First of all you need to isolate the infected machines.
if its already on the servers, unplug them from the network.
if anitvirus software is failing to fix the problem, is it failing to update from the sophos website? and are the clients updating properly. I know when we had sophos here before we switched to Nod32 it didnt always dish out the updates from the server to the clients; had to keep a close eye on that little nasty.
Have you tried runing any trojan remover software such as s&d or adawere too see if they have any luck.
Im sure i once came across this once and i found it hidden in the "documents and setting" area possibly under application data. best do a search for ctfmon.exe and delete it if you find it there.
as for the infected machines, just send out an image, no point in messing about with them.
for now with staff having the same problem at home, i would test all there data sticks on a isolated machine. If they use there laptops on the network, i would disable the teaching staff laptops in AD so they cant logon till you have a look at them all.
cant think of any thing else.