If you suspect that your device has been compromised, the first thing to do is rescind
all SU permission in your root management app (SuperSU, Superuser, SU Manager etc), forcing you to explicitly grant SU permission to any app that requests it.
I'd then advise resetting
all passwords from a desktop browser (or other standalone device,
not the suspect one) to counter/pre-empt any attempts to hijack online accounts.
Once that's done. I'd further advise a complete reset (factory data wipe) of the device. Skip the "automatically restore..." part of the setup procedure, and asap download
AFWall+ from the Play Store. This excellent firewall app will guard against unwanted intrustions/external connections. Another app that comes highly recommended here is
Network Connections, which will allow you to examine every external connection to/from your device.
By all means save and post logs, but the priority right now is to secure your device; the forensics can wait for the moment.