---
title: "Using the Rescue Disk feature of Portable Inspector"
slug: "using-the-rescue-disk-feature-of-portable-inspector"
description: "SecurityInspection/PortableInspector/ready_to_release/HelpCenter"
tags: ["Portable Inspector", "Portable Inspector Pro"]
updated: 2024-08-15T03:05:44Z
published: 2024-08-15T03:05:44Z
---

> ## Documentation Index
> Fetch the complete documentation index at: https://help.txone.com/llms.txt
> Use this file to discover all available pages before exploring further.

# Using the Rescue Disk feature of Portable Inspector

### **Summary**
* * *
Use the Rescue Disk to examine your endpoint without launching your operating systems. It finds and removes persistent or difficult-to-clean security threats that can lurk deep within your operating system.

Rescue Disk can scan hidden files, system drivers, and the Master Boot Record (MBR) of your endpoint’s hard drive without disturbing the operating system. Rescue Disk does not load potentially-infected system files into memory before trying to remove them.

Take note that by default, Rescue Disk quarantines any detected threats to the local hard drive. If you wish to scan without writing any information to your local hard drive, change the scan action settings to Scan only.

![image.png](https://cdn.document360.io/f5889a21-4b9d-49ff-a4a7-03538c6b843a/Images/Documentation/image%28260%29.png){height="400" width=""}

### **Details**
* * *

Rescue Disk supports the following file systems:
| Operating System | File System |
| --- | --- |
| Windows | NTFS and FAT | 
| Linux | EXT2, EXT3, EXT4 and XFS <br/>Note: Rescue Disk runs on any Linux distribution installed on a supported file system.| 

:::(Info) ( Rescue Disk may encounter this error due to the following configurations/settings. Please ensure to disable the following:)

* Encrypted Disks and Partitions
* SCSI Disks
* Raid Disks
* Windows Fast Boot or Windows Fast Startup
* Secure Boot
* Hibernation

:::

**Follow these steps:**

**Preparation**
1.	Insert the USB device into the endpoint.
2.	Restart the endpoint.
3.	When the endpoint powers up, open the BIOS or UEFI Setup Utility.
4.	Look for Boot, Boot Order, or Boot Options in the menu, and change the First Boot Device to the USB device.
5.	Exit the menu. Rescue Disk will automatically open after restarting.

**Using the Rescue Disk**	

1.	After you have restarted the endpoint, the Rescue Disk console opens automatically.

2.	Press ENTER, or wait for a short while. The Confirm Disk Log window appears.

3.	Select Yes. The Choose Action window appears.

4.	Select [1] Scan for Security Threats, and then select the type of scan:


<div style="margin-left:20px;">
    
*   [1] Quick Scan: Scans only the folders most vulnerable to system threats (such as the Windows System folder)
*  	[2] Full Scan: Scan all folders. 
    
The Rescue Disk automatically starts scanning, and you must wait for the scan to finish. 

:::(Info) (The confirmation message only appears if you have configured the Rescue Disk to:)

* Scan and quarantine objects
* Inform users before the quarantine starts

:::

 </div>
 
5.	If any threats are detected, the message "Are you sure you want to resolve these objects?" appears. Select Yes to remove threats.

6.	After scan logs are saved to the Scanning Tool, confirm the removal of the Scanning Tool from the endpoint.

7.	Press ENTER to restart the endpoint.

 <br/>
 <br/>
 For support assistance, please contact us at <u>support@txone.com </u>or your Support Provider. 
 <br/>
