cisagov / ESXiArgs-Recover

A tool to recover from ESXiArgs ransomware
Creative Commons Zero v1.0 Universal
295 stars 41 forks source link

Even tough the /recover.sh returned success I'm unable to register the VM : No VMs were found in [datastore1] RH_79_template" #11

Open mariosomma opened 1 year ago

mariosomma commented 1 year ago

Hello There,

Applying the /recover.sh RH_79_template, I'm getting the attached result, but I'm still unable to register the VM==> "No VMs were found in [datastore1] RH_79_template"

Should I do something else o in a different way..? Any suggestion, experience to share..

Thx a lot in advance.. Ciao..Mario.

This is what I have in my VM directory:

[esx_server:/vmfs/volumes/5ceff160-7005ea2a-a3f2-ac1f6b0b18f2/RH_79_template] ls -altr total 262146240 -rw-r--r-- 1 root root 446 Jun 22 2021 RH_79_template-774f34e8.hlog -rwxr-xr-x 1 root root 2836 Jul 15 2021 RH_79_template.vmtx drwxr-xr-t 1 root root 81920 Nov 29 08:47 .. drwxr-xr-x 1 root root 73728 Feb 3 10:44 . -rw-r--r-- 1 root root 9 Feb 8 17:05 RH_79_template.vmdk.args -rw-r--r-- 1 root root 17 Feb 8 17:05 RH_79_template-flat.vmdk.args -rw-r--r-- 1 root root 9 Feb 8 17:05 RH_79_template.vmsd.args -rw-r--r-- 1 root root 1024 Feb 8 17:05 RH_79_template.vmsd -rw------- 1 root root 1557 Feb 8 17:05 RH_79_template.vmdk -rw-r--r-- 1 root root 10 Feb 8 17:05 RH_79_template.nvram.args -rw------- 1 root root 9708 Feb 8 17:05 RH_79_template.nvram -rw------- 1 root root 268435457024 Feb 8 18:20 RH_79_template-flat.vmdk

This is the result of /recover.sh RH_79_template ==> "" Copying RH_79_template.vmx mv: can't rename 'RH_79_template.vmx': No such file or directory cp: can't stat 'RH_79_template.vmx~': No such file or directory Error: unable to find vmx backup. You may be unable to re-register the virtual machine. .. .. Validating... Disk chain is consistent.

Success! Unregister the virtual machine and re-register it and you should be good to go. ""\