Kaspersky Rescue Disk is a bootable security environment for examining a Windows computer without starting its installed copy of Windows. The user writes the rescue image to a USB drive or DVD, starts the computer from that media and runs Kaspersky Rescue Tool inside a separate operating environment. Malware that blocks an installed antivirus or starts early with Windows has less control over this outside scan.
Booting comes first
The computer must start from the rescue medium rather than its internal drive. That may require the firmware boot menu, a changed boot order or approval for removable media. Copying the image file onto an ordinary USB folder is not enough; a suitable imaging utility must write it as bootable media.
Kaspersky Rescue Disk targets x64 computers that run Windows. A very old processor, limited memory or unsupported graphics device can prevent the graphical session from opening. The rescue menu includes alternate startup choices, but compatibility cannot be assumed merely because Windows runs on the same machine.
Updates need a network
The downloaded image carries anti-virus databases, yet threat information continues to change after that image was created. Kaspersky Rescue Disk needs Internet access to update its databases and consult Kaspersky Security Network. A scan can run with older data, but it has less current information.
Network access can be awkward in a rescue session. Wi-Fi may need credentials again, and some adapters lack a working driver in the boot environment. A wired connection can reduce that uncertainty. The database date should be checked before a long scan, not after the computer has already spent hours reading every file.
Hidden disks need caution
A storage device may not appear when the computer firmware uses Intel RST, RAID mode or a VMD controller. The official troubleshooting path may require switching the storage mode to AHCI or disabling VMD temporarily. These changes affect how the installed operating system reaches its disk.
Changing a firmware storage setting without recording its original value can leave Windows unable to boot later. Kaspersky directs the user to restore the original settings after rescue work. If the disk remains absent, collecting the hardware information report is safer than repeatedly changing unrelated firmware options.
Scan actions affect files
Kaspersky Rescue Tool lets the user choose scan targets and records detected objects in a report. Quarantine isolates an object while retaining a recovery path. Deletion removes that path, so an uncertain detection should be reviewed before the most permanent action runs.
Encrypted volumes and damaged files can limit what the scanner reads. A clean report does not prove that an unmounted or inaccessible volume was examined. The target list and final report need to show the expected disks and directories. Registry Editor is also present, but Kaspersky warns that manual registry changes can damage Windows.
Persistence has boundaries
A special partition on the USB drive can retain selected application and network settings between rescue sessions. Kaspersky Rescue Disk still stores databases, reports and other working data on the computer’s hard drive. Persistence therefore does not turn the USB stick into a complete portable case record.
The cleanup commands remove different amounts of data. Database cleanup deletes only the local anti-virus databases. Full artifact cleanup also removes quarantine, reports, dumps and traces, then restarts the computer. Reports or quarantined samples needed for later review must be copied before that cleanup runs.
Recovery remains separate
Removing malware does not repair every change it made. A damaged boot loader, deleted system file or encrypted document may still require Windows recovery tools or a known backup. Kaspersky Rescue Disk is designed to find and neutralize suspicious objects; it cannot reconstruct data that no longer exists.






