Extract malware defender quarantine files

I haven’t post here from a lonnnng time… And i restart to explain a quick trick.

Few days ago, i search how to extract a malware from a malware defender quarantine files. A friend tell me, it’s encrypted by a RC4 and he give me the key. I have made a script to automatise that: MalwareDefenderDecrypter

The output is quite dirty, there is some bytes (probably headers) to remove until the MZ.

I have also add a kaspersky script decoder

Leave a Reply

Your email address will not be published. Required fields are marked *

You may use these HTML tags and attributes: <a href="" title=""> <abbr title=""> <acronym title=""> <b> <blockquote cite=""> <cite> <code> <del datetime=""> <em> <i> <q cite=""> <strike> <strong>