|You need to disable all lan traffic. Sweep each machine, each usb drive and everyone's flash.|
See lsass.exe in users logon in documents and settings folder. Rename to lsass.exe old. Do that to all users. Regedit out all lsass.exe in users (be careful lsass.exe is real file only in users) Reboot.
See how to diable autorun in registry also.
On everyones flash drive make a hidden folder named autorun.inf and maybe start.exe or whatever other file is named in the bad autorun.inf file.
Might need to clean install all machines and update all hotfixes and service packs. Reload all av an malware
Then put back on line and hope best practices prevent this again.
"Best Practices", Event viewer, host file, perfmon, antivirus, anti-spyware, Live CD's, backups, are in my top 10