Hi, here's the log file produced by the latest FRST run. I checked the LocalLow directory after the run and it looks like the Temp subdirectory did not get cleaned out.
Fix result of Farbar Recovery Scan Tool (x64) Version:28-06-2015 01
Ran by The Green Dream at 2015-07-07 08:54:20 Run:2
Running from C:\Users\The Green Dream\Desktop
Loaded Profiles: The Green Dream & (Available Profiles: The Green Dream)
Boot Mode: Normal
==============================================
fixlist content:
*****************
Start
CreateRestorePoint:
CloseProcesses:
C:\Users\The Green Dream\AppData\LocalLow\EmieBrowserModeList
C:\Users\The Green Dream\AppData\LocalLow\EmieUserList
C:\Users\The Green Dream\AppData\LocalLow\EmieSiteList
CMD: ipconfig /flushdns
CMD: netsh advfirewall reset
CMD: netsh advfirewall set allprofiles state on
Reg: reg delete HKLM\SOFTWARE\Policies\Microsoft\Windows\IPSec\Policy\Local /f
Reg: reg add HKLM\SOFTWARE\Policies\Microsoft\Windows\IPSec\Policy\Local /f
CMD: bitsadmin /reset /allusers
CMD: DEL %TEMP%\*.* /F /S /Q
CMD: RD /S /Q %TEMP%
RemoveProxy:
Reboot:
end
*****************
Restore point was successfully created.
Processes closed successfully.
C:\Users\The Green Dream\AppData\LocalLow\EmieBrowserModeList => moved successfully.
C:\Users\The Green Dream\AppData\LocalLow\EmieUserList => moved successfully.
C:\Users\The Green Dream\AppData\LocalLow\EmieSiteList => moved successfully.
========= ipconfig /flushdns =========
Windows IP Configuration
Successfully flushed the DNS Resolver Cache.
========= End of CMD: =========
========= netsh advfirewall reset =========
Ok.
========= End of CMD: =========
========= netsh advfirewall set allprofiles state on =========
Ok.
========= End of CMD: =========
========= reg delete HKLM\SOFTWARE\Policies\Microsoft\Windows\IPSec\Policy\Local /f =========
The operation completed successfully.
========= End of Reg: =========
========= reg add HKLM\SOFTWARE\Policies\Microsoft\Windows\IPSec\Policy\Local /f =========
The operation completed successfully.
========= End of Reg: =========
========= bitsadmin /reset /allusers =========
BITSADMIN version 3.0 [ 7.5.7601 ]
BITS administration utility.
© Copyright 2000-2006 Microsoft Corp.
BITSAdmin is deprecated and is not guaranteed to be available in future versions of Windows.
Administrative tools for the BITS service are now provided by BITS PowerShell cmdlets.
{8E868DBD-F1C3-4CAF-A347-0802D5D3032C} canceled.
1 out of 1 jobs canceled.
========= End of CMD: =========
========= DEL %TEMP%\*.* /F /S /Q =========
Deleted file - C:\Users\THEGRE~1\AppData\Local\Temp\CVHLauncher(201507062144281900).log
C:\Users\THEGRE~1\AppData\Local\Temp\FXSAPIDebugLogFile.txt
The process cannot access the file because it is being used by another process.
Deleted file - C:\Users\THEGRE~1\AppData\Local\Temp\msohtmlclip1\01\clip_colorschememapping.xml
Deleted file - C:\Users\THEGRE~1\AppData\Local\Temp\msohtmlclip1\01\clip_themedata.thmx
========= End of CMD: =========
========= RD /S /Q %TEMP% =========
C:\Users\THEGRE~1\AppData\Local\Temp\FXSAPIDebugLogFile.txt - The process cannot access the file because it is being used by another process.
========= End of CMD: =========
========= RemoveProxy: =========
HKU\.DEFAULT\SOFTWARE\Microsoft\Windows\CurrentVersion\Internet Settings\Connections\\DefaultConnectionSettings => value removed successfully
HKU\.DEFAULT\SOFTWARE\Microsoft\Windows\CurrentVersion\Internet Settings\Connections\\SavedLegacySettings => value removed successfully
HKU\S-1-5-21-1737765885-1117587993-3094924587-1000\SOFTWARE\Microsoft\Windows\CurrentVersion\Internet Settings\Connections\\DefaultConnectionSettings => value removed successfully
HKU\S-1-5-21-1737765885-1117587993-3094924587-1000\SOFTWARE\Microsoft\Windows\CurrentVersion\Internet Settings\Connections\\SavedLegacySettings => value removed successfully
HKU\S-1-5-21-1737765885-1117587993-3094924587-1000-{ED1FC765-E35E-4C3D-BF15-2C2B11260CE4}-0\SOFTWARE\Microsoft\Windows\CurrentVersion\Internet Settings\Connections\\DefaultConnectionSettings => value removed successfully
HKU\S-1-5-21-1737765885-1117587993-3094924587-1000-{ED1FC765-E35E-4C3D-BF15-2C2B11260CE4}-0\SOFTWARE\Microsoft\Windows\CurrentVersion\Internet Settings\Connections\\SavedLegacySettings => value removed successfully
========= End of RemoveProxy: =========
The system needed a reboot..
==== End of Fixlog 08:55:50 ====