well today i formated my PC because of this virus [ jpgutilsy.dll]
my system [ when infected with virus]
windows xp service pack 3
comodo firewall with optimum firewall security
quick heal anti virus [i1 more month
i also downloaded malwarebytes antimalware but it also was useless
symptoms:::
1]my every browser was takking too much time to open .[ firefox and ie8 was seriously damaged ]
2]l3 out of 10 times when i clicked i was redirected to some other websites like snap deals
this was quite noticeable when i used to click any wikipedia link obtained from Google search
3] in comodo defence plus i found that jpgutilsy.dll starts with windows and downloads some invisible data from internet
i blocked it using my firewall : after reading logs about jpgutilsy.dll i made a block-list compatible with peer block
and i was surprised that my pc was connecting to these ips when pc starts, browsers starts , browser is closed and at the shut down time unfortunately peer block was not able to block these ips when shutting down [i dont trust this peer block it sometime fail to block ips ]it was comodo firewall !!!—HOW?? well in comodo acive process list in defense plus that jpgutilsy.dll is subprocess of svcost.exe and it is connecting to internate as jpgutilsy.dll and through svcost also so in firewall i modified svocost.exe firewall seting such that it will not allow anything other than comodo secure dns ips not even windows update!
so then i installed comodo antivirus but my bad it was not able to detect it as virus
and one more thing i forgot to write that since i noticed jpgutilsy.dll was responsible to disturb my system i blocked it in defence plus but no effect it wasnot blocking it i was not able to find the jpgutilsy.dll at it original location [ as shown in defence plus c/windows/system 32/jpgutilsy.dll]
COMODO DFENCE PLUS WAS NOT ABLE TO BLOCK JPGUTILSY.DLL
COMODO WAS NOT ABLE TO SNADBOX JPGUTILSY.DLL
I SEND THIS APPLICATION TO BLOCKED LIST IN DEFENSE EPLUS
I BLOCKED IT VIA FIREWALL
CIS DIDNT DETECT IT
FIREWALL WAS ONLY ABLE TO BLOCK IT FROM CONNECTING TO INTERNET
DEFENSE + WAS NOT ABLE TO BLOCK IT OR SANDBOXED IT
WISH LIST::: COMODO SHOULD HAVE A PLUG IN OR INBUILD SYSTEM SO IT CAN IMPORT IBLOCKLIST LISTS , I KNOW PEER BLOCK DON’T WORK ON WINDOWS 7 AND VISTA MACHINE AND I DONT EVEN TRUST PEER BLOCK
PLEASE NOTE THAT WHEN I CHECKED IT ON CLOUD [ ON LINE LOOK UP ] THE RESULT WAS QUESTION MARK -UNKNOWN RESULT
I DELETED JPGUTILSY.DLL VIA DEFENSE PLUS BUT IT CAME BACK AGAIN