I have a little question. Hoes does AV's remove file infections from system files? They sure can't wipe the modified bytes, replace with an original(because distribution is illegal) or remove the file, so how do they do it?
This is depends on AV and it implementation.
In several cases they
1) can ask you to allow download of clean file copy or use installation CD;
2) rebuild file, zeroing infection payload part/cut malware overlay and restoring EP/modified part (file still will be modified).