Best Practice - Virus Scan of DeltaV Workstation in a domain, restored from an image (Acronis Backup)

Scenario - A suspected exploit has caused me to wipe all operator stations & restore them from a recent saved image. Before connecting it to the domain, I want to check that the image does not contain a (the) virus. What sounds like the best practice?

  • Download a virus scanner from the internet that runs on bootable media; create enough bootable USB's to minimize downtime (scan multiple operator stations in parallel)?
  • Create a local administrator account (uncommon name) that will gain desktop access while isolated; update Trellix locally (assume this is possible when no connection to ePO), then scan with Trellix from Windows.
  • Another alternative?