How to Work with Files Quarantined by Trend Micro OfficeScan
If Trend Micro OfficeScan for Windows pops up an alert window during normal use of your computer, indicating that it has quarantined a virus file, you can decide later how to deal with the infected file. NCSU's version of OfficeScan places quarantined virus-infected files in the C:\TMQuarantine folder on your computer's hard drive.
OfficeScan stores quarantined files in an encrypted format, so the files cannot be opened and used. Additional documentation on recovering quarantined files is available from Trend Micro's eSupport website.
Learn more about:
How to view or delete quarantined files
- Open your Start menu and click on the Computer icon. For Windows XP users, this icon will be titled My Computer.
- Your Computer window will list the drives in your computer. Double-click on your C: drive.
- In your C: drive, you will see a list of folders. Locate and double-click on the folder titled TMQuarantine.

- In the TMQuarantine folder, you will see a listing of all the files that OfficeScan's real-time virus scanner has detected and placed in quarantine. The filenames are not changed by OfficeScan.

- In almost all cases, the files placed in quarantine by OfficeScan are files that cannot be cleaned of viruses, and should be deleted. To delete the infected files in your TMQuarantine folder, simply highlight them and press Delete.
- Close the window.
How to recover a file from quarantine
Note: Do NOT perform this procedure unless you are certain that the file you are recovering from quarantine is not a virus.
- Open your web browser and download the VSEncode utility (ZIP format):
http://www.ncsu.edu/antivirus/files/VSEncode.zipNote: You will need to log in with your Unity ID and password.
- Close your web browser.
- Locate where you saved the VSEncode.zip file and copy it to the C:\TMQuarantine folder.

- Extract the contents of VSEncode.zip. It should contain two files:
- VSEncode.exe
- VSAPI32.DLL
If they extract into a VSEncode folder, copy these two files in to your C:\TMQuarantine folder.
- Look in the C:\TMQuarantine folder and find the name of the file that you wish to remove from quarantine. Take note of the filename; you will need it later. Leave the C:\TMQuarantine window open.
- Open a Command Prompt window:
- Windows Vista: Open the Start menu, click in the Start Search box, type "cmd" and press Enter.
- Windows XP: Open the Start menu, click Run. In the Run box, type "cmd" and press Enter.
- The Command Prompt window will open. Type "cd C:\TMQuarantine" and press Enter.

- Type the following command:
- vsencode -d /f filename
- Replace filename with the actual name of the file you wish to recover.
- VSEncode will decrypt the file.
- If the decryption was successful, you can return to the C:\TMQuarantine window and move your move your file to another location on your computer. You should now be able to open the file.
- Close the C:\TMQuarantine and Command Prompt windows.
If you have problems while performing these steps, contact the NC State Help Desk for assistance.
Orig. Posted: Tue, 01/06/2009 - 14:57 — helee2.ncsu.edu Last Modified: Thu, 01/08/2009 - 21:01
