Ransomware : Your Worst Information Technology Nightmare
Crypto-Ransomware  Remediation ConsultantsRansomware has become a modern cyber pandemic that poses an enterprise-level threat for businesses vulnerable to an assault. Different versions of crypto-ransomware such as CrySIS, Fusob, Locky, SamSam and MongoLock cryptoworms have been out in the wild for many years and still cause damage. Modern strains of ransomware such as Ryuk, Maze, Sodinokibi, DopplePaymer, Conti and Nephilim, plus more as yet unnamed malware, not only perform encryption of online critical data but also infect many configured system protection. Information synchronized to cloud environments can also be ransomed. In a vulnerable data protection solution, this can render any recovery hopeless and effectively sets the datacenter back to zero.

Restoring applications and information after a crypto-ransomware attack becomes a sprint against the clock as the targeted business fights to stop the spread, clear the crypto-ransomware, and resume mission-critical operations. Due to the fact that ransomware requires time to spread throughout a network, penetrations are usually launched on weekends, when penetrations may take longer to discover. This multiplies the difficulty of quickly marshalling and organizing a qualified response team.

Progent makes available a range of services for protecting Valencia businesses from ransomware attacks. Among these are team training to become familiar with and not fall victim to phishing attempts, ProSight Active Security Monitoring (ASM) for endpoint detection and response (EDR) using SentinelOne's behavior-based threat defense to detect and suppress zero-day modern malware assaults. Progent in addition can provide the services of experienced ransomware recovery professionals with the talent and perseverance to restore a compromised network as soon as possible.

Progent's Ransomware Recovery Help
Soon after a crypto-ransomware attack, paying the ransom demands in cryptocurrency does not provide any assurance that cyber criminals will respond with the keys to decipher any or all of your data. Kaspersky Labs ascertained that seventeen percent of ransomware victims never recovered their data after having sent off the ransom, resulting in increased losses. The gamble is also costly. Ryuk ransoms are typically several hundred thousand dollars. For larger organizations, the ransom can be in the millions. The other path is to setup from scratch the critical elements of your Information Technology environment. Without access to full information backups, this requires a broad range of IT skills, well-coordinated team management, and the willingness to work 24x7 until the task is finished.

For two decades, Progent has provided certified expert Information Technology services for companies throughout the U.S. and has earned Microsoft's Partnership certification in the Datacenter and Cloud Productivity competencies. Progent's team of subject matter experts includes consultants who have attained top certifications in leading technologies like Microsoft, Cisco, VMware, and popular distributions of Linux. Progent's security consultants have earned internationally-renowned industry certifications including CISM, CISSP-ISSAP, CRISC, GIAC, and CMMC 2.0. (Refer to Progent's certifications). Progent also has experience in financial systems and ERP software solutions. This breadth of experience affords Progent the capability to rapidly ascertain important systems and consolidate the remaining pieces of your Information Technology environment following a ransomware event and rebuild them into an operational network.

Progent's ransomware team uses best of breed project management tools to orchestrate the sophisticated restoration process. Progent understands the urgency of working swiftly and in concert with a client's management and IT team members to assign priority to tasks and to put critical applications back on line as soon as possible.

Customer Case Study: A Successful Crypto-Ransomware Attack Restoration
A customer escalated to Progent after their organization was attacked by Ryuk ransomware. Ryuk is believed to have been developed by North Korean state sponsored criminal gangs, possibly adopting algorithms leaked from America's National Security Agency. Ryuk attacks specific businesses with little ability to sustain operational disruption and is one of the most lucrative incarnations of ransomware. High publicized victims include Data Resolution, a California-based information warehousing and cloud computing business, and the Chicago Tribune. Progent's customer is a regional manufacturer based in Chicago and has around 500 staff members. The Ryuk intrusion had shut down all company operations and manufacturing processes. Most of the client's system backups had been online at the start of the attack and were damaged. The client was taking steps for paying the ransom demand (exceeding $200,000) and wishfully thinking for the best, but in the end made the decision to use Progent.


"I can't say enough about the support Progent gave us during the most fearful period of (our) businesses existence. We most likely would have paid the cyber criminals behind the attack if it wasn't for the confidence the Progent group provided us. That you could get our e-mail system and production applications back online faster than a week was something I thought impossible. Every single staff member I interacted with or texted at Progent was amazingly focused on getting us back on-line and was working breakneck pace to bail us out."

Progent worked hand in hand the customer to quickly get our arms around and prioritize the mission critical areas that needed to be addressed to make it possible to restart company functions:

  • Active Directory
  • Email
  • MRP System
To start, Progent adhered to Anti-virus event response industry best practices by halting lateral movement and cleaning systems of viruses. Progent then began the process of restoring Active Directory, the foundation of enterprise systems built upon Microsoft technology. Exchange email will not work without Active Directory, and the customer's financials and MRP software used SQL Server, which requires Windows AD for security authorization to the database.

In less than 48 hours, Progent was able to rebuild Windows Active Directory to its pre-attack state. Progent then completed rebuilding and storage recovery on critical servers. All Microsoft Exchange Server ties and attributes were usable, which facilitated the restore of Exchange. Progent was also able to assemble intact OST data files (Outlook Email Offline Data Files) on user workstations and laptops to recover mail data. A not too old off-line backup of the businesses accounting software made them able to return these vital applications back online for users. Although a large amount of work remained to recover totally from the Ryuk virus, essential services were restored rapidly:


"For the most part, the production line operation ran fairly normal throughout and we made all customer orders."

Throughout the next month critical milestones in the restoration process were accomplished in close cooperation between Progent team members and the client:

  • Internal web applications were brought back up with no loss of information.
  • The MailStore Microsoft Exchange Server containing more than four million historical emails was restored to operations and available for users.
  • CRM/Customer Orders/Invoicing/Accounts Payable (AP)/Accounts Receivables/Inventory capabilities were fully functional.
  • A new Palo Alto 850 firewall was set up.
  • Ninety percent of the desktop computers were back into operation.

"Much of what occurred in the initial days is mostly a fog for me, but my team will not soon forget the dedication each and every one of your team put in to help get our company back. I have been working together with Progent for the past 10 years, maybe more, and each time I needed help Progent has shined and delivered as promised. This time was a testament to your capabilities."

Conclusion
A likely business catastrophe was dodged with hard-working professionals, a broad spectrum of IT skills, and close teamwork. Although upon completion of forensics the ransomware virus attack described here would have been prevented with advanced cyber security systems and security best practices, user and IT administrator training, and appropriate security procedures for data backup and applying software patches, the reality remains that state-sponsored criminal cyber gangs from China, North Korea and elsewhere are relentless and represent an ongoing threat. If you do fall victim to a ransomware incursion, remember that Progent's team of experts has a proven track record in ransomware virus blocking, removal, and data disaster recovery.


"So, to Darrin, Matt, Dan, Claude, Jesse, Arnaud, Allen, Tony and Chris (and any others who were involved), thank you for making it so I could get rested after we got past the first week. Everyone did an impressive job, and if any of your guys is in the Chicago area, a great meal is the least I can do!"

Download the Crypto-Ransomware Recovery Case Study Datasheet
To read or download a PDF version of this case study, please click:
Progent's Ransomware Virus Recovery Case Study Datasheet. (PDF - 282 KB)

Contact Progent for Ransomware Recovery Consulting Services in Valencia
For ransomware cleanup services in the Valencia area, call Progent at 800-462-8800 or see Contact Progent.


© 2002-2026 Progent Corporation. All rights reserved.