I was not able to connect to vCenter Server Appliance, so I restarted it.
After that it showed that it will be renewed ssl certificates because VCSA wasn´t restarted for a long period (more than one year in this case).
Later in console I got stuck on:
Hostname or IP has changed. Regenerating the self-signed certificates. Starting VMware vPostgres: ok Waiting for the embedded database to start up: .[OK]
With Veeam 7/8/9 B&R stop to work if you rename server.
To restore functionality you need to change and analyze these register fields putting new server name. I suggest to eviscerate every single key, could you have more subfolder than in my case HKLM\SOFTWARE\ Veeam\Veeam Backup and Replication\SqlServerName Veeam\Veeam Backup Catalog\CatalogSharedFolderPath
It's important that you will change registry keys that are related to sql istances: \\HKLM\Software\VeeaM\Veeam Backup Catalog\SqlServerName (Should be local) \\HKLM\Software\VeeaM\Veeam Backup Reporting\SqlServerName (Should be local)
Considering that this kind of virus can not be solved with normal AV definition here they are some mitigation approaches: 1. Using a product like Sophos UTM (Unified threat management) 2. Proceed to block these files extension going over extension itself but analyzing file header too (this task should be done from antispam provider/tools)
9. Enabling server auditing on shares and files to quickly identify infection location searching for technet Microsoft article, otherwise there is this script Auditing File Access on File Servers