Is there a way to find out what process created certain file? [duplicate]
Process Monitor, from SysInternals, might be what you're looking for. It can be filtered to show just filesystem changes, and then you have the enviable task of filtering it manually to exclude the usual things like Windows Explorer.
EDIT: As a side-note, you may be able to eliminate the malware completely with ComboFix. This is available from BleepingComputer (but does not work on 64-bit Windows).