Jump to content


Register a free account to unlock additional features at BleepingComputer.com
Welcome to BleepingComputer, a free community where people like yourself come together to discuss and learn how to use their computers. Using the site is easy and fun. As a guest, you can browse and view the various discussions in the forums, but can not create a new topic or reply to an existing one unless you are logged in. Other benefits of registering an account are subscribing to topics and forums, creating a blog, and having no ads shown anywhere on the site.

Click here to Register a free account now! or read our Welcome Guide to learn how to use this site.


Lost access to internet due to a virus

  • Please log in to reply
1 reply to this topic

#1 vrojack


  • Members
  • 2 posts
  • Local time:02:07 PM

Posted 22 February 2009 - 04:18 PM

I got a virus on my computer that disabled my ability to surf the internet thru firefox and IE. AVG reported problems with the following files
aec.yss, atmarpc.sys and nfr.dll

I searched internet I found the following info which looks like what I got


AVG quarantined the files above and I was able to access the internet but I still have a NFRagent service on my computer.
I've tried all of the following application but none have removed it.

SUPERAntiSpyware Free Edition
Spybot - Search & Destroy
Malwarebytes' Anti-Malware

My computer still looses connection to the internet once in a while and I am afraid the virus may not be fully removed.
Is there anything else I can do to fully remove the virus.

Thanks - vrojack

BC AdBot (Login to Remove)


#2 vrojack

  • Topic Starter

  • Members
  • 2 posts
  • Local time:02:07 PM

Posted 22 February 2009 - 04:36 PM

Sorry I forgot to mention after AVG quarantined the files and I rebooted and logged in I did not see my desktop. Basically I could not run explorer and the only way I was able to get the desktop to show was to undo the registry modification listed on the website in the URL above.

I think the specific one that helped was the removal of the following key:

# [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\explorer.exe]
* Debugger = "%ProgramFiles%\Microsoft Common\svchost.exe"

0 user(s) are reading this topic

0 members, 0 guests, 0 anonymous users