From the link: 'Remember: the only 100% foolproof anti–stealth
technique is to cold booting the computer from a non–infected write–
protected system diskette, to ensure that no virus is present in
memory. '
Wow. Does anybody really do this?
***
Everybody that does malware removal for others *should* be doing this.
Working on a live infection can be like a dog chasing its tail. Some even
suggest swapping out the harddrive to a known clean surrogate computer and
scanning the drive with *that* system to avoid any possibility of malicious
code interfering with the process.
Some malware is really easy to remove, and it is not even necessary to
"clean boot" - so, it depends on what you are dealing with.
***
I've never heard of this being done. Does Norton, Symantec, etc even have
such an option?
***
They *all* have rescue disks as far as I know, some require or suggest that
the user create one when first executing the AV program. There is also a
create boot disk suggestion when completing the install of most OSes.
***