Categorized | Antivirus

Windows Diagnostic Adware Removal Instructions

The Emsisoft malware research team has discovered a new outbreak of the Windows Diagnostic adware. Emsisoft Anti-Malware detects this malware as Adware.Win32.WindowsDiagnostic.

Windows Diagnostic is a rogue application. A rogue application tries to trick you by displaying false positive/misleading scan results report, which says that your computer has a problem, or infected with viruses or trojan, but you will not be able to fix it before you purchase.

Variants of the rogue defragmenter:

Create new files:

  • %AllUsersProfile%\Application Data\%random%
  • %AllUsersProfile%\Application Data\%random%.exe
  • %AllUsersProfile%\Application Data\EAGueaRwrDlOoPP.exe
  • %AllUsersProfile%\Application Data\~%random%
  • %AllUsersProfile%\Application Data\~%random%r
  • %UserProfile%\Desktop\Windows Diagnostic.lnk
  • %UserProfile%\Local Settings\Temp\tmp3.tmp
  • %UserProfile%\Start Menu\Programs\Windows Diagnostic\
  • %UserProfile%\Start Menu\Programs\Windows Diagnostic\Uninstall Windows Diagnostic.lnk
  • %UserProfile%\Start Menu\Programs\Windows Diagnostic\Windows Diagnostic.lnk

Create/modify registry entries:

  • HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\system\
    DisableTaskMgr: 0×00000001
  • HKEY_CURRENT_USER\Software\
    75fa38b7-8b94-4995-ad32-52e938867954:
    BD: 43 00 3A 00 5C 00 44 00 6F 00 63 00 75 00 6D 00 65 00 6E 00 74 00 73 00 20 00 61 00…
  • HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\Main\
    Use FormSuggest: “Yes”
  • HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Internet Settings\
    WarnonBadCertRecving: 0×00000000
    CertificateRevocation: 0×00000000
  • HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Policies\ActiveDesktop\
    NoChangingWallPaper: 0×00000001
  • HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Policies\Associations\
    LowRiskFileTypes: “/{hq:/s`s:/ogn:/uyu:/dyd:/c`u:/bnl:/ble:/sdf:/lrh:/iul:/iulm:/fhg:/clq:/kqf:/`wh:/lqf:/lqdf:/lnw:/lq2:/l2t:/v`w:/rbs:”
  • HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Policies\Attachments\
    SaveZoneInformation: 0×00000001
  • HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Policies\System\
    DisableTaskMgr: 0×00000001
  • HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Run\
    EAGueaRwrDlOoPP: “%AllUsersProfile%\Application Data\EAGueaRwrDlOoPP.exe”
  • HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\Download\
    CheckExeSignatures: “no”
  • HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Explorer\Advanced\
    Hidden: 0×00000000
  • HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Explorer\Advanced\
    ShowSuperHidden: 0×00000000

Screenshots:

How to remove the infection of Windows Diagnostic (Adware.Win32.WindowsDiagnostic)?

To delete this malware infection, please download and install Emsisoft Anti-Malware. Run a full scan on all drives and move all detected items to the quarantine.

Related Posts
  • Windows Simple Protector Adware Removal Instructions
    The Emsisoft malware research team has discovered a new outbreak of the Windows Simple Protector adware. Emsisoft Anti-Malware detects this malware as Adware.Win32.WindowsSimpleProtector. Windo...
  • Windows Restore Adware Removal Instructions
    The Emsisoft malware research team has discovered a new outbreak of the Windows Restore adware. Emsisoft Anti-Malware detects this malware as Adware.Win32.WindowsRestore. Windows Restore is a r...
  • Windows Repair Adware Removal Instructions
    The Emsisoft malware research team has discovered a new outbreak of the Windows Repair adware. Emsisoft Anti-Malware detects this malware as Adware.Win32.WindowsRepair. Windows Repair is a rogu...
  • Windows Process Regulator Adware Removal Instructions
    The Emsisoft malware research team has discovered a new outbreak of the Windows Process Regulator adware. Emsisoft Anti-Malware detects this malware as Adware.Win32.WindowsProcessRegulator. Win...
  • Windows Passport Utility Adware Removal Instructions
    The Emsisoft malware research team has discovered a new outbreak of the Windows Passport Utility adware. Emsisoft Anti-Malware detects this malware as Adware.Win32.WindowsPassportUtility. Windo...
  • Windows Recovery Adware Removal Instructions
    The Emsisoft malware research team has discovered a new outbreak of the Windows Recovery adware. Emsisoft Anti-Malware detects this malware as Adware.Win32.WindowsRecovery. Windows Recovery is ...
  • Windows Remedy Adware Removal Instructions
    The Emsisoft malware research team has discovered a new outbreak of the Windows Remedy adware. Emsisoft Anti-Malware detects this malware as Adware.Win32.WindowsRemedy. Windows Remedy is a ...
  • Windows Servant System Adware Removal Instructions
    The Emsisoft malware research team has discovered a new outbreak of the Windows Servant System adware. Emsisoft Anti-Malware detects this malware as Adware.Win32.WindowsServantSystem. Windows S...
  • Windows Troublemakers Agent Adware Removal Instructions
    The Emsisoft malware research team has discovered a new outbreak of the Windows Troublemakers Agent adware. Emsisoft Anti-Malware detects this malware as Adware.Win32.WindowsTroublemakersAgent....
  • Windows Troubles Remover Adware Removal Instructions
    The Emsisoft malware research team has discovered a new outbreak of the Windows Troubles Remover adware. Emsisoft Anti-Malware detects this malware as Adware.Win32.WindowsTroublesRemover. Windo...

Comments are closed.

Security Status

Beware Facebook "Timeline" scams http://t.co/W5EW0cVv
5 months ago
Nigerian government (unknowingly) hosts phishing website http://t.co/uQd42ENw
5 months ago
PCMag Awards McAfee All Access its Editors’ Choice: SANTA CLARA, Calif.--(BUSINESS WIRE)--McAfee today announced... http://t.co/FakV7Vd8
5 months ago
RT @mikko: I hadn't noticed Google Maps has added 3D models of buildings. Here's a (very accurate) view of F-Secure HQ in Helsinki http://t.co/IKfAZlak
5 months ago
North Koreans aren't known for their online presence. But others may be lured into clicking Kim Jong-Il 'videos' too http://t.co/yQOon6YT
5 months ago
How to Protect Your Professional Reputation on Facebook Timeline http://t.co/I4bcR2VN
5 months ago
This is pretty impressive from @Softpedia: Facebook scans 2 trillion link clicks and blocks 220 million posts each day http://t.co/vKsn9gNl
5 months ago
Need for integrated approach to security in industrial control systems - http://t.co/tPBCNOow with @PikeResearch
5 months ago
Some free-based music we play at work http://t.co/xu5agZfc
5 months ago
Japan’s cyber defense weapon: a virus. It includes quotes by @Luis_Corrons via @InfosecurityMag
5 months ago