If the affected Windows machine has event logging enabled and those logs are sent elsewhere, clearing the log and rebooting the machine does no good.
I can tell you factually that every single one of our Windows Desktops and Servers sends their logfiles to a secure event logging solution where those logfiles cannot be manipulated or deleted.
It doesn't take much to then filter through the events to see what's happened/happening with any of our Windows (and Linux) serers, of which there are about 16,000 total.
The FireEye article - my reply 41 - will interest.