A colleague of mine had an idea, one which I cannot seem to figure out how to implement. I figure this might be a possible stopgap solution to this infection seeing as it relies on Power Shell do to all it's malicious actives.
His idea - Great a group policy that disables Power Shell. This would in theory prevent the infection from performing its higher level functions. As I understand it the whole point of the program up until Power Shell is getting Power Shell downloaded/to run and that the heavy lifting is done via Power Shell.
I don't know if you can do group policy changes via a batch file, but assuming you could, this would make it easy to push this change to every computer on your network so that Power Shell is disabled (even when installed).