Hello,
In a Heise article, a DLL used by a well-known diagnostic software was manipulated in such a way that messages to and from the vehicle could be read or altered.
http://www.heise.de/newsticker/meldung/Audi-TT-Airbag-heimlich-ueber-Diagnose-Software-deaktiviert-2858815.html
Documentary:
http://www.hit.bme.hu/~buttyan/publications/carhacking-Hacktivity-2015.pdf
This made it possible to discreetly disable the airbag of a vehicle during a simulated workshop visit.
In theory, it would also be possible for program code to perform malicious actions based on specific vehicle identification numbers (VINs).
Conclusion: Manufacturers need to better protect their diagnostic software. A signature verification of the involved DLLs is advisable to prevent them from being easily replaced with a malicious variant.
Generally, you should avoid using software from unknown sources, and the diagnostic computer should have up-to-date antivirus protection.
Best regards, Rainer.
PS: KOBD2Check checks its own integrity and uses only operating system components to communicate with the diagnostic hardware.
