try looking in c:\users\*account name*\AppData\local, good chance you have an exe made up of random letters/numbers, but really any exe there you can consider suspect. Take its name, delete it, then search your registry(start, run, regedit) for the name of it and delete all references to it(normally two).
You can also likely deal with it outside of safemode. When you first log in load up task manager(ctrl + shift +esc), if your quick that will load up before the virus. If you dont get it in time just log out and repeat. If you do get task manager right click on the rogue application and select go to process. From here you have the name of the exe and you can kill the process too.
That will work for 90% of the fake anti-virus things. But really only need to do that if you cant get malware bytes running.
edit: that is assuming vista or 7, some steps will be slightly different in xp. mostly the location of your documents