I would format and reinstall the OS on the infected machines. If these are work machines you do not want a keylogger or spam bot left on a machine because it wasn't detected or couldn't be removed.
You should run a root kit detection program also on the other computers.
Probably not the answer you were hoping for, but it's the only way you can be sure viruses, root kits and spyware are fully removed. RootkitRevealer v1.71
Also for future security I would consider a product like this to protect your whole office network. Astaro Internet Security - Astaro Security Gateway Overview