Ransomware : Your Worst Information Technology Disaster
Ransomware  Remediation ConsultantsRansomware has become an escalating cyber pandemic that represents an enterprise-level danger for businesses of all sizes vulnerable to an assault. Different iterations of crypto-ransomware like the CrySIS, Fusob, Locky, SamSam and MongoLock cryptoworms have been running rampant for years and continue to cause damage. More recent strains of ransomware like Ryuk, Maze, Sodinokibi, Netwalker, LockBit and Nephilim, as well as more as yet unnamed viruses, not only encrypt on-line critical data but also infiltrate any accessible system protection mechanisms. Information synchronized to the cloud can also be ransomed. In a poorly designed environment, this can render automatic restore operations impossible and basically knocks the entire system back to zero.

Recovering programs and information following a ransomware intrusion becomes a race against time as the targeted organization struggles to stop lateral movement, remove the crypto-ransomware, and resume enterprise-critical operations. Since ransomware requires time to move laterally throughout a network, penetrations are often launched on weekends and holidays, when penetrations in many cases take more time to discover. This compounds the difficulty of promptly assembling and orchestrating a knowledgeable mitigation team.

Progent has a range of solutions for securing Greensboro enterprises from ransomware events. Among these are user education to become familiar with and avoid phishing attempts, ProSight Active Security Monitoring (ASM) for endpoint detection and response using SentinelOne's AI-based cyberthreat protection to detect and extinguish day-zero modern malware assaults. Progent also provides the assistance of veteran ransomware recovery consultants with the track record and commitment to re-deploy a compromised system as soon as possible.

Progent's Crypto-Ransomware Restoration Help
Soon after a ransomware invasion, even paying the ransom in cryptocurrency does not guarantee that merciless criminals will return the codes to unencrypt any of your files. Kaspersky Labs determined that seventeen percent of ransomware victims never restored their files after having paid the ransom, resulting in increased losses. The gamble is also very costly. Ryuk ransoms are commonly several hundred thousand dollars. For larger enterprises, the ransom demand can reach millions. The other path is to re-install the critical parts of your Information Technology environment. Absent the availability of full system backups, this calls for a broad range of IT skills, well-coordinated team management, and the ability to work continuously until the job is finished.

For two decades, Progent has provided expert IT services for businesses across the US and has earned Microsoft's Partnership certification in the Datacenter and Cloud Productivity competencies. Progent's pool of subject matter experts includes consultants who have been awarded advanced certifications in important technologies such as Microsoft, Cisco, VMware, and popular distributions of Linux. Progent's cybersecurity specialists have earned internationally-recognized certifications including CISM, CISSP-ISSAP, ISACA CRISC, SANS GIAC, and CMMC 2.0. (Visit Progent's certifications). Progent in addition has expertise with accounting and ERP software solutions. This breadth of experience provides Progent the ability to efficiently ascertain critical systems and consolidate the surviving pieces of your network system following a crypto-ransomware penetration and configure them into a functioning system.

Progent's recovery team of experts uses best of breed project management systems to orchestrate the complicated restoration process. Progent appreciates the importance of acting quickly and together with a client's management and IT resources to assign priority to tasks and to put critical applications back on line as soon as possible.

Client Case Study: A Successful Ransomware Virus Restoration
A small business sought out Progent after their network was penetrated by the Ryuk ransomware. Ryuk is generally considered to have been deployed by North Korean state hackers, suspected of adopting techniques leaked from the United States NSA organization. Ryuk attacks specific businesses with little or no tolerance for operational disruption and is among the most lucrative instances of ransomware. Well Known victims include Data Resolution, a California-based information warehousing and cloud computing business, and the Chicago Tribune. Progent's customer is a single-location manufacturing business located in Chicago and has about 500 workers. The Ryuk intrusion had shut down all business operations and manufacturing capabilities. Most of the client's data protection had been on-line at the start of the attack and were destroyed. The client was actively seeking loans for paying the ransom demand (more than $200K) and wishfully thinking for good luck, but ultimately brought in Progent.


"I cannot say enough in regards to the expertise Progent gave us during the most critical period of (our) businesses existence. We had little choice but to pay the criminal gangs except for the confidence the Progent team afforded us. The fact that you were able to get our messaging and important applications back on-line in less than one week was earth shattering. Each expert I worked with or e-mailed at Progent was urgently focused on getting my company operational and was working 24/7 on our behalf."

Progent worked with the customer to rapidly understand and prioritize the mission critical areas that had to be restored to make it possible to resume departmental operations:

  • Active Directory (AD)
  • E-Mail
  • Accounting/MRP
To begin, Progent followed Anti-virus penetration mitigation industry best practices by halting lateral movement and removing active viruses. Progent then began the work of bringing back online Microsoft AD, the core of enterprise networks built on Microsoft technology. Exchange messaging will not work without Active Directory, and the customer's accounting and MRP software utilized Microsoft SQL Server, which depends on Windows AD for access to the databases.

Within 2 days, Progent was able to re-build Active Directory to its pre-attack state. Progent then assisted with setup and storage recovery of the most important servers. All Microsoft Exchange Server data and attributes were usable, which greatly helped the rebuild of Exchange. Progent was also able to assemble local OST files (Outlook Email Offline Folder Files) on team desktop computers to recover email messages. A recent off-line backup of the businesses accounting/MRP software made them able to restore these vital programs back on-line. Although a large amount of work still had to be done to recover completely from the Ryuk damage, the most important systems were recovered quickly:


"For the most part, the assembly line operation ran fairly normal throughout and we made all customer deliverables."

Throughout the next couple of weeks critical milestones in the restoration process were completed through close collaboration between Progent team members and the client:

  • In-house web sites were returned to operation with no loss of information.
  • The MailStore Exchange Server containing more than 4 million historical messages was restored to operations and available for users.
  • CRM/Orders/Invoicing/AP/AR/Inventory functions were 100% operational.
  • A new Palo Alto 850 firewall was deployed.
  • Most of the user desktops were functioning as before the incident.

"So much of what went on those first few days is nearly entirely a blur for me, but our team will not soon forget the countless hours each and every one of you accomplished to help get our company back. I've trusted Progent for the past ten years, possibly more, and every time Progent has shined and delivered as promised. This event was a stunning achievement."

Conclusion
A probable business extinction catastrophe was avoided by dedicated professionals, a broad range of subject matter expertise, and close collaboration. Although upon completion of forensics the ransomware virus incident described here should have been disabled with modern cyber security solutions and best practices, staff education, and well designed security procedures for information backup and applying software patches, the fact is that state-sponsored cyber criminals from China, Russia, North Korea and elsewhere are relentless and are not going away. If you do fall victim to a crypto-ransomware penetration, feel confident that Progent's roster of experts has proven experience in crypto-ransomware virus blocking, cleanup, and information systems restoration.


"So, to Darrin, Matt, Aaron, Dan, Claude, Jesse, Arnaud, Allen, Tony and Chris (and any others that were contributing), I'm grateful for allowing me to get some sleep after we made it past the initial push. All of you did an impressive effort, and if anyone is visiting the Chicago area, dinner is on me!"

Download the Crypto-Ransomware Removal Case Study Datasheet
To review or download a PDF version of this ransomware incident report, please click:
Progent's Ransomware Recovery Case Study Datasheet. (PDF - 282 KB)

Contact Progent for Ransomware Cleanup Expertise in Greensboro
For ransomware recovery consulting in the Greensboro metro area, call Progent at 800-462-8800 or visit Contact Progent.


© 2002-2026 Progent Corporation. All rights reserved.