Your PC performance suffers more than you, if you have got Windows Diagnostic (WindowsDiagnostic) issue.  That may seem strange since the issue is related to fake antispyware which is rather known as infection of advertising kind, meaning that it should  rather  be a boring and noisy stuff addressing users directly. However, instead of that, the infection rather  wants users to hear its message through annoyance of another kind. Namely, the software tends to arrange frequent system freezes and denial of services of most frequently used applications  and make software operating with currently entered data shut down without saving data precious for users. The adware also attempts to disable Autosave option in MS Office  text , tables and graphics editors.
In the meantime, the adware certainly shows loads of tricky popups, just like any fake security tool.
  • Full name: Windows Diagnostic, WindowsDiagnostic, Windows-Diagnostic
  • Version: 2011
  • Type: Rogue anti-spyware
  • Origin: Russian federation

Installation of the program results from several schemes, some of which are interrelated and depends on peculiarities of user’s behavior and its computer arrangements. In particular, there is a trojan installation  in which trojan acts either as a backdoor dropper or a hijacker subject to system settings and browser vulnerabilities. In any case, the trojan first examines web-settings to clarify if redirecting to given website is possible without user’s participation. Then it tries to collect data on user’s habits and behaviors in order to predict its response on web-ads or uninvited software installation. Subject to examination and observation the trojan either starts a luring campaign on the web basis or automatically drops the content. Consequentially, the trojan may be well-detectable by repeated online ads suggesting Windows Diagnostic. In the meantime, the appearance of the same pages may be caused by ad links posted on rather dubious or unfair websites.
Once installation of the program is done, it is immediately ready to present its graphics faking antivirus stool. There are plenty of signs available for user’s comprehension and clearly identifying the scamware.
Components of rogue programs are often named in a way similar to legit files of common knowledge and copied into the location of restricted by default access, such as system folders. This is to emphasize the importance of precise following the steps below. It is also preferable that you make a Safe Mode reboot to get your system into Safe Mode while removing Windows Diagnostic manually.

%UserProfile%\Desktop\Windows Diagnostic.lnk
%UserProfile%\Start Menu\Programs\Windows Diagnostic\
%UserProfile%\Start Menu\Programs\Windows Diagnostic\Uninstall Windows Diagnostic.lnk
%UserProfile%\Start Menu\Programs\Windows Diagnostic\Windows Diagnostic.lnk

HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Run “<random>.exe”
HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Run “<random>”
HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Internet Settings “CertificateRevocation” = ‘0′
HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Internet Settings “WarnonBadCertRecving” = ‘0′
HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Policies\ActiveDesktop “NoChangingWallPaper” = ‘1′
HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Policies\Associations “LowRiskFileTypes” = ‘/{hq:/s`s:/ogn:/uyu:/dyd:/c`u:/bnl:/ble:/sdf:/lrh:/iul:/iulm:/fhg:/clq:/kqf:/`wh:/lqf:/lqdf:/lnw:/lq2:/l2t:/v`w:/rbs:’
HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Policies\Attachments “SaveZoneInformation” = ‘1′
HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Policies\System “DisableTaskMgr” = ‘1′
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\system “DisableTaskMgr” = ‘1′
HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\Download “CheckExeSignatures” = ‘no’
HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\Main “Use FormSuggest” = ‘yes’
HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Explorer\Advanced “Hidden” = ‘0′
HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Explorer\Advanced “ShowSuperHidden” = 0′

