Forensic Software: Data carving a malware file from vmdk unallocated space

Hi Forensic Focus, I am currently investigating a vmdk image. This machine has been infected by a malware that deleted the MBR and partitions which makes the machine no longer bootable. I am currently trying to extract a deleted file from the unallocated space which I suspect to be the malware file (I’m pretty sure it is).

Article Link: http://www.forensicfocus.com/Forums/viewtopic/p=6587021/#6587021