How Did My Computer Become Infected with Windows Diagnostic malware?

More likely than not, you visited an infected web page and were then infected with the trojan behind the rogue virus called Windows Diagnostic. Virus writers are becoming experts in SEO (search engine optimization) and are getting infected sites ranking very high in the search engines. Although these sites only rank high for a short time, they can do tremendous damage while they are showing up.

In this particular case, the computer I was cleaning up was infected when its owner went to the following sites from a Google search.

http://www.discountesteelauder.co.cc/78ke
http://www.mainezoocoupons.co.cc/bi4k


Neither site is operational now, but they did show up in search results and helped infect the computer with some nasty rogue malware called Windows Diagnostic. This malware is virtually identical to a number of other drive utility type scareware products like Windows Repair, Windows Scan, Windows Safe Mode, Windows Disk, and Windows Restore. It shows a PC Performance & Stability report and scares you into thinking your computer is about to crash...unless you purchase the product.

What Does Windows Diagnostic malware look like?

Windows Diagnostic Malware - Rogue Antivirus

The Windows Diagnostic malware presents a "PC Performance & Stability Report" when it pops up on your computer. This report shows the same sorts of alerts that many rogue antivirus type programs show. However, it takes things a step further. Instead of showing viruses, trojans, and other malicious programs that have invaded your computer, it tells you that your hard drive and computer are crashing with a variety of messages such as:

"Hard Drive Failure The system has detected a problem with one or more installed IDE / SATA hard disks. It is recommended that you restart the system"
"System Error An error occurred while reading system files. Run a system diagnostic utility to check your hard disk drive for errors"
"Critical Error Hard drive critical error. Run a system diagnostic utility to check your hard disk drive for errors. Windows can't find hard disk space. Hard drive error"
"Fix Disk Windows Diagnostic Diagnostics will scan the system to identify performance problems. Start or Cancel"
"Windows Diagnostic Diagnostics Windows detected a hard disk error. A problem with the hard drive sectors has been detected. It is recommended to download the following sertified <sic> software to fix the detected hard drive problems. Do you want to download recommended software?"
"Requested registry access is not allowed. Registry defragmentation required Read time of hard drive clusters less than 500 ms 32% of HDD space is unreadable Bad sectors on hard drive or damaged file allocation table GPU RAM temperature is critically high. Urgent RAM memory optimization is required to prevent system crash Drive C initializing error Ram Temperature is 83 C. Optimization is required for normal operation. Hard drive doesn't respond to system commands Data Safety Problem. System integrity is at risk. Registry Error - Critical Error"
"Critical Error! Damaged hard drive clusters detected. Private data is at risk"
"Critical Error Hard Drive not found. Missing hard drive"
"Critical Error RAM memory usage is critically high. RAM memory failure"
"Critical Error Windows can't find hard disk space. Hard drive error"
"Critical Error! Windows was unable to save all the data for the file \System32\496A8300. The data has been lost. This error may be caused by a failure of your computer hardware"
"Critical Error A critical error has occurred while indexing data stored on hard drive. System restart required"
"System Restore The system has been restored after a critical error. Data integrity and hard drive integrity verification required"
"Activation Reminder Windows Diagnostic Activation Advanced module activation required to fix detected errors and performance issues. Please purchase Advanced Module license to activate this software and enable all features"
"Low Disk Space You are running very low disk space on Local Disk (C:)"

What Does the Windows Diagnostic malware do to your system?


First of all, this program disables Task Manager so that it makes removing the pest that much harder. Beyond the fact that it pops up the annoying messages virtually non stop, it also does something even more devious, it sets the hidden attribute on virtually all files on the hard drive, so the desktop, Start Menu, Documents, etc show as blank. From the novices point of view, it appears the virus wiped all the information from the hard drive. A very scary thought indeed.

Because of the widespread havoc this malware causes, there are many steps involved in removing it

First read this information on how to fix the task manager and re-enable it,

Can I Remove Windows Diagnostic manually?


To try to remove the Windows Diagnostic malware manually you'll need to complete the following tasks. However, if you delete the wrong item in the registry it could render your computer unbootable. For this reason, do not try to remove this malware manually unless you are experienced in deleting files and removing items from the registry. In reality, its much easier to use a program such as Malwarebytes Anti-Malware to clean the system. This is covered in my step-by-step procedure below.

Stop Windows Diagnostic processes:
 [random name].exe
 
Disable Windows Diagnostic DLL files:
 %AllUsersProfile%\Application Data\[random].dll
 
Delete Windows Diagnostic Registry Entries:
 HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Run “[random].exe”
 HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Run “[random]”
 HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Policies\Associations “LowRiskFileTypes” = ‘/{hq:/s`s:/ogn:/uyu:/dyd:/c`u:/bnl:/ble:/sdf:/lrh:/iul:/iulm:/fhg:/clq:/kqf:/`wh:/lqf:/lqdf:/lnw:/lq2:/l2t:/v`w:/rbs:’
 HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Policies\Attachments “SaveZoneInformation” = ’1′
 HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\Download “CheckExeSignatures” = ‘no’
 HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\Main “Use FormSuggest” = ‘yes’
 HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Internet Settings “WarnonBadCertRecving” = ’0′
 HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Policies\System “DisableTaskMgr” = ’1′
 
Remove Windows Diagnostic files:
 %AllUsersProfile%\Application Data\~[random]
 %AllUsersProfile%\Application Data\~[random]
 %AllUsersProfile%\Application Data\[random].dll
 %AllUsersProfile%\Application Data\[random].exe
 %AllUsersProfile%\Application Data\[random]
 %AllUsersProfile%\Application Data\[random].exe

Step by Step Procedure for Removing Windows Diagnostic malware


1) Restart Your Computer in Safe Mode (with Networking) by pressing F8 when the computer boots and selecting the appropriate option.

2) If the malware program appears to still pop up even in Safe Mode, then follow these extra steps.

  • Click on Start, Run and type MSCONFIG and Press Enter (For Windows XP)
  • Click the Start Orb and type MSCONFIG and Press Enter (For Windows Vista and 7)
  • In the System Configuration Utility, click on the Startup tab and look for an entry that appears to be a random character named .exe file. In my case, the file was LoEwouCqpDax.exe. As you can see the file name is just a bunch of random characters and should be fairly easy to spot in the Startup section.
  • Once you've located this filename, uncheck it and click Ok. When the computer asks to restart, go ahead and restart in Safe Mode as in Step 1.

3) Now that the computer is somewhat stable, open a web browser and download Malwarebytes Anti-Malware from their site

4) After Malwarebytes has downloaded, install it and try to update it. In one particular occasion, it was unable to update and I had to update it manually. In order to update Malwarebytes manually, you'll need to download the mbam-rules.exe file and run it.

5) Now proceed to run Malwarebytes Anti-Malware and remove any problems it finds.

6) After cleaning and rebooting the system, you may be still experiencing a very annoying aspect of this trojan. It hides files over the entire hard drive. Yes, you can simply go into the system and Show Hidden Files, but this unhides system files and other Windows files that should not be deleted. By hiding these important files, you aren't going to delete something you really need by accident.  So, how do we unhide the normal files, but keep the system files hidden? With a command prompt command!

To Unhide files and folders that Windows Diagnostic and other programs hide


For Windows XP

1) Click on Start, Run
2) Type CMD and press Enter
3) At the command prompt type the following and press Enter

CD \

4) Now the command prompt should show the root folder of the hard drive. Most likely C:\
5) At the command prompt type the following and press Enter

ATTRIB -H *.* /S /D

This command will unhide the files that are currently hidden. Because the important system files have a system attribute attached to them as well, the above command will not work for them and they will be skipped and kept hidden from prying eyes.

This command will take some time, so dont be afraid if it takes anywhere from a few minutes to half an hour to finish. What the command does is simple. It removes the hidden attribute from all files on the hard drive. The /S parameter tells it to search the current folder and all subfolders, while the /D parameter processes tthe folders as well.

6) Type Exit and press Enter when the procedure is complete. Then reboot your computer

For Windows Vista/7

1) Click on Start, All Programs
2) Click Accessories and Find Command Prompt
3) Right click on the Command Prompt option and choose Run as Administrator
4) At the command prompt type the following and press Enter

CD \

5) Now the command prompt should show the root folder of the hard drive. Most likely C:\
6) At the command prompt type the following and press Enter

ATTRIB -H *.* /S /D

This command will unhide the files that are currently hidden. Because the important system files have a system attribute attached to them as well, the above command will not work for them and they will be skipped and kept hidden from prying eyes.

This command will take some time, so dont be afraid if it takes anywhere from a few minutes to half an hour to finish. What the command does is simple. It removes the hidden attribute from all files on the hard drive. The /S parameter tells it to search the current folder and all subfolders, while the /D parameter processes tthe folders as well.

7) Type Exit and press Enter when the procedure is complete. Then reboot your computer

Run a Thorough Virus Scan


Finally, as an extra precaution, scan your computer with online virus scanner like Housecall, BitDefender, or eTrust or download and install an antivirus program and run a complete scan. A list of online scanners is below, some however will only scan but not remove issues.
 

Online Virus Checkers
Trend Micro Housecall - will scan and remove threats
BitDefender Scan Online - will scan and remove threats
ESet (NOD32) Online Scanner
Kaspersky Online Scan - will scan and remove threats
Panda Activescan - appears to only scan for but not remove threats
McAfee FreeScan - appears to only scan for but not remove threats
eTrust Antivirus Web Scanner - will scan and remove threats
Symantec Security Check - will scan and remove threats
Dr.Web Online Check - user can upload and test for threats on particular files

Trojan Scanner
TrojanScan by WindowsSecurity.com

Spyware Scanners
Malwarebytes AntiMalware
Super AntiSpyware
Spybot Search and Destroy


Congratulations! Your computer should be free of the Windows Diagnostic, Windows Restore, Windows Repair or other similar named nasty.

Written by Mark Hasting





Links to Other Important Information

Support for Windows XP and Windows Vista without latest service packs ends in 2010

How to Fix 500 Internal Server Error in PHP 5.4 script

Computer shows Stop error and Continously Reboots after SP3 installed.

Product Key Does Not Match Current Windows SKU Error

Review of FastAgain PC Booster and How to Uninstall it

How to Remove MSBLAST.EXE worm

How to Remove Content Advisor Password in Internet Explorer

How to Fix Google Chrome not Opening Web Pages or Settingsnew

How to Remove Incredimail Automatically

How to Fix Problem of Limited or No Connectivity After installing Windows XP Service Pack 2

How to Recover From a Corrupted Registry in Windows XP

How to Speed Up Windows Boot Time

Acer ERecovery Service is Not Available

Acer Recovery CD Restore Failed Reason: 0xf0000051

How to Fix Problem with No Active Mixer Devices Available in Windows XP

Parents Guide to MySpace.com - a report every parent should read

Save and Restore Desktop Layout of Icons

What is Windows Genuine Advantage and How to Overcome Problems With It

Change Forgotten Administrator Password in Windows XP/2000/Vista

Not Enough Server Storage Error When Connecting to Computer on Network

Installing Windows Vista Upgrade on a Blank Hard Drive

How to Delete Your Windows Vista Logon Password

Remove Unwanted Icons from the Windows Vista Welcome Center

Cannot Connect to Network Printer with Windows Vista

How to Wipe, Delete, Degauss, and Destroy Data on a Hard Drive

Fixing RTHDCPL.EXE - Illegal System DLL Relocation Error in Windows XP

How to Fix Blank or Missing Title Bar in IE9

Unable to Open New Tab in IE9 - Spinning Favicon

Fix 404 Errors for /apple-touch-icon-precomposed.png and /apple-touch-icon.png

What is the Config.Msi folder and Can I Delete It?

Flash Player Installation Issues

How to Set Yahoo Mail as your Default Email Program

Unknown File in Winsock LSP - NWPROVAU.DLL - Can it be Removed?

How to Delete a Service in Windows Vista

How to Disable the On-Screen Keyboard in Windows Vista

Make Disk Cleanup Run Faster

What is CTFMON.EXE and How Can I Remove It

How to Export MSN Favorites to Internet Explorer

How to Fix Registry Editing Has Been Disabled By Your Administrator Error

How to Change Default Editor in Windows and Fax Viewer

How to Fix Problem when Windows Security Center reports multiple antivirus programs installed

How to Fix Problem when Windows Updates will download but will not install

How to Fix Problem when Windows Automatic Updates Service wont Start

Cannot Download Files With Internet Explorer

How to Keep Your Computer Up-to-Date

How to Fix the Prompt for Click to Run an ActiveX Control on this webpage

How to Remove "This Page Contains Both Secure and NonSecure Items" Warning Message

How to Fix Problem with Blank Add/Remove Control Panel

How to Fix Windows Vista Update Error 80244019

Troubleshooting An Error Occurred During Directory Enumeration

How to View and Decipher Minidump files created by Blue Screen error messages

How to Fix BLService Error on HP Computer in Vista

Google Adsense Hijacking - How to Respond

Windows Defrag Does Not Complete

Review of BigString Recallable Email

Fix Incorrect Time Stamp on Hotmail Messages

Deleting or Editing Typed URLs in the Internet Explorer Address Bar

Belarc Advisor - Quick Computer Inventory Software

How to Get Out of Full Screen Mode in Internet Explorer

How to Correct Missing "Copy to CD" option in My Pictures Tasks

How to Fix Code 39 error with CD or DVD Drive

How to Fix Problems When Windows Installer Popups Error With Missing .MSI Files

How to Fix Problems When Network Setup Wizard and Network Connections Won't Open

How to Fix Problems with Windows Help Errors

How to Delete Individual Entries from Run Command History

Foxit - Adobe Reader Alternative

How to Fix Autochk Program Not Found error

Difference between Master/Slave and Cable Select on a Hard Drive

How to Use Microsoft SyncToy to backup your important files

How to Delete Temporary Internet Files, Cookies, and History files

Review of PCDecrapifer Software Removal Tool

How to Fix Security Flaw in Adobe Reader

Computer Speakers Sound like Chipmunks

How to SVCHOST.EXE Application Error 0x745f2780

Troubleshooting the Unmountable Boot Volume Error in Windows XP

How to Disable, Uninstall, and Remove Windows Messenger instant messaging from Windows XP

How to Remove Windows Messenger in Windows XP

Free DVD Decoder Software and Help

Free CD Burning Software and Help

How to Use Remote Desktop to Access Multiple Computer on Your LAN

HijackThis Tutorial for removing Spyware

Review of Adsense Detective, Getting Stats and Results from Adsense

How to Disable System Restore in Windows ME or Windows XP

How to Uninstall Internet Explorer 7

How to Install NetBEUI in Windows XP

What is the KB891711.exe file in Windows 98 or Windows ME?

How to Troubleshoot and Solve USB Device Error Code 10

Spooler Subsystem App has encountered a problem and needs to close Error and How to Fix it

How to Fix Problem opening Microsoft Outlook

How to Disable News Headlines in Netscape

How to Bring Back Missing Folders in Netscape Communicator

How to Fix Access Denied Error when Using MSCONFIG

How to Fix HPQKBFiltr.Sys Keylogger Error in Kaspersky Antivirus

How to Backup and Restore Outlook Express Mail, Address Book, Blocked Senders List and other Settings

How to Fix Error 501 Permission Denied when changing fonts in Outlook Express

What is the Tilde (~) File on my Desktop?

What is the thumbs.db file and can I remove it

Password is Not Saved in Outlook Express or Outlook in Windows XP

Allow Viewing of Attachments in Outlook Express 6

How to Fix Problem of No Spell Check in Outlook Express

How to Fix Problems Viewing or Accessing Secure Web Sites

How to Start or Boot Windows into Safe Mode

What is the Winmail.dat file attached to emails?

How to Correct Unreadable Fonts in Norton Antivirus or Norton Systemworks

How to correct issue with No Visible Menu Bar or Tabs in Windows XP Task Manager

How Disable/Enable the Windows XP Welcome Screen

How to Fix RTLGINA2.DLL error with Windows XP Welcome Screen and Netgear WG111

How to Fix Windows Update Error 0x80070420

PopUp Ad Removal Software and Help

Review of ErrorNuker program to identify and fix problems with the Windows Registry

Spyware and Adware Removal Help

Review of Netflix Online DVD Rental

Recommended Software for PC Hell Visitors