Also, since you were able to pull off a sfc /scannow I think you might be able to enable the built in admin account or create a new account through the command prompt; then use the Bootsafe tool to enable safe mode so we can get a FRST scan from the infected account.
Once you have created the new account log out of the infected account and run the bootsafe tool from the new account.
Once in safe mode run a FRST scan on the infected account.
Once you have created the new account log out of the infected account and run the bootsafe tool from the new account.
Once in safe mode run a FRST scan on the infected account.
Comment