Jqs.exe
Jqs.exe Description
Jqs.exe is a fake security threat appearing on counterfeit warning notifications, all designed and launched by the rogue anti-spyware program known as Windows Security Suite. These Jqs.exe pop-up windows read as follows:
“Windows Security Suite Process Control. An unidentified program is trying to access system process address space. Process name: jqs.exe…”
This Jqs.exe is a fake and should not be taken lightly. Following the prompts will only cause the user to purchase and download the fake spyware remover Windows Security Suite. Instead, remove both the rogue spyware remover and Jqs.exe from the computer as soon as they are detected.
Type: Fake Warning Messages
How Can You Detect Jqs.exe?
Jqs.exe has typically the following processes in memory:
- %UserProfile%\Recent\kernel32.dll
- %UserProfile%\Recent\runddl.dll
- %UserProfile%\Recent\grid.dll
- %UserProfile%\Recent\snl2w.exe
- %UserProfile%\Recent\CLSV.exe
- c:\Documents and Settings\All Users\Application Data\345d567\sqlite3.dll
- %UserProfile%\Recent\energy.dll
- %UserProfile%\Recent\PE.dll
- %UserProfile%\Recent\grid.sys
- c:\Documents and Settings\All Users\Application Data\345d567\WI345d.exe
- c:\Documents and Settings\All Users\Application Data\345d567\mozcrt19.dll
- %UserProfile%\Recent\tempdoc.dll
- %UserProfile%\Recent\SM.dll
- %UserProfile%\Recent\dudl.sys
- %UserProfile%\Recent\std.exe
Jqs.exe creates the following registry entries:
- HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Internet Settings\5.0\User Agent\Post Platform “698909210803″
- HKEY_CLASSES_ROOT\WI345d.DocHostUIHandler
- HKEY_CLASSES_ROOT\CLSID\{3F2BBC05-40DF-11D2-9455-00104BC936FF}
- HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Run “Windows Security Suite”
Important Article Disclaimer

English 
Deutsch
Español
Français
Portuguese
Jqs.exe 











