’ve run, albeit extremely slowly, both Malwarebytes and Avast and both state there is no threat identified. Spybot will not run. It only becomes a nuisance when I plug in the ethernet cable I’ve attached some pngs, hoping that this will give a better idea of the situation so that someone might be able to help me. I’ve tried to remove it from Start-Up (as Administrator) but that tells me to go to Task Manager to stop it from running, when I get to Task Manager there is no option to stop it. Can anyone give me any guidance please?

magna86

Your message says "The fixes are specific to your problem and should only be used for this issue on this machine my problem is on my windows 8 PC, I’m contacting you on my Windows 7 PC. I have downloaded mwb and farbar and will have to transfer them to my windows 8 pc via usb then copy the reports and transfer them back to my windows 7 pc to forward to you. I have no other option.

Instructions https://forum.avast.com/index.php?topic=194892.0

I ran mwb and farbar as instructed. Farbar saved the logs and they are attached. mwb reported no threats, it said that it had saved the scan report successfully to the desktop, but it did not appear there, so I ran the scan again and copied and pasted the result into a text file and that is attached, I named it mwb report 2nd scan. I’ve attached a snip of what came up as the desktop showing only Handbrake, but this isn’t my desktop.

Wanting to learn, I took a look at the Farbar reports and am gobsmacked at what seem to be hundreds of porn and sex sites, it weren’t me guv :o

Seems like a nasty virus, seems like it’s been on my PC since Jan 2017 but only just started hogging 96% of memory, so how do I get rid of it, how did it get through Avast, why didn’t mwb pick it up during the many scans? please help and please bear in mind that I am contacting you on a different PC because as soon as I connect to the web wshare kicks in and prevents me from doing anything.

You haven’t attached the logs.
Please do so.

My apologies, I thought that I was attaching them all in the one box, my mistake.

In this case, a user with Administrator level access / privileges must run the scans and the fixes. On this machine that would be users either Jaye or Aunt Sally.

Scanned with Administrator access. Couldn’t update either mwb or farbar, as soon as I plug in the ethernet cable Wondershare goes all out to 97% of memory and I get no access.

Administrator logs are now attached, apologies again.

Please run these steps with an account with Administrator level access. Thank you.

FIRST >>>>

Please go to START (Windows Orb) >> Control Panel >> Uninstall a Program or Programs and Features and remove the following (if listed):

[b]Duplicate Cleaner Free 3.2.7

QuickTime 7[/b]

To do so, left clicking on the name once and then click Uninstall/Change at the bar above the list window.

Follow the prompts of the uninstaller BUT please read carefully any questions it asks before answering; some uninstallers will try and deceive you into keeping the software.

SECOND >>>>

https://sites.google.com/site/cannedfixes/farbar-recovery-scan-tool/FRST.gif
Fix with Farbar Recovery Scan Tool

https://sites.google.com/site/cannedfixes/home/hosted-images-formatting/icon_exclaim.gif
[b] This fix was created for this user for use on that particular machine.
https://sites.google.com/site/cannedfixes/home/hosted-images-formatting/icon_exclaim.gif

https://sites.google.com/site/cannedfixes/home/hosted-images-formatting/icon_exclaim.gif
Running it on another one may cause damage and render the system unstable.
https://sites.google.com/site/cannedfixes/home/hosted-images-formatting/icon_exclaim.gif
[/b]
Download attached fixlist.txt file and save it to the Desktop:

Both files, FRST and fixlist.txt have to be in the same location or the fix will not work!

How is the system running now?

Do you use wondershare products? like wondershare video converter? the appservice is an update utility
try updating the product or contact wondershare maybe problem with app optimization. You can also disable it in the services(App would still work, but you cannot update).

Note: Im no expert, i need an adult, someone confirm.

I thought I had posted a response but I can’t find it. So, I followed instructions for FRST and Fixlist. It has been running now for 40 mins, it just says Fixing is in progress, please wait…

How long will it run for and what should I do if it doesn’t stop?

This fix is still running that’s 1 hour and 40 minutes now. What do I do?

the only comments I can make are that duplicate cleaner reported that it had been successfully uninstalled, Quick Time asked if it could make changes to which I replied Yes it didn’t report back but it disappeared from my list of programs. Malwarebytes put up an orange message saying:-

Real time protection layers turned off, one or more Real-Time Protection layers are turned off. Turn on all Real-Time Protection layers to block and prevent threats. There are 2 buttons one says Protection settings, the other says turn on (this box is orange. I haven’t clicked on either box, just left them as is.

I assume that you have noted from my messages that it’s a Windows 8 PC

I feel that the fix is not running properly, What do I do, I can’t leave the PC running overnight.

J

This fix is still running that's 1 hour and 40 minutes now. What do I do?
It probably hangs at "empty temp"

abort, reboot and try again.
If same problem just abort and wait for a reply from @dbrisendine, he will be back online tomorrow

Have you rebooted and run the fixlist again? Can you attach the Fixlog.txt file(s)?

Apologies for the delay, I’ve been out and about. Following advice I used task manager to end the task only to find that a fix log had been created very soon after the fix had started (log 17.16 attached). Also following instructions I ran the fix again, it hung again but this time I used task manager to end the task after about 30 minutes and found that a fix log had again been created very soon after the fix had started (log 21.06 also attached).

Because I’ve been out I haven’t yet run the ‘fixed PC’, I will do that later today.

In case ransomware gets on my PC, I regularly remove all my files to external hard drives, given that wondershare had apparently been on my PC since January, will any of my files have been infected?

Given that I had to uninstall Duplicate Cleaner and Quick Time are these files bad or can they be reinstalled?

Any idea how Wondershare got on my PC, I don’t, knowingly, have any of their products, never even heard of them until now.

J

Although the tool hung on removing a registry key, it looks like it did remove Wondershare. How is your system running now?

It appears that the malware / app was part of a “free phone tool” for Android phones.


AdwCleaner by Xplode

Download AdwCleaner from here or from here. Save the file to the desktop.

NOTE: If you are using IE 8 or above you may get a warning that stops the program from downloading. Just click on the warning and allow the download to complete.

Close all open windows and browsers.

  • Vista/7/8 users: Right click the AdwCleaner icon on the desktop, click Run as administrator and accept the UAC prompt to run AdwCleaner.
    You will see the following console:

http://i1351.photobucket.com/albums/p785/dbreeze2/Scanners%20screens/AdwCleaner_v6_start_zps5nymee4e.png

- Click the [b]Scan[/b] button and wait for the scan to finish.
- After the Scan has finished the window may or may not show what it found and above, in the progress bar, you will see: [b]Waiting for action. Please uncheck elements you don't want to remove.[/b]
- Click the [b]Clean[/b] button.
- [b]Everything checked[/b] will be deleted.
- When the program has finished cleaning a report appears.
- Once done it may ask to reboot, allow this

http://1.bp.blogspot.com/-vitKqfMQS4o/UEDylIQ7HJI/AAAAAAAABLc/Hx-IwqKoaxg/s1600/adwcleaner_delete_restart.jpg

  • On reboot a log will be produced; please attach that in your next reply. This report is also saved to C:\AdwCleaner\AdwCleaner[C#].txt

Optional:

NOTE: If you see AVG Secure Search being targeted for deletion, Here’s Why and Here. You can always Reinstall it.

have run AdwCleaner, log attached

How is your system running now?

To be honest, I am reluctant to even turn it on. This has been the first time that I have had any such problem, I am very careful and I don’t understand how it can be that wondershare had apparently been running on my PC since January with me being completely unaware, until last week, it really doesn’t bear thinking about and it has knocked my confidence a bit.

Will any of my files have been infected?

Also, will any of my files have been shared on the web?

Will I be getting a visit from the Vice Squad ::slight_smile:

Perhaps I should encrypt my files? If so, can you recommend a good encrypter?

Given that I had to uninstall Duplicate Cleaner and Quick Time are these files bad or can they be reinstalled?

It is now 3am, it’s too late now, I suppose I’ll have to pluck up the courage and try it out in the afternoon. I will reply when it’s been running for a while, in the meantime I would really appreciate it if you could comment on my concerns please?

You really did not have any infection. You had part of some free application that did not get removed when the rest of application was uninstalled.

Also, will any of my files have been shared on the web?
Again, this was not that type of issue. Your files appear to not have been a target at all.
Will I be getting a visit from the Vice Squad ::)
Not about this incident.
Perhaps I should encrypt my files? If so, can you recommend a good encrypter?
Encryption is a good idea but even better is backing-up your data. You can check out Paragon, Acronis and Macrum Refect for some good Home User backup software.
Given that I had to uninstall Duplicate Cleaner and Quick Time are these files bad or can they be reinstalled?
Quick Time is no longer being updated by Apple and is a security risk. Duplicate Cleaner is a "free" software that includes adware programs.
It is now 3am, it's too late now, I suppose I'll have to pluck up the courage and try it out in the afternoon. I will reply when it's been running for a while, in the meantime I would really appreciate it if you could comment on my concerns please?

UNderstood and will check later to see if you need anything else.