By the description it sounds like they are detecting safemode and restarting the computer if safemode is detected. If so, the trojan has evolved, perhaps with a rootkit layer.
PS: Whatever remedy is tried, first disconnect the machine from the internet by unplugging the ethernet cable or shutting off wifi.
PS: Whatever remedy is tried, first disconnect the machine from the internet by unplugging the ethernet cable or shutting off wifi.