It looks that Symantec's FixTDSS is able to remove TDL3 - tested on Jaxryley's sample.
I am Jack's NULL pointer (actual e-mail contact.ntinternals_at_gmail.com)
A forum for reverse engineering, OS internals and malware analysis
1312 DllMain|module: \\?\globalroot\lhjwnnds\vltmjrsb\tdlcmd.dll version: 0.2
1312 isProcess|iexplore.exe
1312 isProcess|isBrowser: iexplore.exe TRUE
1312 ModuleAdd|tdlcmd (00260000): \\?\globalroot\lhjwnnds\vltmjrsb\tdlcmd.dll
1312 HOOKWSPStartup|start hooking 1312
1312 initsettings|botid: xxxxxxxxxxxf04a530b49a092c7d006de7e affid: 93035 socks: 0 reboots: 2 uptime: 0 version: 0.2
1312 HOOKDnsQuery_W|DnsQuery_W
1312 HOOKDnsQuery_W|DnsQuery_W
1312 CheckDomain|start CheckDomain http://www.google.com.au
1312 CheckDomain|CheckDomain(http://www.google.com.au) 0x635d7d4a
1312 _strformat|alloced: 30 printed: 25
1312 ClickerSendCheck|url: http://www.google.com.au/ ref: (null)
new tdl4 version appeared, 0.03 (cfg.ini)Hello,
[main]
version=0.03
aid=40124
sid=0
builddate=4096
rnd=179605362
[inject]
*=cmd.dll
[cmd]
srv=https://nichtadden.in/;https://91.212.226.67/;https://li1i16b0.com/;https://zz87jhfda88.com/;https://n16fa53.com/;https://01n02n4cx00.cc/;https://lj1i16b0.com/
wsrv=http://zl00zxcv1.com/;http://zloozxcv1.com/;http://71ha6dl01.com/;http://axjau710h.com/;http://rf9akjgh716zzl.com/;http://dsg1tsga64aa17.com/;http://l1i1e3e3oo8as0.com/;http://7gafd33ja90a.com/;http://n1mo661s6cx0.com/
psrv=http://clkh71yhks66.com/
version=0.14