I would. The machine's been fully compromised for close to 4 weeks. If it's opening things on startup, then there's no telling what else it's done at startup that erased itself.
Make sure to rotate out passwords as well as they've most likely been seen or downloaded.
MailEnable survivor / convert --