With all the outbreaks of RansomWare where an application is launched on a PC causing all user data (images and documents) to be encrypted including traversing shared folders to encrypt data on other systems it seems the Trend Micro Worry Free Business Security agent is now a little paranoid of any application capable of “unauthorized encryption”.  A client contacted us recently because Excel.exe had mysteriously disappeared from the system.

Trend Micro WFBS is usually so good at successfully finding the malware I discovered that I haven’t needed to restore a quarantined file in a long time and didn’t know how.

The process is pretty simple:

  • Open a CMD prompt (elevate to Administrator if needed)
  • Navigate to %programfiles%Trend MicroClient Sever Security AgentVSE
  • type in: vsencode.exe /u

A GUI will open displaying all currently quarantined files.  Select the file you want to restore and click on RESTORE.  It should attempt to drop the file where it originally took it from.

reference:

http://docs.trendmicro.com/all/smb/wfbs-s/v9.0/en-us/wfbs_9.0_olhsrv/restore_encrypted_agent.html