Hello all,
This is a weird situation. A couple months ago, we had a production system issue and we used Veeam’s instant recovery to bring a database server back online. Being a small IT shop, once the server was up and available we transitioned to user support and long story short, we never finalized the restore and moved to production. Fast forward a couple of months and we were hit by a ransomware attack and all of our VM files (.vmdk, .vmx etc) have been encrypted. We were able to find a snapshot of our storage that seems to be intact from a few days before the attack, but the actual files in that snapshot for this particular server do not boot, which is what it did to trigger the instant recovery months ago.
My question is, where would this VM have been running? Is there a hope of it also being on the snapshot somewhere? We do not have a well-versed Veeam person on staff, our entire IT department has been here a maximum of 4 years and none of us were involved in the deployment of this system. We also currently do not have any of our account information to log in and open a support case.