Location is greyed out, i cannot remove internet explorer 11 addon after virus removal

Anonymous
2015-09-22T16:27:00+00:00

I am running Windows 10 64 bit

After removing a virus using windows defender and malwarebytes, I could no longer...

A. remove these internet explorer add ons, to wit:

  1. Ó¦Óñ¦Ò»¼ü°²×°²å¼þ npQQPhoneManagerExt.dll
  2. 电脑管家网页防火墙 TSWebMon64.dat

B. activate Location in Notification since it is always greyed out now

Windows for home | Windows 10 | Security and privacy

Locked Question. This question was migrated from the Microsoft Support Community. You can vote on whether it's helpful, but you can't add comments or replies or follow the question.

0 comments No comments

157 answers

Sort by: Most helpful
  1. Anonymous
    2015-10-05T16:28:06+00:00

    What is the {BFA794E4-F964-4FDB-90F6-51056BFE4B44}? Bad BHO also?

    The search gave me 36 results... quite a lot also.

    Was this answer helpful?

    0 comments No comments
  2. Anonymous
    2015-10-05T15:04:26+00:00

    Defender alerted me it was finding the viruses during the scan....

    Was this answer helpful?

    0 comments No comments
  3. Anonymous
    2015-10-05T15:02:39+00:00

    What is D-Clk?

    Was this answer helpful?

    0 comments No comments
  4. Anonymous
    2015-10-05T05:58:59+00:00

    Here is how to delete the services. Do this for the two QQ... (Chinese) services & the TAOFrame service. (But let the Geolocation service alone. That is a MS service we will want to enable as part of getting your Location problem solved.)

    (1) R-Clk START, select "Run", type "Services.msc", & hit ENTER.

         Services will open.

    (2) Find a bad guy in the list, R-Clk it, & select "Properties".

         Its properties sheet opens, with the service name in blue.

    (3) R-Clk the service name, & select "Copy".

         The name enters the clipboard, ready to be pasted.

    (4) R-Clk START, select "Run", type "RegEdit", & hit ENTER.

         The registry editor opens. (Remember to be careful in there always.)

    (5) Get to the top:  R-Clk in the left pane & press the Home key on the keyboard.

    (6) Click the "Edit" menu, select "Find", paste the service name into the box, & hit ENTER.

         Should get you to a screen such as for my Adobe Acrobat example.

    (7) Examine the screen carefully to be sure its the virus, then...

         R-Clk the service name in blue in the left pane, & select "delete".

    (8) Use the menu to "Find Next", or use F3 (may need to hold FN as well).

         I think the only other occurrence will be a mirror which is now gone, else delete it.

         If other than a mirror is found - post a picture - do not delete. It may be a record-keeping key.

    (9) Repeat the process for the other two.

    Note:  For extra care, before deleting a key in the registry, you may...

    (1) Click the File menu, & select "Export...".

    (2) Type a name into the box, & hit ENTER.

         A copy of the key you are about to delete appears on the Desktop.

    To put the key back into the registry, you D-Clk that file. Otherwise, delete it someday.

    Was this answer helpful?

    0 comments No comments
  5. Anonymous
    2015-10-05T02:35:33+00:00

    False alarm! That is just a record of what was already removed. You may keep the record or remove it as you wish. OR - WAIT - click for more information first! It might reveal manual steps for you to perform that Defender couldn't do.

    Notice Malwarebytes didn't find them, they're gone. The PUPs Malwarebytes quarantined are not full-fledged viruses. I guess if one is industrious one may investigate each one & choose whether to restore any. But I just clicked "Delete all" & never saw them again. Yours are your choice. It is good of Malwarebytes to give us a choice.

    I've gone to look into the services. Yes, Taoframe & the QQ... duo are bad guys - nicely disabled. But we want to make them disappear. Geolocation Service, OTOH, is a MS service we want to enable. It could be part of the Location problem you are having that it is disabled. I've gone to look.

    EDIT 11:48 PM:  I've just got one pang of doubt considering the date Defender reports for those viruses, which is today's date. Did Defender alert you it was finding the viruses during the scan - or did you just wander into the History Tab? In any event, they are removed. DO click for more information on them to see whether there are bits & pieces for you to manually remove even just for neatness sake.

    Was this answer helpful?

    0 comments No comments