Decrypt Encrypted Quarantine Files

Trend Micro recommends that you have [product] encrypt all quarantine files to prevent accidental "reinfection" or reintroduction of the malware into your network. At times, however, it may be necessary to decrypt an encrypted file.

To decrypt an encrypted quarantine file:

  1. Download the following file: vsencode.zip (see below for the full path) and then extract the contents to the [product] Quarantine directory. The following files appear:

VSEncode.exe
Vsapi32.dll
VSEncode_Readme.txt

  1. Open a command prompt (Windows Start button > Run > cmd) and use DOS commands to change to quarantine directory:

\Program Files\Trend Micro\[product]\Quarantine

  1. Enter the following command at the DOS prompt:

          VSEncode -d

  1. All encrypted files in the quarantine directory will be decrypted and the log, VSEncrypt.log, created in the root directory.

  2. Caution: The decrypted files are likely to be dangerous. Viruses can infect the server. Trojans can drop their payload, worms may propagate, and spyware can open backdoors to the server. Use caution. Delete or re-encrypt the files as soon as possible.

See also

http://solutionfile.trendmicro.com/SolutionFile/11435/en/vsencode.zip