Ransomware : Your Feared Information Technology Catastrophe
Ransomware  Recovery ExpertsRansomware has become an escalating cyberplague that poses an enterprise-level threat for businesses vulnerable to an attack. Different iterations of ransomware like the Reveton, WannaCry, Bad Rabbit, Syskey and MongoLock cryptoworms have been running rampant for many years and continue to inflict damage. Newer variants of crypto-ransomware like Ryuk, Maze, Sodinokibi, Netwalker, Conti and Egregor, plus frequent unnamed viruses, not only encrypt on-line critical data but also infiltrate most available system backups. Files synched to off-premises disaster recovery sites can also be corrupted. In a poorly architected environment, it can render automated restoration useless and effectively sets the entire system back to zero.

Retrieving programs and data following a crypto-ransomware outage becomes a race against time as the victim tries its best to contain, cleanup the ransomware, and restore business-critical activity. Since ransomware takes time to replicate throughout a network, penetrations are often sprung on weekends and holidays, when attacks are likely to take longer to recognize. This multiplies the difficulty of quickly assembling and organizing a capable mitigation team.

Progent offers a range of services for securing Downers Grove businesses from ransomware events. Among these are user training to become familiar with and not fall victim to phishing scams, ProSight Active Security Monitoring (ASM) for endpoint detection and response using SentinelOne's behavior-based threat protection to detect and disable zero-day modern malware attacks. Progent also offers the assistance of veteran ransomware recovery professionals with the track record and commitment to restore a breached system as quickly as possible.

Progent's Ransomware Restoration Services
Subsequent to a crypto-ransomware penetration, sending the ransom demands in cryptocurrency does not ensure that cyber hackers will return the needed codes to decrypt any or all of your information. Kaspersky estimated that 17% of crypto-ransomware victims never restored their data after having paid the ransom, resulting in increased losses. The risk is also very costly. Ryuk ransoms are typically several hundred thousand dollars. For larger enterprises, the ransom demand can be in the millions of dollars. The other path is to setup from scratch the critical elements of your Information Technology environment. Absent access to essential information backups, this requires a wide range of IT skills, professional team management, and the capability to work 24x7 until the task is complete.

For twenty years, Progent has made available certified expert Information Technology services for businesses across the US and has earned Microsoft's Partnership certification in the Datacenter and Cloud Productivity competencies. Progent's group of subject matter experts (SMEs) includes consultants who have been awarded high-level industry certifications in foundation technologies such as Microsoft, Cisco, VMware, and popular distributions of Linux. Progent's cyber security consultants have earned internationally-renowned certifications including CISA, CISSP, CRISC, GIAC, and CMMC 2.0. (Refer to Progent's certifications). Progent also has expertise in financial management and ERP applications. This breadth of expertise provides Progent the capability to efficiently identify critical systems and integrate the surviving parts of your IT system after a crypto-ransomware attack and rebuild them into an operational system.

Progent's ransomware team deploys best of breed project management applications to orchestrate the complicated restoration process. Progent understands the urgency of working swiftly and in concert with a customer's management and IT team members to assign priority to tasks and to get critical systems back on line as fast as possible.

Client Story: A Successful Ransomware Intrusion Recovery
A client engaged Progent after their network system was penetrated by the Ryuk ransomware. Ryuk is believed to have been developed by North Korean state sponsored cybercriminals, possibly using approaches exposed from the U.S. National Security Agency. Ryuk attacks specific organizations with little tolerance for operational disruption and is one of the most lucrative instances of ransomware. Well Known victims include Data Resolution, a California-based information warehousing and cloud computing firm, and the Chicago Tribune. Progent's customer is a single-location manufacturing business located in the Chicago metro area with about 500 staff members. The Ryuk attack had paralyzed all business operations and manufacturing capabilities. Most of the client's data protection had been online at the beginning of the intrusion and were damaged. The client considered paying the ransom demand (exceeding two hundred thousand dollars) and praying for good luck, but ultimately called Progent.


"I cannot speak enough in regards to the help Progent gave us during the most stressful period of (our) businesses survival. We may have had to pay the cyber criminals if it wasn't for the confidence the Progent experts provided us. The fact that you could get our e-mail and key servers back on-line sooner than one week was something I thought impossible. Every single expert I got help from or texted at Progent was hell bent on getting us back on-line and was working 24 by 7 to bail us out."

Progent worked hand in hand the customer to quickly get our arms around and prioritize the most important areas that had to be restored in order to restart business functions:

  • Active Directory
  • Electronic Mail
  • Financials/MRP
To get going, Progent adhered to Anti-virus event response industry best practices by isolating and cleaning up infected systems. Progent then initiated the steps of recovering Windows Active Directory, the key technology of enterprise environments built upon Microsoft Windows technology. Microsoft Exchange Server messaging will not work without Active Directory, and the client's MRP software leveraged Microsoft SQL, which requires Active Directory for access to the databases.

In less than two days, Progent was able to restore Active Directory services to its pre-penetration state. Progent then performed reinstallations and hard drive recovery on essential systems. All Exchange ties and attributes were intact, which accelerated the restore of Exchange. Progent was also able to assemble local OST files (Outlook Email Offline Data Files) on staff PCs to recover mail information. A not too old offline backup of the client's financials/ERP software made them able to restore these vital programs back servicing users. Although a large amount of work still had to be done to recover completely from the Ryuk event, the most important services were restored quickly:


"For the most part, the production manufacturing operation was never shut down and we delivered all customer deliverables."

During the next couple of weeks important milestones in the recovery process were made in tight cooperation between Progent engineers and the customer:

  • Self-hosted web applications were brought back up without losing any information.
  • The MailStore Exchange Server with over 4 million archived emails was spun up and accessible to users.
  • CRM/Customer Orders/Invoicing/Accounts Payable/AR/Inventory Control functions were fully recovered.
  • A new Palo Alto Networks 850 firewall was brought on-line.
  • Nearly all of the user desktops were fully operational.

"So much of what was accomplished those first few days is nearly entirely a blur for me, but our team will not soon forget the commitment each and every one of you accomplished to give us our company back. I have been working together with Progent for at least 10 years, possibly more, and every time I needed help Progent has outperformed my expectations and delivered as promised. This event was a stunning achievement."

Conclusion
A likely company-ending disaster was dodged with dedicated experts, a wide spectrum of IT skills, and close collaboration. Although in hindsight the ransomware virus penetration detailed here should have been identified and prevented with up-to-date cyber security technology and NIST Cybersecurity Framework best practices, user education, and well thought out security procedures for data backup and applying software patches, the fact remains that state-sponsored cybercriminals from China, North Korea and elsewhere are tireless and are an ongoing threat. If you do get hit by a ransomware incursion, remember that Progent's roster of professionals has a proven track record in ransomware virus defense, cleanup, and information systems recovery.


"So, to Darrin, Matt, Dan, Claude, Jesse, Arnaud, Allen, Tony and Chris (along with others that were involved), I'm grateful for allowing me to get rested after we got through the first week. Everyone did an fabulous effort, and if anyone that helped is in the Chicago area, a great meal is on me!"

Download the Crypto-Ransomware Recovery Case Study Datasheet
To review or download a PDF version of this ransomware incident report, click:
Progent's Ryuk Virus Recovery Case Study Datasheet. (PDF - 282 KB)

Contact Progent for Ransomware System Restoration Consulting Services in Downers Grove
For ransomware system restoration services in the Downers Grove metro area, call Progent at 800-462-8800 or go to Contact Progent.


© 2002-2026 Progent Corporation. All rights reserved.