Please download TDSSKiller
Save it to the Desktop.
Note: If the infection does not let you download files on the infected computer, download the files/programs requested below to a clean computer and then transfer them to the Desktop of the infected computer. You can use a USB flash drive, or other removable media (CD, DVD, or, external hard drive).
Double-click* on TDSSKiller.exe to run the tool.
(*Vista/Windows 7 users, right-click the file, and select: Run As Administrator)
Click the Start Scan button.
Do not use the computer during the scan
If the scan completes with nothing found, click Close to exit.
When the scan finishes it displays a Scan results screen stating whether or not an infection was found on your computer.
To remove the infection, click on the Continue button.
If it does not say Cure on the results screen, leave it at the default action of Skip, and press the Continue button.
Do not change to Delete or Quarantine as it may delete infected files that are required for Windows to operate properly.
Reboot to finish the cleaning process.
If no reboot is requested, click on Report.
A log file should appear.
A log file named TDSSKiller_version_date_time_log.txt (i.e. TDSSKiller.184.108.40.206_27.07.2010_09.o7.26_log.txt) is created and saved to the root directory (usually Local Disk C:).
>>Please provide the contents of TDSSKiller in your reply.<<
Next, download Malwarebytes’ Anti-Malware (black button with green and white icon) Save to the Desktop:
Double-click mbam-setup.exe and follow the prompts to install the program. (For Vista/Windows 7, select: Run as Administrator)
Run Malwarfebytes’ AntiMalware and update the program.
Once updated, select Perform Full Scan and click the scan button.
When the scan finishes, click OK in the message box, and you will see the results of the scan.
Click the Remove Selected button to get rid of the malware.
When Malwarebytes finishes, you may be prompted to reboot. If so, reboot.
>>Please post the TDSSKiller and the Malwarebytes logs in your reply so we can see where we are at, and plan any additional removal strategy, if necessary.<<