This would appear to be the same Fake AV that I removed from a clients machine recently it starts as a drive-by and produces some good fake windows system messages.

I had to use safe mode (with process explorer, autoruns, and manual removal) to remove it, so I personally think that there is a merit in safe mode for infection removal, even if it's just the fact that you are dealing with a lot fewer processes that can interact with the malware.

What I often do is to start with a bootable media based scanner and then safe mode and finally follow up with a normal running mode deep scan and disinfect, of all attached drives. This may be overkill but I find it's cheaper for the customer in the long run as it tends to prevent re-infection, which is the goal here