Ok, the usual problem that has been brought to me for repair... here's the easiest way to do it.
This method doesn't require an extra PC, we do it on the infected PC.
Download Kaspersky Anti-Virus... the best IMO. Rename its installer to [random letters or numbers].exe or .msi, why? Brontok will detect program names and windows with 'ANTI, VIRUS, CMD, EXE' so on and closes it so you won't be able to install anything that would remove it.
If you got a Kaspersky license key place it on the same folder as the installer for auto detection and get it to run in full mode.
Now how can you install something when brontok closes every program installer?? We use the installer parameter! Every known installer maker have their own parameters for unattended or optional install.
The Setup (This is a rough example):
Right drag on the kaspersky installer and release... you'll see a menu pops up, select 'Create Shortcut'... then right click on the shortcut and select 'Properties', you are now on the shortcut properties window... on the 'Target' field after the double qoutes add /QUIET for this will install kaspersky in quiet mode without opening any window, in other words will just install in the background so brontok won't be able to detect it.
Wait.... after a few minutes you will notice your hardrive had stopped its read/write process which is a good sign that it has finished installing...
Restart and see the magic! It will block every autostart of the virus... now clean and scan the whole drive until it is clean.
Residue? There are! When you restart again... you'll notice an error message "Cannot find.." you just have to remove it from the registry... but registry is locked right?
Download 'Windows Configurator' its a free registry tweaker and unlocks your locked registry!
You can now go to run type 'regedit' and search for the filename that was displayed on the "Cannot find..." dialogue box... remove that added entry.. usually added on the end of the '.exe' registry entry...
If 'Folder Options' is lost... search google on how to restore it.. just requires a few registry tweaks again.
Reply