Things that stick out for me..

R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = https://www.datafarm.com/scripts/datafarm.dll

O23 - Service: gearsec - GEAR Software - C:\WINDOWS\system32\gearsec.exe



But I'm not really qualified to determine if they are a genuine thread or a genuine app..