Jqs.exe

Jqs.exe is a fake security threat appearing on counterfeit warning notifications, all designed and launched by the rogue anti-spyware program known as Windows Security Suite. These Jqs.exe pop-up windows read as follows:

"Windows Security Suite Process Control. An unidentified program is trying to access system process address space. Process name: jqs.exe..."

This Jqs.exe is a fake and should not be taken lightly. Following the prompts will only cause the user to purchase and download the fake spyware remover Windows Security Suite. Instead, remove both the rogue spyware remover and Jqs.exe from the computer as soon as they are detected.

File System Details

Jqs.exe may create the following file(s):
# File Name Detections
1. %UserProfile%\Recent\kernel32.dll
2. %UserProfile%\Recent\runddl.dll
3. %UserProfile%\Recent\grid.dll
4. %UserProfile%\Recent\snl2w.exe
5. %UserProfile%\Recent\CLSV.exe
6. C:\Documents and Settings\\Application Data\345d567\sqlite3.dll
7. %UserProfile%\Recent\energy.dll
8. %UserProfile%\Recent\PE.dll
9. %UserProfile%\Recent\grid.sys
10. C:\Documents and Settings\\Application Data\345d567\WI345d.exe
11. C:\Documents and Settings\\Application Data\345d567\mozcrt19.dll
12. %UserProfile%\Recent\tempdoc.dll
13. %UserProfile%\Recent\SM.dll
14. %UserProfile%\Recent\dudl.sys
15. %UserProfile%\Recent\std.exe
16. C:\Documents and Settings\\Application Data\345d567\WINSSSys
17. C:\Documents and Settings\\Application Data\345d567\WINSSSys\vd952342.bd
18. c:\Program Files\Mozilla Firefox\searchplugins\search.xml
19. %UserProfile%\Recent\ANTIGEN.drv
20. C:\Documents and Settings\\Application Data\345d567\WINSS.ico
21. %UserProfile%\Application Data\Windows Security Suite\cookies.sqlite
22. c:\ADWARE_LOG
23. C:\Documents and Settings\\Application Data\345d567
24. %UserProfile%\Start Menu\Programs\Windows Security Suite.lnk
25. %UserProfile%\Desktop\Windows Security Suite.lnk
26. C:\Documents and Settings\\Application Data\345d567\26.mof
27. %UserProfile%\Application Data\Microsoft\Internet Explorer\Quick Launch\Windows Security Suite.lnk
28. %UserProfile%\Start Menu\Windows Security Suite.lnk
29. %UserProfile%\Application Data\Windows Security Suite
30. C:\Documents and Settings\\Application Data\WINSSSys
31. C:\Documents and Settings\\Application Data\WINSSSys\winss.cfg
32. %UserProfile%\Application Data\Windows Security Suite\Instructions.ini
33. %UserProfile%\Recent\DBOLE.drv
34. C:\Documents and Settings\\Application Data\345d567\working.log
35. %UserProfile%\Recent\PE.tmp

Registry Details

Jqs.exe may create the following registry entry or registry entries:
HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Internet Settings\5.0\User Agent\Post Platform "698909210803"
HKEY_CLASSES_ROOT\WI345d.DocHostUIHandler
HKEY_CLASSES_ROOT\CLSID\{3F2BBC05-40DF-11D2-9455-00104BC936FF}
HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Run "Windows Security Suite"

Trending

Most Viewed

Loading...