Combofix rootkit detected, cannot remove

I've removed a LOT of infections from this computer.  TDSSKiller found several rootkits.  I have ran Malwarebytes, Avast! Free Antivirus, SUPERAntiSpyware, and Combofix.  I have done a repair install of Windows XP.  Someone suggested running GMER, but I'm not sure how to read it.  I'm uploading the results.

Combofix will say Rootkit is detected, and then will freeze after that message is displayed.  The only way I can get Combofix to run all the way through is to use the /nombr switch.  I have ran it again after and get the same result.  Any suggestions?
gmer.log
LVL 8
Scott ThompsonComputer Technician / OwnerAsked:
Who is Participating?
 
jacobstewartConnect With a Mentor Commented:
If its that badly infected.  backup the data format and reinstall.  A computer is never the same after being infected like that.

Even if you do get it "clean" and something comes back 3 weeks down the road it will come back to you.
0
 
willcompCommented:
Does TDSSKiller still show a rootkit present? If so, which one?

The important thing now is to identify the rootkit.
0
 
ryan80Commented:
I would wipe that bad boy clean and reinstall.
0
Improved Protection from Phishing Attacks

WatchGuard DNSWatch reduces malware infections by detecting and blocking malicious DNS requests, improving your ability to protect employees from phishing attacks. Learn more about our newest service included in Total Security Suite today!

 
Sudeep SharmaTechnical DesignerCommented:
Post the TDSSKiller logs. Further did you tried FixTDS from Symantec as well.

FixTDSS Download
http://www.symantec.com/content/en/us/global/removal_tool/threat_writeups/FixTDSS.exe
0
 
Scott ThompsonComputer Technician / OwnerAuthor Commented:
I have tried FixTDSS from Symantec.  I will upload the TDSSKiller results, which did not find anything.
TDSSKiller.2.8.6.0-16.08.2012-13.txt
0
 
Sudeep SharmaTechnical DesignerCommented:
Logs contained in "TDSSKiller.2.8.6.0-16.08.2012-13.txt" wasn't completed, it ends at 13:42:25.0531 3312  [ ca7e42e0b8d117165ed553a7d681352a ] SeaPort, so I would still suggest to run it again and make sure it completed.
0
 
Scott ThompsonComputer Technician / OwnerAuthor Commented:
Customer decided to reload.  Thank you for your help!
0
Question has a verified solution.

Are you are experiencing a similar issue? Get a personalized answer when you ask a related question.

Have a better answer? Share it in a comment.

All Courses

From novice to tech pro — start learning today.