1) Delete most of the comments 2) Stuff breaks. WTF? The code was processing its own comments!
Also I would add a third option here (the option we chose with LedgerSMB) which is:
"Localize the bad code, and replace with good code, a block at a time."
Some code can never be cleaned up effectively. In this case, you separate out, rewrite, and live with the fact that this will break some stuff while you get something that, on the whole, is more robust. Now in this approach the thing that is critical is you make as few changes to the legacy code base as you can. You also look for other layers at which you can implement things like new, needed security controls, or API's and you do everything you can to avoid putting new stuff through the legacy sections.