OS – Microsoft – Windows – Rescue CD

OS – Microsoft – Windows – Rescue CD

Anyone in IT hears that call all too often.

My PC is dead.  Please help!

What options does one have …

  • Drive cross country
  • Drive a couple of hours

All good options.  But, another option is to make a rescue CD, snail mail it, and hopefully it helps.

Here is a good, easy to read and understand write-up on what a Rescue-CD is:


Once a system is infected with malware it becomes difficult to remove that malware as it is already embedded in the system and has control over many components which are key to the system’s operations. Malware, like rootkits, use system components to hide themselves and prevent other software from detecting or removing them. This is often the case of who gets there first; if the malware is able to get control of the system earlier on then it also has control over any software that may be run later. Besides just hiding, malware can also block the execution of other security applications. If you cannot install or run a security application in the first place then you cannot scan and detect the malware. The best time to remove this malware is when it is not running, but malware often starts with the Operating System, so we would have to stop the Operating System to stop the malware. On a shutdown OS nothing is running and malware like rootkits cannot hide themselves and so it would be easy to find and remove them.

Here are some Vendors \ Products.

  1. Microsoft (Windows Defender Offline)
  2. AVG – Rescue CD
  3. F-Secure (Rescue CD)
  4. Kaspersky (Rescue CD)
  5. Norton Power Eraser
  6. Norton Bootable Recovery Tool
  7. PC Tools – Alternate Operating System Scanner

To use this Rescue-CD the general steps are:

  1. Visit the Vendor’s web site
  2. Download the file.  It will usually be bundled as an ISO file.  Thus ensuring that one can smoothly burn it unto a CD and boot from it
  3. Burn the ISO file using a tool such as ISOBurn (http://www.imgburn.com/), Free ISO Burner (http://www.freeisoburner.com/), ISO Recorder (http://alexfeinman.com/isorecorder.htm)
  4. Once you have a Rescue-CD, reboot your machine
  5. During the Boot Sequence, choose your CD/DVD as your boot media
  6. Once booted, follow the offered screen sequence

My personal take and experience:

  1. As the tools mentioned here are trying to identify and address problems with MS Windows based install, they are apt to load and run within a foreign OS such as Linux.  The Linux variant might not have a nice graphical, touched up interface such as Ubuntu.  And, so if you ‘re thinking of sending it to Aunt Sally or Aunt Suzie, she might not take well to the general obtuse interface and rather live with the infection.
  2. I could not get MS Windows Defender to run.  I downloaded a copy on 10/10/2012 and tried running it on 3 PCs, but no help
  3. The “PC Tools – Alternate Operating System Scanner” package was last updated on Dec 9, 2010.  As time passes and the bundled Virus Signature ages, it might not be as effective against more recent viruses.
  4. Along the same lines per efficacy of the PC Tools’ Alternate Operating System Scanner Tool, it failed to run on a couple of machines.
  5. On the other hand, the Kaspersky tool quickly proved to be approachable and useful.  Upon booting up a computer with the Kaspersky Rescue CD, you will quickly see a very appealing desktop based on Gentoo Linux.  The subsequents menus are easy to understand and follow.  It is easy enough to choose which partitions you want to Scan.  And, when you come to the critical junction of choosing which if any of the infected files you want to heal, remove, or leave as is your choices could not be any easier.



  1. Big Geek Daddy – Free Virus Cleaners


Leave a Reply

Please log in using one of these methods to post your comment:

WordPress.com Logo

You are commenting using your WordPress.com account. Log Out /  Change )

Twitter picture

You are commenting using your Twitter account. Log Out /  Change )

Facebook photo

You are commenting using your Facebook account. Log Out /  Change )

Connecting to %s