I hope you still remember the 13 antivirus rescue CDs that I’ve tested and here is another one from ESET. Even RISING Antivirus has officially included a rescue CD into their latest 2009 release. Actually I wanted to test ESET’s rescue disk when it was still in BETA but it turns me off because it requires me to download a file that is over a gigabyte in order to create the Rescue LiveCD.
ESET SysRescue is a new feature that you can find in the latest ESET NOD32 Antivirus v4 and ESET Smart Security v4. ESET SysRescue is a utility that enables you to create bootable media such as a CD, DVD or USB flash drive. Users can boot an infected computer from this recovery medium to both scan and clean the system. The main advantage is that ESET Smart Security can run independent from the host operating system with direct access to the disk and the entire file system, making it possible to remove infiltrations that normally could not be deleted (e.g., when the operating system is running, etc.).

It enables users to diagnose and recover compromised systems more easily. Customers build their own system rescue CDs, which can be used to clean up and repair systems compromised by malware without reimaging the system. Here’s how to create a SysRescue CD together with my simple review on it.
You can either create ESET SysRescue by running the shortcut from Start Menu, or open the main program window. You will have to toggle Advanced mode, go to Tools and then click Create rescue CD in the primary window.
When the ESET SysRescue wizard window appears, click Next. At this time the wizard will try to check if you have Windows AIK (build 6001 or newer) installed on your computer and if not you will have to download a 1.34GB 6001.18000.080118-1840-kb3aikl_en.iso ISO file from the given link. ESET SysRescue makes use of Microsoft Windows Automated Installation Kit (WAIK), a tool to create standalone Preinstallation (PE) versions of Microsoft Windows that can be started from bootable media. WAIK requires that you have Microsoft Windows XP Service Pack 2 or later installed. Due to the support of the 32-bit version of Windows PE, ESET SysRescue must be created in the 32-bit version of ESET Smart Security using WAIK 1.1 and higher. You can refer to yesterday’s article on how to mount the ISO file to a virtual drive and then install Windows AIK.
Once you’ve successfully installed Windows AIK, you can now proceed to creating ESET SysRescue. The next window allows you to select the target where you want SysRescue to be installed. You can create an ISO image of SysRescue, burn it to a CD/DVD or even to a USB drive.

Final screen shows the current settings of SysRescue. If you need to change anything there, just click the Change button. If not, just hit the Create button and you’ll have your ESET SysRescue ready in no time.
SysRescue supports updating of the virus signature database IF your network card works in Windows PE that was created using WAIK. There is no difference in using a USB or CD version of SysRescue because you can’t save or keep the updated virus signature database. Once you shutdown, the signature will be reverted back to the version when you created it and you’ll run the update again with a working ESET username and password the next time you boot up SysRescue.
I ran a full scan on my hard drive and SysRescue took 37 minutes and 3 seconds to scan 300004 objects which is an average of 135 objects per second. I’d say that speed is pretty fast compared to the other 13 rescue disk that I’ve tested. The scan is very thorough as it tries to scan files inside compressed archive and also in setup installers. With the latest virus signature database, it manage to catch and clean ALL 33 virus (Brontok, JambanMu, FUD trojan, FUD Stubs and etc) that I planted in the test computer.
SysRescue is fast, has very good detection, supports online virus signature database update, has a familiar graphical user interface and allows you to create usb/cd/iso version of SysRescue. I am starting to like ESET products. Do take note that SysRescue is ONLY free for licensed users and NOT for everyone although the ISO can be easily found on many warez sites.







