Hi Colby.
The desktop problem is from a SmitFraud varient called Privacy Danger. There is also CoolWebSearch and a couple trojans in your log. You might want to print the following as there are several steps and you will not have an interent connection while working in safe mode.
Download Smitfraudfix from Here or Here. Double-click smitfraudfix.exe, Select 1 and hit Enter to create a report of the infected files. The report can be found at the root of the system drive, usually at C:\rapport.txt
Reboot your computer in Safe Mode (before the Windows icon appears, tap the F8 key continually).
Double-click smitfraudfix.exe, Select 2 and hit Enter to delete infect files.
You will be prompted: Do you want to clean the registry ? answer Y (yes) and hit Enter in order to remove the Desktop background and clean registry keys associated with the infection.
The tool will now check if wininet.dll is infected. You may be prompted to replace the infected file (if found): Replace infected file ? answer Y (yes) and hit Enter to restore a clean file. A reboot may be needed to finish the cleaning process.
To restore Trusted and Restricted site zone, select 3 and hit Enter.
You will be prompted: Restore Trusted Zone ? answer Y (yes) and hit Enter to delete trusted zone.
Note: process.exe is detected by some antivirus programs (AntiVir, Dr.Web, Kaspersky) as a “RiskTool”. It is not a virus, but a program used to stop system processes. Antivirus programs cannot distinguish between “good” and “malicious” use of such programs, therefore they may alert the user.
http://www.beyondlogic.org/consulting/proc...processutil.htm
Next, Download CWShredder Here to its own folder.
Update CWShredder
[]Open CWShredder and click I AGREE
[]Click Check For Update
[*]Close CWShredder
Boot into Safe Mode:
Restart your computer and as soon as it starts booting up again continuously tap F8. A menu should come up where you will be given the option to enter Safe Mode.
Now run CWShredder. Click I Agree, then Fix and then Next, let it fix everything it asks about. Reboot your computer into normal windows.
Now open HJT and click to Do a System Scan Only. When complete place a check mark next to the following lines that are still present
O2 - BHO: MSVPS System - {88418AA3-16F5-4FC2-A9D8-90B1266DF841} - C:\WINDOWS\nsduo.dll
O4 - HKLM..\Run: [scroller] fpapli.exe
O16 - DPF: {29614A0D-8046-4476-A4E1-E2B430220C98} (Project1.ampSearch) - file://C:\fsms_data\nbwe\ampsearch.CAB
O21 - SSODL: sysdx - {9FB5DA97-7E67-440D-BF7C-AFFBA9F29055} - (no file)
O21 - SSODL: msmdev - {324AA5AB-4CD5-4901-B64A-31BC87C70627} - C:\WINDOWS\msmdev.dll
O21 - SSODL: msmhost - {65A968D6-46F6-4D2A-A7B1-1CD878F7C202} - C:\WINDOWS\msmhost.dll
O24 - Desktop Component 0: Privacy Protection - file:///C:\WINDOWS\privacy_danger\index.htm
Close all other windows, including your browser, and click Fix Checked
Download the OTMoveIt http://download.bleepingcomputer.com/oldtimer/OTMoveIt.exe by OldTimer.
Save it to your desktop.
Please double-click OTMoveIt.exe to run it.
Copy the file paths below to the clipboard by highlighting ALL of them and pressing CTRL + C (or, after highlighting, right-click and choose copy):
C:\WINDOWS\nsduo.dll
C:\Windows\system32\fpapli.exe
C:\WINDOWS\msmdev.dll
C:\WINDOWS\msmhost.dll
C:\WINDOWS\privacy_danger
Return to OTMoveIt, right click on the “Paste List of Files/Folders to be moved” window and choose Paste.
Click the red Moveit! button.
Copy everything on the Results window to the clipboard by highlighting ALL of them and pressing CTRL + C (or, after highlighting, right-click and choose copy), and paste it on your next reply with a new Hijack log.
Close OTMoveIt
If a file or folder cannot be moved immediately you may be asked to reboot the machine to finish the move process. If you are asked to reboot the machine choose Yes.
After completing everything above, post the SmitFraudFix log, the OTMoveIt results, and a fresh HJT log.
Please note: The following line must not be fixed in HJT
O10 - Unknown file in Winsock LSP: c:\windows\system32\nwprovau.dll
Doing so will kill your internet connection.
Please upload this file to Virus Total
c:\windows\system32\nwprovau.dll