This is what I usually do when removing similar infections. First turn off system restore. Then go into safe mode and run combofix and smitfraud fix. Usually if there's one there's going to be...