Decrypting and Restoring Files
- If the file is on the OfficeScan agent endpoint:
- Open a command prompt and go to <Agent installation folder>.
- Run VSEncode.exe by double-clicking the file or by typing the following at
a command prompt:
This parameter opens a screen with a list of files found under <Agent installation folder>\SUSPECT\Backup.
- Select a file to restore and click Restore. The tool can only restore one file at a time.
- In the screen that opens, specify the folder where to restore the file.
- Click Ok. The file is restored
to the specified folder.
It might be possible for OfficeScan to scan the file again and treat it as infected as soon as the file is restored. To prevent the file from being scanned, add it to the scan exclusion list. See Scan Exclusions for details.
- Click Close when you have finished restoring files.
- If the file is on the OfficeScan server
or a custom quarantine directory:
- If the file is on the OfficeScan server computer, open
a command prompt and go to <Server installation folder>\PCCSRV\Admin\Utility\VSEncrypt.
If the file is on a custom quarantine directory, navigate to <Server installation folder>\PCCSRV\Admin\Utility and copy the VSEncrypt folder to the endpoint where the custom quarantine directory is located.
- Create a text file and then type the full path of
the files you want to encrypt or decrypt.
For example, to restore files in C:\My Documents\Reports, type C:\My Documents\Reports\*.* in the text file.
Quarantined files on the OfficeScan server computer are found under <Server installation folder>\PCCSRV\Virus.
- Save the text file with an INI or TXT extension. For example, save it as ForEncryption.ini on the C: drive.
- Open a command prompt and go to the directory where the VSEncrypt folder is located.
- Run VSEncode.exe by typing the
VSEncode.exe /d /i <location of the INI or TXT file>
<location of the INI or TXT file> is the path of the INI or TXT file you created (for example, C:\ForEncryption.ini).
- Use the other parameters to issue various commands.
Table 1. Restore Parameters
None (no parameter)
Create a debug log and save it to the endpoint. On the OfficeScan agent endpoint, the debug log VSEncrypt.log is created in the <Agent installation folder>.
Overwrite an encrypted or decrypted file if it already exists
Encrypt or decrypt a single file
Do not restore the original file name
Display information about the tool
Launch the tool’s user interface
/r <Destination folder>
The folder where a file will be restored
/s <Original file name>
The file name of the original encrypted file
For example, type VSEncode [/d] [/debug] to decrypt files in the Suspect folder and create a debug log. When you decrypt or encrypt a file, OfficeScan creates the decrypted or encrypted file in the same folder. Before decrypting or encrypting a file, ensure that it is not locked.
- If the file is on the OfficeScan server computer, open a command prompt and go to <Server installation folder>\PCCSRV\Admin\Utility\VSEncrypt.