Guide | How To Antivirus Rescue CD/USB - Bootable Tools of Scanning and Removal of malwares

The associated guide may contain user-generated or external content.

viktik

Level 25
Thread author
Verified
Well-known
Sep 17, 2013
1,492
Antivirus Rescue CD/USB can be used to create a bootable CD/USB which can be used to scan a malware infected computer and to remove the detected malwares in the system.


  1. ESET SysRescue Live
  2. Kaspersky Rescue Disk 10
  3. BitDefender RescueCD (USB)
  4. Avira Antivir Rescue System
  5. Trend Micro Rescue Disk
  6. Norton Bootable Recovery Tool
  7. eScan rescue disk
  8. DrWeb Live CD/USB

Recommended : ESET, Kaspersky, Bitdefender, Avira

You can use Universal USB Installer to create live USB pendrive of antivirus rescue CD


Below you can see the list of antivirus rescue CD supported by it

1992094.jpg




1. ESET SysRescue Live
ESET SysRescue Live is a malware cleaning tool that runs independent of the operating system from a CD, DVD, or a USB. It has direct access to the disk and the file system, and therefore is capable of removing the most persistent threats.

More info : ESET SysRescue Live

User guide : http://download.eset.com/manuals/eset_sysrescue_userguide_enu.pdf


DOWNLOAD ESET SysRescue Live
Creating eset USB live rescue disk
  • Insert the USB Pendrive
  • start ESET Live USB Creator
  • If you have downloaded the ISO image file then tick "Use previously downloaded ISO file". Otherwise the image file will be downloaded from the internet.
  • Click "create USB drive"

1992086.jpg



  • carefully select the USB pendrive that you have inserted

1992087.jpg


  • All the data from USB pendrive will be overwritten.
  • Click "YES"

1992088.jpg


1992089.jpg


  • ESET rescue live USB pendrive created
  • If you downloaded the eset rescue image file from the internet click "Save ISO file" to save it for later use.
  • Click "close"

1992090.jpg



Using ESET rescue Live
  • Reboot the computer and boot using USB pendrive
  • Select Enable live grid early warning system
  • Select Enable detection of potentially unwanted applications

1992077.png


1992078.png


  • Connect to internet. You may have to do some network settings in order to internet.
  • Update the signature database

1992079.png




1992080.png


  • All the partition in hard disk will be mounted named "localDisk1" "LocalDisk2"

1992081.png


  • If threats are found, select the appropriate action

1992082.png


  • You can scan any file by doing a custom scan on selected partition

1992083.png



2. Kaspersky Rescue Disk 10
Kaspersky Rescue Disk is designed to scan, disinfect and restore infected operating systems. It should be used when it is impossible to boot the operating system.

Boot from the Kaspersky Rescue Disk to scan and remove threats from an infected computer without the risk of infecting other files or computers.

Burn this ISO image to a CD, insert it into the infected system’s CD-ROM drive, enter the PC’s BIOS, set it to boot from the CD and reboot the computer.

Kaspersky Rescue Disk 10 is designed to scan and disinfect x86 and x64-compatible computers that have been infected. The application should be used when the infection is so severe that it is impossible to disinfect the computer using anti-virus applications or malware removal utilities (such as Kaspersky Virus Removal Tool) running under the operating system.

In this case, disinfection is more efficient because malware programs do not gain control when the operating system is being loaded. In the emergency repair mode, you can only start objects scan tasks, update databases roll back updates and view statistics.

Kaspersky Rescue Disk 10 allows performing the following actions:

  • Configure objects scan settings:
  • change security level
  • change actions to be performed on detected objects
  • create a scan scope
  • change types of objects to be scanned
  • limit scan time
  • configure scan of compound files
  • change a scan method
  • set default settings
  • Configure databases update settings:
  • select an update source
  • specify proxy-server settings
  • specify regional settings
  • roll back to previous databases
  • Configure additional settings:
  • select detection of specific threat types
  • create a trusted zone
  • configure notifications settings
  • specify time of storing reports
  • specify time of storing Quarantine and Backup objects
  • Create a report on scan and update tasks.
  • View statistics about applican’s functioning.

User Guide : http://media.kaspersky.com/downloads/consumer/kasp10.0_rescuedisk_en.pdf

How to copy Kasperksy rescue disk to USB pendrive : http://support.kaspersky.com/8092


DOWNLOAD Kaspersky rescue CD


Create USB pendrive live rescue disk using Universal USB Installer

  • Insert a USB pendrive
  • Select "Kaspersky rescue disk" in Linux distribution
  • Browse the location of downloaded kaspersky rescue disk ISO image file
  • Select the USB pendrive "drive letter" .
  • Click "create"

1992095.jpg


  • Click "yes"

1992096.jpg


Using kaspersky rescue disk


1992098.jpg


  • You will need to do some network settings to connect to internet

1992099.jpg


  • update the virus database

1992100.jpg



  • each partition in the hard disk is mounted with names similar to "sda1" "sda2"

1992101.jpg


  • Scan setting



1992102.jpg


  • update settings.
  • you can manually update the database using the downloaded virus definition files

1992103.jpg


  • If malware is found then take appropriate action

1992104.jpg



3. BitDefender RescueCD (USB)
BitDefender RescueCD (USB) is for creating a bootable CD or USB (flash drive) to use on a computer that will not boot up to Windows due to damage caused by virus, trojans, worms or rootkits.

How to create a Bitdefender Rescue CD


DOWNLOAD BitDefender RescueCD

Create Bitdefender rescue USB pendrive

1992110.jpg


1992111.jpg



1992112.jpg


Using bitdefender rescue disk
  • Update the database

1992114.jpg


1992115.jpg


1992116.jpg


  • Take appropriate action
  • Disinfect is a good choice.

1992117.jpg


  • Click "fix issues" to remove the malwares
1992118.jpg


  • You may need to do network setting to connect to internet

1992122.jpg


  • add the network connection settings that is required to connect to internet

1992121.jpg


  • you can do manual database update using downloaded the bitdefedner virus database file.

1992124.jpg




4. Avira Antivir Rescue System

The Avira Rescue System scans and repairs malware-infected computers that no longer boot or are generally unresponsive. Running on both Windows and Linux operating systems, our integrated scan and repair Wizard is highly intuitive and easy to use. Are you concerned about recovering data from your system? If so, the Avira Rescue System is the ideal tool for you. And if for some reason you need outside assistance, the Rescue System can establish a remote desktop connection with Avira Support. The Avira Rescue System is updated daily so that the most recent security updates are always available. To use the Rescue System burn it to a CD or copy it to a bootable USB stick and then boot your system from that CD or USB stick.

How to use Avira Rescue System

How to use Avira Rescue System


DOWNLOAD Avira Antivir Rescue System

Documentation


  • Select the drive which you want to scan

1992387.png


  • using file explorer you can check which drive has the windows operating system installed. That will be the drive that you need to scan
  • You may scan all the drives in the computer

1992384.png



1992385.png


  • you may need to do network settings in order to connect to internet
  • From "system settings' click "Network" to do the network settings

1992388.png



5. Trend Micro Rescue Disk

It uses DOS like interface.

Trend Micro Rescue Disk allows you to use a CD, DVD, or USB drive to examine your computer without launching Microsoft Windows. It finds and removes persistent or difficult-to-clean security threats that can lurk deep within your operating system.

Rescue Disk does not need to load potentially-infected system files into memory before trying to remove them. It can scan hidden files, system drivers, and the Master Boot Record (MBR) of your computer’s hard drive without disturbing the operating system.

Boot Device Support

  • Ability to boot from CD/DVD or USB
Getting Started

  1. Click Download to begin.
  2. If prompted, click Save or Save As, and save the file on your computer’s desktop.
  3. While the installer downloads, prepare one of the following:
    • Blank CD or DVD (do not use a rewritable disc)
    • Empty USB Drive (128MB or larger)
      NOTE: The drive will be reformatted before creating Rescue Disk, and anything already on the USB drive will be lost. Please back up any important files before using a USB drive for Trend Micro Rescue Disk.
  4. When you have finished downloading the file, double-click the Trend Micro Rescue Disk icon to start the installer.


To launch your computer from a CD or DVD, you must set the BIOS to boot from a different device. While the exact procedure differs from computer to computer, the overall process is usually like this:

  1. Insert the disc or USB drive into the computer.
  2. Restart the computer.
  3. When the computer powers up again, look for a BIOS setup message, which often looks like “Press [KEY] to run Setup” where [KEY] might be Delete, ESC, or one of the F1–F12 keys.
  4. Once the BIOS Setup Utility has opened, look for a tab labeled Boot, Boot Order, or Boot Options.

DOWNLOAD Trend Micro Rescue Disk

To create USB pendrive containing Trend micros rescue disk

  • Insert USB pendrive
  • Execute trend micro rescue disk
  • Select "USB Device"


1992379.jpg


  • Select the USB pendrive . Make sure the drive letter you choose it for correct USB pendrive
  • Click "create"
1992380.jpg


  • click "create now"
1992381.jpg

  • Click "later"

1992382.jpg



6. Norton Bootable Recovery Tool
Gets your computer back up and running if it becomes so infected that it won’t work properly or even start.

The Norton Bootable Recovery Tool helps fix your “worst nightmare” computer problems, such as when crimeware embeds itself so deeply into your computer’s operating system that it takes a special tool to remove it. Norton Bootable Recovery Tool does two things:

  1. It helps you create customized rescue media (CD/DVD/USB) before your system becomes infected
  2. In the event of an emergency situation where your computer has become so infected that it won’t start, it will help restore your computer to normal working order
When you first install your Norton Security Software, be sure to take a moment to download the Norton Bootable Recovery Tool wizard and follow the simple steps to create your customized rescue media. Your customized copy of Norton Bootable Recovery Tool can be used to start your computer in a safe environment, then remove the threats that caused the problem. For full functionality, Norton Bootable Recovery Tool requires a wired Internet connection.


DOWNLOAD Norton bootable Recovery Tool




7. eScan Rescue Disk
Uses very basic interface. Updating database is tough. Has very basic network settings to connect to internet.

Some malware are very destructive in nature or badly programmed that they affect the stability of Windows leading to recurring crash of programs and Windows. It then becomes a nightmare to correct the Windows Operating System if you’re unable to boot in to Windows even in Safe Mode. This makes it very hard for the technical person to troubleshoot and fix the problem and they normally end up reformatting the hard drive to reinstall Windows. This can lead to loss of data and productivity.

There are also other malware that get embedded very deeply in the Windows operating system in such a way that whenever you boot Windows, the malware is also loaded at the startup and may escape detection by the antivirus software running in the system.

In such cases you will need to start Windows from a clean source to scan and remove the malware and fix Windows errors. eScan Rescue Disk provides you with a Windows based clean environment that not only helps you to scan and clean the system but also to fix the Windows registry changes done by viruses.


DOWNLOAD eScan rescue disk

Documentation





8. DrWeb Live CD/USB
Emergency System Recovery Disk


If your Windows or Linux system has been rendered non-bootable by malware, restore it for FREE with

Dr.Web LiveCD

Dr.Web LiveCD will clean your computer of infected and suspicious files, help you copy important information to a removable data storage device or another computer, and then attempt to cure infected objects.

How it works : http://www.freedrweb.com/livecd/how_it_works/

DOCUMENTATION
DOWNLOAD Dr Web Live CD


Dr.Web LiveUSB


Use a USB flash drive to restore your system

Dr.Web LiveUSB enables you to perform the emergency repair of an operating system using a USB flash drive.

The solution supports Windows operating systems (32- and 64-bit). In order to boot Dr.Web® LiveUSB, BIOS of your computer must support USB-HDD boot devices.

How it works


DOWNLOAD DrWeb Live USB


creating Dr web rescue disk USB pendrive

  • Insert the USB pendrive
  • Start the Dr Web Live USB
  • Select the USB pendrive
  • Click "generate Dr. web livedisk"

1992172.jpg



1992173.jpg



1992174.jpg


using Dr web live disk



1992175.png


  • Update virus database
  • You may have to do network settings to connect to internet

1992181.png


  • The hard disk partition is named as "sda1" "sda2"
1992177.png



  • Custom scan allows user to scan any folder

1992176.png


  • Neutralize the detected malwares

1992180.png
 
Last edited:

jadequest99

Level 3
Verified
Sep 15, 2014
103
Would like some advice on which of these two rescue system usb is best? I just want to choose either ESET SysRescue or Kaspersky Rescue Disk 10? I don't know much about "Dr. Web LiveDisk?" I went to the website but rather get suggestions before I download & install first. Thanks MT's community.
 
Last edited:

jadequest99

Level 3
Verified
Sep 15, 2014
103
I'm just now watching a tutorial and backup my files incase something goes wrong, so I can't give you any advice on what to do. Caution though these videos are not recent.
If you want there's a video on YouTube Link you can watch :





 
Last edited:

nissimezra

Level 25
Verified
Apr 3, 2014
1,460
I'm just now watching a tutorial and backup my files incase something goes wrong, so I can't give you any advice on what to do.
If you want there's a video on YouTube Link you can watch :


thanks bro
i followed britec video and everything looks great but when tsting it boots but stuck somewhere.
 

nissimezra

Level 25
Verified
Apr 3, 2014
1,460
Would like some advice on which of these two rescue system usb is best? I just want to choose either ESET SysRescue or Kaspersky Rescue Disk 10? I don't know much about "Dr. Web LiveDisk?" I went to the website but rather get suggestions before I download & install first. Thanks MT's community.
eset is much better. i use to use kaspersy but since eset came I started using it.
 
  • Like
Reactions: marzametal

nissimezra

Level 25
Verified
Apr 3, 2014
1,460
try to download the Sardu in another browser like Firefox and try it again, could be the USB stick?
no problem to downlowad the problem is that it doesnt work. let say you boot to kaspersky, it will boot but when scan it stack. you work for nothing. i built a usb but when boot everything stack
try it and let me know if it works with scan not only boot
 
  • Like
Reactions: Moose

jadequest99

Level 3
Verified
Sep 15, 2014
103
I used DrWeb's and it found too many false positives, but that's my experience using it. I went with ESET SysRescue Disk instead.
 

Trave160

New Member
Apr 16, 2015
2
Btw there's showing "No network connection" on my PC in ESET rescue disk. Probably cause am using a different Ethernet Port cause of my gaming motherboard. Is there a way to manually update the ESET sysrescue USB?
 

viktik

Level 25
Thread author
Verified
Well-known
Sep 17, 2013
1,492
Btw there's showing "No network connection" on my PC in ESET rescue disk. Probably cause am using a different Ethernet Port cause of my gaming motherboard. Is there a way to manually update the ESET sysrescue USB?

you will have to do some network settings to connect to internet. it uses linux operating system. If you can do network setting in linux then it will work

If you downloaded the eset rescue image file recently then it already has the latest database.
 
Last edited:

Trave160

New Member
Apr 16, 2015
2
you will have to do some network settings to connect to internet. it uses linux operating system. If you can do network setting in linux then it will work

If you downloaded the eset rescue image file recently then it already has the latest database.

I did, no point cause I don't think the driver supports the Ethernet Adapter on the mobo. I use Static IP doesn't even work some of the rescue disks actually supports my Adapter but this one doesn't
 

About us

  • MalwareTips is a community-driven platform providing the latest information and resources on malware and cyber threats. Our team of experienced professionals and passionate volunteers work to keep the internet safe and secure. We provide accurate, up-to-date information and strive to build a strong and supportive community dedicated to cybersecurity.

User Menu

Follow us

Follow us on Facebook or Twitter to know first about the latest cybersecurity incidents and malware threats.

Top