I posted this before but I went on holiday before it was resolved and my post got closed due to inactivity.

My laptop has somehow got infected by the delta toolbar virus and I am having trouble removing it. I would prefer to remove it without having to format my computer so was hoping someone might have some suggestions.

Basically I have run various spyware/malware tools (spybot, mcafee, ad-aware, malwarebytes) in both normal mode and safemode but they either find problems and remove them but they return immediately (I run the tool twice to check), or they can't remove the delta-related ones at all. I have also tried going into the registry and searching for the keys that various web pages suggest removing but none of them are there! (And obviously I have removed it all (exensions/homepage etc) from Chrome.

My computer is a Dell Inspiron ultrabook with Windows 8. The registry key that spybot keeps finding but not being able to remove is HKLM/SOFTWARE/Datamngr.

I have backed up my registry using ERDNT. DDS won't run for some reason it just keeps coming up with the error message "DDS will not run in 'compatibility mode'".

This is my aswMBR log:

aswMBR version Copyright(c) 2011 AVAST Software
Run date: 2014-01-29 21:54:17
21:54:17.196 OS Version: Windows x64 6.2.9200
21:54:17.197 Number of processors: 4 586 0x3A09
21:54:17.199 ComputerName: JANE UserName:
21:54:17.599 Initialze error 1
21:57:14.014 AVAST engine defs: 14012901
21:58:09.727 Disk 0 (boot) \Device\Harddisk0\DR0 -> \Device\0000002f
21:58:09.731 Disk 0 Vendor: A110 Size: 476937MB BusType: 8
21:58:09.736 Disk 1 \Device\Harddisk1\DR1 -> \Device\00000030
21:58:09.740 Disk 1 Vendor: WLAD Size: 8192MB BusType: 8
21:58:09.746 Disk 0 MBR read successfully
21:58:09.751 Disk 0 MBR scan
21:58:09.825 Disk 0 unknown MBR code
21:58:09.830 Disk 0 Partition 1 00 EE GPT 2097151 MB offset 1
21:58:09.873 Disk 0 scanning C:\WINDOWS\system32\drivers
21:58:09.878 Service scanning
21:58:10.746 Modules scanning
21:58:10.752 Disk 0 trace - called modules:
21:58:10.761 ntoskrnl.exe CLASSPNP.SYS disk.sys storport.sys hal.dll iaStorAV.sys
21:58:10.771 1 nt!IofCallDriver -> \Device\Harddisk0\DR0[0xffffe000021c3060]
21:58:10.778 3 CLASSPNP.SYS[fffff80000601abb] -> nt!IofCallDriver -> \Device\0000002f[0xffffe00000fe9060]
21:58:10.787 AVAST engine scan C:\WINDOWS
21:58:10.796 AVAST engine scan C:\WINDOWS\system32
21:58:10.804 AVAST engine scan C:\WINDOWS\system32\drivers
21:58:10.813 AVAST engine scan C:\Users\YouTarzan
21:58:10.821 AVAST engine scan C:\ProgramData
21:58:10.830 Scan finished successfully
21:58:22.325 Disk 0 MBR has been saved successfully to "C:\Users\YouTarzan\Desktop\MBR.dat"
21:58:22.347 The log file has been saved successfully to "C:\Users\YouTarzan\Desktop\aswMBR.txt"

And this is the spybot log:

26/01/2014 12:18:48
Scan took 00:30:04.
6 items found.

Delta.Toolbar: [SBI $15E43F9C] Settings (Registry Key, nothing done)

MS DirectInput: [SBI $9A063C91] Most recent application (Registry Change, nothing done)

MS DirectInput: [SBI $7B184199] Most recent application ID (Registry Change, nothing done)

MS Regedit: [SBI $C3B62FC1] Recent open key (Registry Change, nothing done)

Windows Explorer: [SBI $D20DA0AD] Recent file global history (Registry Key, nothing done)

History: [SBI $49804B54] Browser: History (1) (Browser: History, nothing done)

The Delta.toolbar one in bold above is the one that spybot can't seem to remove. There have also been a number of weird things going on with my computer recently which I don't know if they are anything to do with this/a virus so I'll mention them just in case. - 1. my microsoft password mysteriously changed to a different one of my passwords so I changed my microsoft password properly on the website in case it had been hacked. 2, now that i have changed my password my computer now recognises that the old one is wrong so tells me this everytime i turn my computer on and doesnt seem to want to 'remember' the new one!

I have also just run adwCleaner on the advice from Ken545 during my previous post:

# AdwCleaner v3.018 - Report created 08/02/2014 at 13:41:17
# Updated 28/01/2014 by Xplode
# Operating System : Windows 8.1 (64 bits)
# Username : YouTarzan - JANE
# Running from : C:\Users\YouTarzan\Desktop\AdwCleaner.exe
# Option : Scan

***** [ Services ] *****

***** [ Files / Folders ] *****

File Found : C:\WINDOWS\System32\Tasks\BitGuard
File Found : C:\WINDOWS\System32\Tasks\DSite
File Found : C:\WINDOWS\Tasks\DSite.job
Folder Found C:\Program Files (x86)\Toolbar Cleaner
Folder Found C:\ProgramData\blekko toolbars
Folder Found C:\ProgramData\DSearchLink
Folder Found C:\ProgramData\Search Protection
Folder Found C:\Users\YouTarzan\AppData\LocalLow\adawaretb
Folder Found C:\Users\YouTarzan\AppData\Roaming\DSite
Folder Found C:\Users\YouTarzan\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\BitGuard

***** [ Shortcuts ] *****

***** [ Registry ] *****

Data Found : [x64] HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Windows [AppInit_DLLs] - c:\progra~3\bitguard\271769~1.27\{c16c1~1\loader.dll
Data Found : [x64] HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Windows [AppInit_DLLs] - c:\progra~3\bitguard\271832~1.68\{c16c1~1\loader.dll
Key Found : HKCU\Software\5853d9dfe16ee410
Key Found : HKCU\Software\dsiteproducts
Key Found : HKCU\Software\Microsoft\Internet Explorer\SearchScopes\{3BD44F0E-0596-4008-AEE0-45D47E3A8F0E}
Key Found : HKCU\Software\Microsoft\Windows\CurrentVersion\Ext\Settings\{6C97A91E-4524-4019-86AF-2AA2D567BF5C}
Key Found : HKCU\Software\Microsoft\Windows\CurrentVersion\Ext\Stats\{6C97A91E-4524-4019-86AF-2AA2D567BF5C}
Key Found : [x64] HKCU\Software\dsiteproducts
Key Found : [x64] HKCU\Software\Microsoft\Internet Explorer\SearchScopes\{3BD44F0E-0596-4008-AEE0-45D47E3A8F0E}
Key Found : HKLM\SOFTWARE\5853d9dfe16ee410
Key Found : HKLM\Software\adawaretb
Key Found : HKLM\SOFTWARE\Classes\CLSID\{6C97A91E-4524-4019-86AF-2AA2D567BF5C}
Key Found : HKLM\SOFTWARE\Classes\Prod.cap
Key Found : HKLM\Software\DataMngr
Key Found : HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{6C97A91E-4524-4019-86AF-2AA2D567BF5C}
Key Found : HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\adawaretb
Key Found : HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\Toolbar Cleaner
Key Found : HKLM\Software\Toolbar Cleaner
Key Found : [x64] HKLM\SOFTWARE\Classes\Interface\{79FB5FC8-44B9-4AF5-BADD-CCE547F953E5}
Value Found : HKLM\SOFTWARE\Microsoft\Internet Explorer\Toolbar [{6C97A91E-4524-4019-86AF-2AA2D567BF5C}]

***** [ Browsers ] *****

-\\ Internet Explorer v11.0.9600.16384

-\\ Google Chrome v32.0.1700.76

[ File : C:\Users\YouTarzan\AppData\Local\Google\Chrome\User Data\Default\preferences ]


AdwCleaner[R0].txt - [2764 octets] - [08/02/2014 13:41:17]

########## EOF - C:\AdwCleaner\AdwCleaner[R0].txt - [2824 octets] ##########

Thanks in advance for your help!

2014-02-09, 14:14

Welcome back, sorry about closing your thread but we cant keep them open that long.

Double click on AdwCleaner.exe to run the tool again.

Click on the Scan button.
AdwCleaner will begin to scan your computer like it did before.
After the scan has finished...
This time, click on the Clean button.
Press OK when asked to close all programs and follow the onscreen prompts.
Press OK again to allow AdwCleaner to restart the computer and complete the removal process.
After rebooting, a logfile report (AdwCleaner[S0].txt) will open automatically.
Copy and paste the contents of that logfile in your next reply.
A copy of that logfile will also be saved in the C:\AdwCleaner folder.

http://imageshack.us/a/img841/7292/thisisujrt.gif Please download Junkware Removal Tool (http://thisisudax.org/downloads/JRT.exe) to your desktop.

Shut down your protection software now to avoid potential conflicts.
Run the tool by double-clicking it. If you are using Windows Vista, 7, or 8; instead of double-clicking, right-mouse click JRT.exe and select "Run as Administrator".
The tool will open and start scanning your system.
Please be patient as this can take a while to complete depending on your system's specifications.
On completion, a log (JRT.txt) is saved to your desktop and will automatically open.
Post the contents of JRT.txt into your next message.

2014-02-09, 15:56
Thanks. i actually accidentally did the 'clean' immediately after yesterdays scan so this is the log from that (todays was blank).

# AdwCleaner v3.018 - Report created 08/02/2014 at 13:51:20
# Updated 28/01/2014 by Xplode
# Operating System : Windows 8.1 (64 bits)
# Username : YouTarzan - JANE
# Running from : C:\Users\YouTarzan\Desktop\AdwCleaner.exe
# Option : Clean

***** [ Services ] *****

***** [ Files / Folders ] *****

Folder Deleted : C:\ProgramData\blekko toolbars
Folder Deleted : C:\ProgramData\DSearchLink
Folder Deleted : C:\ProgramData\Search Protection
Folder Deleted : C:\Program Files (x86)\Toolbar Cleaner
Folder Deleted : C:\Users\YouTarzan\AppData\LocalLow\adawaretb
Folder Deleted : C:\Users\YouTarzan\AppData\Roaming\DSite
Folder Deleted : C:\Users\YouTarzan\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\BitGuard
File Deleted : C:\WINDOWS\System32\Tasks\BitGuard
File Deleted : C:\WINDOWS\Tasks\DSite.job
File Deleted : C:\WINDOWS\System32\Tasks\DSite

***** [ Shortcuts ] *****

***** [ Registry ] *****

Key Deleted : HKLM\SOFTWARE\Classes\Prod.cap
Key Deleted : HKCU\Software\5853d9dfe16ee410
Key Deleted : HKLM\SOFTWARE\5853d9dfe16ee410
Key Deleted : HKLM\SOFTWARE\Classes\CLSID\{6C97A91E-4524-4019-86AF-2AA2D567BF5C}
Key Deleted : HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{6C97A91E-4524-4019-86AF-2AA2D567BF5C}
Key Deleted : HKCU\Software\Microsoft\Windows\CurrentVersion\Ext\Stats\{6C97A91E-4524-4019-86AF-2AA2D567BF5C}
Key Deleted : HKCU\Software\Microsoft\Windows\CurrentVersion\Ext\Settings\{6C97A91E-4524-4019-86AF-2AA2D567BF5C}
Key Deleted : HKCU\Software\Microsoft\Internet Explorer\SearchScopes\{3BD44F0E-0596-4008-AEE0-45D47E3A8F0E}
Value Deleted : HKLM\SOFTWARE\Microsoft\Internet Explorer\Toolbar [{6C97A91E-4524-4019-86AF-2AA2D567BF5C}]
Key Deleted : [x64] HKLM\SOFTWARE\Classes\Interface\{79FB5FC8-44B9-4AF5-BADD-CCE547F953E5}
Key Deleted : HKCU\Software\dsiteproducts
Key Deleted : HKLM\Software\adawaretb
Key Deleted : HKLM\Software\DataMngr
Key Deleted : HKLM\Software\Toolbar Cleaner
Key Deleted : HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\adawaretb
Key Deleted : HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\Toolbar Cleaner
Data Deleted : [x64] HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Windows [AppInit_DLLs] - c:\progra~3\bitguard\271832~1.68\{c16c1~1\loader.dll
Data Deleted : [x64] HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Windows [AppInit_DLLs] - c:\progra~3\bitguard\271769~1.27\{c16c1~1\loader.dll

***** [ Browsers ] *****

-\\ Internet Explorer v11.0.9600.16384

-\\ Google Chrome v32.0.1700.76

[ File : C:\Users\YouTarzan\AppData\Local\Google\Chrome\User Data\Default\preferences ]


AdwCleaner[R0].txt - [2924 octets] - [08/02/2014 13:41:17]
AdwCleaner[S0].txt - [2743 octets] - [08/02/2014 13:51:20]

########## EOF - C:\AdwCleaner\AdwCleaner[S0].txt - [2803 octets] ##########

And the JRT log:

Junkware Removal Tool (JRT) by Thisisu
Version: 6.1.1 (02.04.2014:1)
OS: Windows 8.1 x64
Ran by YouTarzan on 09/02/2014 at 13:15:42.36

~~~ Services

~~~ Registry Values

Successfully deleted: [Registry Value] HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Run\\search protection

~~~ Registry Keys

Successfully deleted: [Registry Key] HKEY_CURRENT_USER\Software\AppDataLow\software\adawarebp
Successfully deleted: [Registry Key] HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\InternetRegistry\REGISTRY\USER\S-1-5-21-880496913-865728010-2256035260-1001\Software\sweetim

~~~ Files

~~~ Folders

Successfully deleted: [Folder] "C:\Users\YouTarzan\appdata\local\adawarebp"

~~~ Event Viewer Logs were cleared

Scan was completed on 09/02/2014 at 13:43:20.38
End of JRT log

2014-02-09, 16:11
Thats fine.

Please download Malwarebytes from Here (http://www.malwarebytes.org/mbam-download.php) or Here (http://www.majorgeeks.com/Malwarebytes_Anti-Malware_d5756.html)

Double-click mbam-setup.exe and follow the prompts to install the program.
At the end, be sure a checkmark is placed next to Update Malwarebytes' Anti-Malware and Launch Malwarebytes' Anti-Malware, then click Finish.
If an update is found, it will download and install the latest version.
Once the program has loaded, select Perform quick scan, then click Scan.
When the scan is complete, click OK, then Show Results to view the results.
Be sure that everything is checked, and click Remove Selected .
When completed, a log will open in Notepad. Please save it to a convenient location and post the results.
Note: If you receive a notice that some of the items couldn't be removed, that they have been added to the delete on reboot list, please reboot.
Post the report please

Then open Malwarebytes and check for updates then run the Quick scan, if it finds anything than post the log if not then let me know it found nothing, I posted the instructions for Malwarebytes in case you need to redownload and install it

Then run this scanner and lets see what else needs to be removed

OTL by OldTimer

Download OTL (http://oldtimer.geekstogo.com/OTL.exe) to your desktop.
Double click on the icon to run it. Make sure all other windows are closed and to let it run uninterrupted.
When the window appears, underneath Output at the top change it to Minimal Output.
Click the "Scan All Users" checkbox.
Check the boxes beside LOP Check and Purity Check.
Click the Run Scan button. Do not change any settings unless otherwise told to do so. The scan wont take long.

When the scan completes, it will open two notepad windows. OTL.Txt and Extras.Txt.
Note:These logs can be located in the OTL. folder on you C:\ drive if they fail to open automatically.
Please copy (Edit->Select All, Edit->Copy) the contents of these files, one at a time, and post it with your next reply. You may need two posts to fit them both in.

2014-02-09, 21:56

MalwareBytes log:

Malwarebytes Anti-Malware (Trial)

Database version: v2014.02.09.05

Windows 8 x64 NTFS
Internet Explorer 11.0.9600.16476
YouTarzan :: JANE [administrator]

Protection: Enabled

09/02/2014 18:46:18
mbam-log-2014-02-09 (18-46-18).txt

Scan type: Quick scan
Scan options enabled: Memory | Startup | Registry | File System | Heuristics/Extra | Heuristics/Shuriken | PUP | PUM
Scan options disabled: P2P
Objects scanned: 215106
Time elapsed: 14 minute(s), 48 second(s)

Memory Processes Detected: 0
(No malicious items detected)

Memory Modules Detected: 0
(No malicious items detected)

Registry Keys Detected: 0
(No malicious items detected)

Registry Values Detected: 0
(No malicious items detected)

Registry Data Items Detected: 0
(No malicious items detected)

Folders Detected: 0
(No malicious items detected)

Files Detected: 2
C:\Users\YouTarzan\Downloads\daemon410-x86.exe (Adware.Vomba) -> Quarantined and deleted successfully.
C:\Users\YouTarzan\Downloads\DAEMONToolsPro530-0359.exe (PUP.Optional.OpenCandy) -> Quarantined and deleted successfully.


Second run was clear.

OTL log:

2014-02-09, 21:57
OTL Extras log:

2014-02-09, 22:24

nurago web meter <-- Did you download and install this, its getting iffy ratings , tracks all your browsing , not nice

The two files that Malwarebytes found where downloaded via the torrents or 2Share, I cant stress enough how dangerous it is to download anything from any P2P ( File Sharing Sites ) not all but the greater percentage of those downloads are infected, its like playing russian roulette malwarewise. I would never allow any P2P programs on any of my systems

Download CKScanner by askey127 from Here (http://downloads.malwareremoval.com/CKScanner.exe) & save it to your Desktop.
Doubleclick CKScanner.exe then click Search For Files
When the cursor hourglass disappears, click Save List To File
A message box will verify the file saved
Please Run this program only once
Double-click the CKFiles.txt icon on your desktop then copy/paste the contents in your next reply

2014-02-09, 23:04
I did install nurago myself however I have now removed it incase it is causing problems.

CKScanner log:

CKScanner 2.4 - Additional Security Risks - These are not necessarily bad
c:\users\youtarzan\downloads\corel draw x5 ++keygen++\coreldrawgraphicssuitex5installer_en.exe
c:\users\youtarzan\downloads\corel draw x5 ++keygen++\read me.txt
c:\users\youtarzan\downloads\corel graphics suite x3 with (keygen and activation)\coreldrawgraphicssuitex3.exe
c:\users\youtarzan\downloads\corel graphics suite x3 with (keygen and activation)\instructions.txt
c:\users\youtarzan\downloads\macromedia studio 8 full edition\macromedia studio 8 full edition\keygen\studio 8 serial.txt
c:\users\youtarzan\downloads\macromedia studio 8 full edition\macromedia studio 8 full edition\keygen\thumbs.db
c:\users\youtarzan\downloads\nero ultra edition + keygen [h33t] [cazor]\nero-
scanner sequence 3.CE.11.JONAUZ
----- EOF -----

2014-02-09, 23:28
Was just a bit concerned about nurago, but really concerned about what CKScanner found. It looks like none of those programs have been installed, there all cracked or keygen programs that you downloaded illegally. Cracked / Keygen software besides being illegal is guaranteed to be 100% infected. Our service like other malware removal forums, besides cleaning you up is to help guide you with tips and tools to help keep you clean in the future, if after your clean and you keep downloading this garbage your basically wasting my time because you will just wind up infecting your self again. The reason your infections are really not to serious right now is because it looks like you have not installed them yet, the only way we can continue with the cleaning is if you delete those files from the downloads folder, if you do not agree than this thread will be closed and no more help will be offered. Let me know what you decide

2014-02-09, 23:53
All deleted.

CKScanner 2.4 - Additional Security Risks - These are not necessarily bad
scanner sequence 3.MN.11.BOLBA0
----- EOF -----

2014-02-10, 00:22

Thanks for understanding. Remember what I said, this is your computer, I can only advise and guide you, the final decisions are yours. Downloading Cracks/KeyGens from the torrents is like playing with dynamite. If you where sitting in my chair and saw all the things that malware can do, things like stealing money from your bank account, making charges on your credit card, infecting your system so it wont go past the start screen unless you pay a ransom and the list goes on, there are some infections going around that can't be cleaned, a format of the hard drive and a clean install of windows is the only option.

Anyway, I am off my soapbox

Go ahead and run a new scan with OTL and post the new log, there wont be any extra log this time so dont go crazy looking for it

2014-02-11, 20:13
Still with me ??????

2014-02-11, 23:36
Sorry. New OTL log:

OTL logfile created on: 11/02/2014 21:16:52 - Run 2
OTL by OldTimer - Version Folder = C:\Users\YouTarzan\Desktop
64bit- An unknown product (Version = 6.2.9200) - Type = NTWorkstation
Internet Explorer (Version = 9.11.9600.16476)
Locale: 00000809 | Country: United Kingdom | Language: ENG | Date Format: dd/MM/yyyy

3.87 Gb Total Physical Memory | 1.88 Gb Available Physical Memory | 48.61% Memory free
5.62 Gb Paging File | 3.28 Gb Available in Paging File | 58.31% Paging File free
Paging file location(s): ?:\pagefile.sys

2014-02-12, 00:25

Nothing really bad, just some leftovers but before we remove them I am seeing Ad-Aware Antivirus and mcAfee running as a service, do you use McAfee or do you want to remove it, it may be still running from an online scan ?

2014-02-14, 15:36
I do use them both but McAfee has been behaving weirdly recently and constantly says there's an update but then says it's up to date when I try to update it so I'm wondering if that was affected so maybe it's best to remove it?

2014-02-14, 15:55

With Antivirus software more is not better, they will fight with each other and hamper system performance, Microsoft recommends just having one, keep it updated and run regular scans

You can use this app to do a clean uninstall of McAfee

Run AppRemover

Vista , Win 7 users, right click on the icon and select "run as administrator"

Please download AppRemover (http://www.appremover.com/) and save it to your desktop.
Double click on AppRemover.exe to run it.
Uncheck "Enable anonymous usage statistics. No personal data will be recorded."
Click on the Next button.
Click on "Remove Security Application" or "Clean Up a Failed Uninstall" depending on what you want to do.
Click on the Next button.
A scan begins, please wait. Once done, click on the Next button.
Now you should have a list of your installed security programs, choose the one you want to uninstall and click on the Next button.
Follow the last step and reboot if asked to do so.

Then run a new scan with OTL and post the log

2014-02-16, 22:02
McAfee uninstalled with AppRemover. OTL log:

2014-02-16, 23:22

Nothing bad just McAfee entries that where not removed when you uninstalled it. What I would like you to do is create a System Restore Point and name it OTL FIX and in case removing any of these entries causes problems you can restore your computer back prior to the fix


Open OTL.exe

Copy/paste the following text written inside of the code box into the Custom Scans/Fixes box located at the bottom of OTL

DRV:64bit: - (cfwids) -- C:\Windows\SysNative\drivers\cfwids.sys (McAfee, Inc.)
DRV:64bit: - (mfewfpk) -- C:\Windows\SysNative\drivers\mfewfpk.sys (McAfee, Inc.)
DRV:64bit: - (mfehidk) -- C:\Windows\SysNative\drivers\mfehidk.sys (McAfee, Inc.)
DRV:64bit: - (mfefirek) -- C:\Windows\SysNative\drivers\mfefirek.sys (McAfee, Inc.)
DRV:64bit: - (mfeavfk) -- C:\Windows\SysNative\drivers\mfeavfk.sys (McAfee, Inc.)
DRV:64bit: - (mfeapfk) -- C:\Windows\SysNative\drivers\mfeapfk.sys (McAfee, Inc.)
DRV:64bit: - (mfeelamk) -- C:\Windows\SysNative\drivers\mfeelamk.sys (McAfee, Inc.)
DRV:64bit: - (mfencrk) -- C:\Windows\SysNative\drivers\mfencrk.sys (McAfee, Inc.)
DRV:64bit: - (mfencbdc) -- C:\Windows\SysNative\drivers\mfencbdc.sys (McAfee, Inc.)
FF:64bit: - HKLM\Software\MozillaPlugins\@mcafee.com/MSC,version=10: c:\PROGRA~1\mcafee\msc\NPMCSN~1.DLL ()
FF - HKLM\Software\MozillaPlugins\@mcafee.com/MSC,version=10: c:\PROGRA~2\mcafee\msc\NPMCSN~1.DLL ()
FF - HKEY_LOCAL_MACHINE\software\mozilla\Thunderbird\Extensions\\msktbird@mcafee.com: C:\Program Files\McAfee\MSK [2013/10/06 09:55:37 | 000,000,000 | ---D | M]
O4 - HKLM..\Run: [mcpltui_exe] C:\Program Files\McAfee.com\Agent\mcagent.exe (McAfee, Inc.)
O4 - HKLM..\Run: [mcui_exe] C:\Program Files\McAfee.com\Agent\mcagent.exe (McAfee, Inc.)
[2014/02/16 19:43:46 | 000,000,000 | ---D | C] -- C:\ProgramData\Microsoft\Windows\Start Menu\Programs\McAfee



ipconfig /flushdns /c

[start explorer]

Then click the Run Fix button at the top. <--Not run Scan
Let the program run unhindered, reboot when it is done
Then post the results of the log it produces

After the fix let me know how your system is behaving and if all is well we will be done here

2014-02-17, 18:23
Computer seems to be behaving ok. OTL log:

2014-02-17, 21:43
Go ahead and run a new scan with OTL and post the log and lets see if those entries are gone