Alright, where to start.
In a nutshell, most of everything went off without a hitch. Here is the rogue killer log.
RogueKiller V12.8.4.0 (x64) [Dec 5 2016] (Free) by Adlice Software
mail :
http://www.adlice.com/contact/
Feedback :
http://forum.adlice.com
Website :
http://www.adlice.com/download/roguekiller/
Blog :
http://www.adlice.com
Operating System : Windows 7 (6.1.7601 Service Pack 1) 64 bits version
Started in : Safe mode with network support
User : OWNER [Administrator]
Started from : C:\Program Files\RogueKiller\RogueKiller64.exe
Mode : Delete -- Date : 12/11/2016 20:12:09 (Duration : 00:32:24)
??? Processes : 0 ???
??? Registry : 7 ???
[PUP] (X86) HKEY_LOCAL_MACHINE\Software\AVG SafeGuard toolbar -> Deleted
[PUP] (X64) HKEY_USERS\S-1-5-21-2941685042-3306150061-3194319401-1000\Software\AVG SafeGuard toolbar -> Deleted
[PUP] (X86) HKEY_USERS\S-1-5-21-2941685042-3306150061-3194319401-1000\Software\AVG SafeGuard toolbar -> Deleted
[PUM.SearchPage] (X64) HKEY_USERS\S-1-5-21-2941685042-3306150061-3194319401-1000\Software\Microsoft\Internet Explorer\Main | Search Bar : Preserve -> Replaced (
http://search.msn.com/spbasic.htm)
[PUM.SearchPage] (X86) HKEY_USERS\S-1-5-21-2941685042-3306150061-3194319401-1000\Software\Microsoft\Internet Explorer\Main | Search Bar : Preserve -> Replaced (
http://search.msn.com/spbasic.htm)
[PUM.Policies] (X64) HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Policies\System | ConsentPromptBehaviorAdmin : 0 -> Replaced (2)
[PUM.Policies] (X86) HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Policies\System | ConsentPromptBehaviorAdmin : 0 -> Replaced (2)
??? Tasks : 0 ???
??? Files : 1 ???
[Suspicious.Path|Suspicious.Startup][File] C:\Users\OWNER\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\processclose_1.0.0.3 - Shortcut.lnk -> Deleted
??? WMI : 0 ???
??? Hosts File : 0 ???
??? Antirootkit : 0 (Driver: Not loaded [0xc000035f]) ???
??? Web browsers : 0 ???
??? MBR Check : ???
+++++ PhysicalDrive0: WDC WD5000AZLX-00K4KA0 ATA Device +++++
--- User ---
[MBR] f411102b2b09b84cf9a380f82927a3a7
[BSP] 04149eb7c221d4aed748929e61cb394a : Windows Vista/7/8|VT.Unknown MBR Code
Partition table:
0 - [ACTIVE] NTFS (0x7) [VISIBLE] Offset (sectors): 2048 | Size: 100 MB [Windows Vista/7/8 Bootstrap | Windows Vista/7/8 Bootloader]
1 - [XXXXXX] NTFS (0x7) [VISIBLE] Offset (sectors): 206848 | Size: 476838 MB [Windows Vista/7/8 Bootstrap | Windows Vista/7/8 Bootloader]
User = LL1 ... OK
User = LL2 ... OK