Help interpret Rootkit logs

I have run various AV and rootkit scans using tools I found on BleepingComputer.com

A number of rootkits have already automatically been removed but it appears that some still remain, for example, the GMER log suggests that I am infected with “malicious Win32:MBRoot”, etc…

Your assistance in interpreting the logs and fixing the rootkits is greatly appreciated!

Regards

Ray

http://www.joeygalaxy.com/avlogs/TDSSKiller.2.7.45.0_10.07.2012_03.03.47_log.txt
http://www.joeygalaxy.com/avlogs/TDSSKiller.2.7.45.0_11.07.2012_01.07.06_log.txt
http://www.joeygalaxy.com/avlogs/tdsskiller.txt
http://www.joeygalaxy.com/avlogs/OTL.Txt
http://www.joeygalaxy.com/avlogs/GMER_11JUL12.log
http://www.joeygalaxy.com/avlogs/RootRepeal.txt
http://www.joeygalaxy.com/avlogs/TMRBLog_1341917694.txt
http://www.joeygalaxy.com/avlogs/avg_av.csv
http://www.joeygalaxy.com/avlogs/avg_rootkits.csv
http://www.joeygalaxy.com/avlogs/mbam-log-2012-07-10.txt
http://www.joeygalaxy.com/avlogs/regrunlog_UnhackMe.txt
http://www.joeygalaxy.com/avlogs/regrunlog_AVscan.htm
http://www.joeygalaxy.com/avlogs/RKreport.txt
http://www.joeygalaxy.com/avlogs/IceSword120_en.log
http://www.joeygalaxy.com/avlogs/FSS.txt

-edit-
The characters in the above logs don’t display properly when uploaded for some reason so I’ve added them to a RAR archive (some logs are too large to attach):
http://www.joeygalaxy.com/avlogs/logs.rar

Did you run GMER before or after TDSSKiller ?

Tools already used (in order from first to last):
tdsskiller
AVG AV scan
prevx webroot secureanywhere (Didn’t save log)
rootkitrevealer
MBAM
unhackme regrun (Removed a lot of infections with this)
icesword120
SpyBHORemover (Didn’t save log, recall removing a couple of BHOs)
OTL
FSS
RogueKiller
GMER
RootRepeal
AVG rootkit scan

New tools used since last post:
SpyDLLRemover log: http://www.joeygalaxy.com/avlogs/SpyDllRemover.html
aswMBR => Scan just finished, log is attached

Tools yet to be used:
Sophos Virus Removal Tool
Dr.Web CureIt!
ComboFix

Awaiting your instruction before I proceed further :slight_smile:

Massive thanks for your precious time!

Disk 0 malicious Win32:MBRoot code @ sector 625121283 !
With the old sinowal bootkits they left a copy of the files on a high sector of the disc. They are totally inert there and are of no consequence.. However, the only way to remove it is to format the drive. Which is not really needed

Great :smiley: So is it safe to assume I am clean or not yet?

Well the only thing left to throw at it is the kitchen sink ;D ;D