Skip to main content
Question

VBK head encrypted by ransomware (first 1 MB) — storage version error, VBM intact, body readable — how to rebuild?

  • October 3, 2026
  • 11 comments
  • 109 views

Всем привет,

Наш файл резервной копии Veeam Agent был частично зашифрован программой-вымогателем. Процесс шифрования был прерван, и затронута только первая часть файла (1 МБ).

Подробности:
- Файл: dm-1c2 - 192.168.10.x.vbk, ~630 ГБ
- Ошибка при монтировании: "Не удалось создать резервную копию источника монтирования. Версия хранилища [...] не поддерживается для доступа только для чтения" — заголовок некорректен.
- vbkview завершается с ошибкой "недопустимое максимальное количество банков слота снимка".
- Шифрование резервной копии (пароль репозитория) НЕ было включено.
- Файл метаданных .vbm полностью цел и доступен для чтения (XML, версия 2626).
- Критические идентификаторы: Идентификатор резервной копии = 508d4cc8-d124-4053-b6fb-b4a5190445c6, Идентификатор задания = d0d61837-77e6-4b8b-8319-fc6a449901db, Имя задания = dm-1c2, Тип задания = 12000 (Агент Veeam).
- Шестнадцатеричный анализ подтверждает: все данные, начиная со смещения 1 048 576, целы — нули, стандартные индексные структуры, строки ASCII (Veeam, NTFS, пути к файлам) и сжатые данные. Каждый сектор размером менее 1 МБ содержит случайные данные с высокой энтропией.
- Конец файла (конец файла) цел.

Вопросы:
1. Существует ли поддерживаемая процедура восстановления заголовка хранилища VBK из неповрежденных метаданных VBM и собственных структур трейлера/ролла резервной копии?
2. Можно ли использовать V&R или vbkview для восстановления/заглушки заголовка?
3. Сочтет ли служба поддержки Veeam (или лаборатория по восстановлению данных) это восстановимым? Потеря данных из-за отсутствия 1 МБ, по-видимому, касается только метаданных, а не данных виртуальной машины.

Запущен агент Veeam для Microsoft Windows, целевой объект = хранилище резервных копий по умолчанию.

Спасибо
 

11 comments

Chris.Childerhose
Forum|alt.badge.img+23

Please ensure to make posts on the community in English as a first point.

You should contact support for this as they will have the people and tools to hopefully help you out.  I would not know how to answer or give good advice here since ransomware is involved.


  • Author
  • New Here
  • October 3, 2026

Hi everyone,

Our Veeam Agent backup file was partially encrypted by ransomware. The encryption was interrupted, and only the first 1 MB of the file is affected.

Details:
- File: dm-1c2 - 192.168.10.x.vbk, ~630 GB
- Error on mount: "Failed to create backup mount source. Storage version [...] is not supported for read-only access" — the header is garbage.
- vbkview fails with "invalid snapshot slot max banks".
- Backup encryption (repository password) was NOT enabled.
- The .vbm metadata file is fully intact and readable (XML, Version 2626).
- Critical IDs: Backup Id = 508d4cc8-d124-4053-b6fb-b4a5190445c6, JobId = d0d61837-77e6-4b8b-8319-fc6a449901db, JobName = dm-1c2, JobType = 12000 (Veeam Agent).
- Hex analysis confirms: everything from offset 1,048,576 onward is intact — zeros, regular index structures, ASCII strings (Veeam, NTFS, file paths), and compressed data. Below 1 MB every sector is random high-entropy data.
- Storage trailer (end of file) is intact.

Questions:
1. Is there a supported procedure to rebuild the storage header of the VBK from the intact VBM metadata and the backup's own trailer/rollup structures?
2. Can V&R or vbkview be pointed at a repaired/stubbed header?
3. Would Veeam support (or a data recovery lab) consider this recoverable? Data loss from the missing 1 MB appears to be metadata only, not VM data.

Running Veeam Agent for Microsoft Windows, target = Default Backup Repository.

Thanks in advance,
[Твой ник]
 


  • Author
  • New Here
  • October 3, 2026

Storage trailer (end of file) is intact — the last ~164 KB contain the OibSummary XML rollup (Storage Id, Point Num=360, block size parameters, OIB details).
 


  • Author
  • New Here
  • October 3, 2026

  • Author
  • New Here
  • October 3, 2026

Verification done: the VBK tail rollup (last ~164 KB) contains a complete OibSummary 
XML block, and all its key IDs match the intact VBM metadata:
- Backup Id: 508d4cc8-d124-4053-b6fb-b4a5190445c6 (present in VBM)
- JobId: d0d61837-77e6-4b8b-8319-fc6a449901db (present in VBM)
- Storage Id: 819910a4-f3ee-4035-9830-3f8413779020 (present in VBM)
- Point Id: e956af3e-6932-489e-9e66-a33de7736ec1, Num=360 (present in VBM)
- OIB Id: a7db3549-c3c9-4e7b-a739-4d4a842b23be (present in VBM)
- ParentBackupId: d90e608e-9b50-483f-8005-ff484a95ea03 (present in VBM)
Storage parameters from the rollup: BlockSize=KbBlockSize1024, 
BlockAlignmentSize=65536, EncryptionState=0, ApproxSize=1050930719744.
Only the first 1,048,576 bytes of the VBK are encrypted; the VBM, the file body 
and the OibSummary trailer are fully intact and cross-verified.
 


Chris.Childerhose
Forum|alt.badge.img+23

This community page is not support you need to open a support ticket on the Veeam website.  No one here can assist with this issue and it is better you speak to support.


  • New Here
  • October 4, 2026

I have the decryptor sent to me by the attacker; it decrypted the files that had their extensions changed, but the .vbk file didn't have its extension changed, and the decryptor isn't fixing it.


Chris.Childerhose
Forum|alt.badge.img+23

​@trofim15 - again contact support no one in the community can help with this.


  • New Here
  • October 4, 2026

I reached out, but no one has replied yet. I was told online that I might be able to get help here.


Chris.Childerhose
Forum|alt.badge.img+23

Not really as this is just a community and you need technical support to help with this issue.


Forum|alt.badge.img+3
  • Veeam Product Management
  • October 5, 2026

I reached out, but no one has replied yet. I was told online that I might be able to get help here.

Hi Trofim, 

I wrote you from our RND forums but as I see posts here, will share the same information, but in short if you have backup files affected by a Ransomware Attack, always start with a Support Case

Veeam Support has some limited ability to assist on such items, but we cannot always guarantee recovery / full rebuild. Each case will need to be reviewed by Support, and there is internal tooling that has some potential to help recover corrupted / encrypted headers.

But again I must stress that we cannot guarantee recovery in all situations

So please continue with Support; if you have concerns on the case handling / processing, use the Talk to a Manager button from the case portal to contact Support Management.