Ransomware : Your Worst Information Technology Nightmare
Ransomware  Recovery ExpertsRansomware has become a modern cyber pandemic that presents an extinction-level threat for organizations poorly prepared for an assault. Different iterations of crypto-ransomware such as CrySIS, Fusob, Bad Rabbit, NotPetya and MongoLock cryptoworms have been running rampant for years and continue to inflict damage. More recent versions of ransomware such as Ryuk, Maze, Sodinokibi, Netwalker, Conti and Nephilim, plus more unnamed viruses, not only perform encryption of online data files but also infect any available system backups. Files synchronized to off-premises disaster recovery sites can also be ransomed. In a vulnerable environment, this can render automated restoration useless and effectively knocks the entire system back to zero.

Getting back on-line programs and information following a crypto-ransomware outage becomes a race against the clock as the targeted business tries its best to stop the spread, cleanup the virus, and restore business-critical operations. Due to the fact that crypto-ransomware requires time to spread throughout a targeted network, assaults are usually sprung during weekends and nights, when successful attacks tend to take more time to discover. This compounds the difficulty of rapidly marshalling and orchestrating a capable mitigation team.

Progent has an assortment of help services for protecting Uniondale enterprises from ransomware penetrations. Among these are team member training to become familiar with and avoid phishing scams, ProSight Active Security Monitoring for endpoint detection and response (EDR) utilizing SentinelOne's AI-based threat protection to identify and suppress zero-day modern malware assaults. Progent in addition provides the assistance of expert crypto-ransomware recovery engineers with the skills and perseverance to reconstruct a breached environment as quickly as possible.

Progent's Ransomware Recovery Support Services
Following a crypto-ransomware event, even paying the ransom in cryptocurrency does not provide any assurance that merciless criminals will provide the needed keys to decrypt any of your information. Kaspersky ascertained that seventeen percent of ransomware victims never recovered their data after having sent off the ransom, resulting in more losses. The gamble is also costly. Ryuk ransoms are often several hundred thousand dollars. For larger organizations, the ransom can reach millions. The fallback is to setup from scratch the essential components of your Information Technology environment. Without access to complete data backups, this requires a broad complement of IT skills, top notch team management, and the ability to work continuously until the job is over.

For two decades, Progent has made available certified expert IT services for companies throughout the U.S. and has earned Microsoft's Partnership certification status in the Datacenter and Cloud Productivity competencies. Progent's pool of subject matter experts includes consultants who have been awarded top certifications in leading technologies like Microsoft, Cisco, VMware, and popular distributions of Linux. Progent's security experts have garnered internationally-recognized certifications including CISM, CISSP, CRISC, GIAC, and CMMC 2.0. (Refer to Progent's certifications). Progent in addition has expertise in accounting and ERP software solutions. This breadth of experience gives Progent the ability to quickly understand critical systems and re-organize the surviving parts of your network environment following a ransomware penetration and assemble them into an operational network.

Progent's ransomware team deploys powerful project management systems to orchestrate the sophisticated restoration process. Progent appreciates the urgency of acting quickly and in unison with a client's management and Information Technology resources to prioritize tasks and to put the most important systems back on-line as fast as possible.

Client Case Study: A Successful Ransomware Intrusion Restoration
A customer engaged Progent after their organization was crashed by the Ryuk ransomware. Ryuk is generally considered to have been created by North Korean government sponsored hackers, possibly using approaches leaked from the United States NSA organization. Ryuk goes after specific companies with little ability to sustain operational disruption and is among the most profitable instances of ransomware malware. Major victims include Data Resolution, a California-based data warehousing and cloud computing business, and the Chicago Tribune. Progent's client is a small manufacturer headquartered in Chicago and has about 500 staff members. The Ryuk penetration had frozen all business operations and manufacturing processes. Most of the client's information backups had been on-line at the beginning of the intrusion and were damaged. The client was evaluating paying the ransom (exceeding $200,000) and wishfully thinking for the best, but in the end brought in Progent.


"I can't tell you enough about the care Progent provided us throughout the most stressful period of (our) company's existence. We had little choice but to pay the hackers behind this attack if not for the confidence the Progent team provided us. The fact that you could get our e-mail and important applications back into operation sooner than seven days was amazing. Every single expert I worked with or texted at Progent was urgently focused on getting my company operational and was working all day and night to bail us out."

Progent worked together with the customer to rapidly determine and prioritize the most important areas that needed to be recovered in order to restart departmental functions:

  • Active Directory (AD)
  • Microsoft Exchange Email
  • MRP System
To begin, Progent followed ransomware event mitigation best practices by halting the spread and clearing infected systems. Progent then initiated the process of restoring Microsoft Active Directory, the key technology of enterprise systems built upon Microsoft Windows Server technology. Exchange email will not operate without Windows AD, and the businesses' MRP applications used Microsoft SQL Server, which needs Active Directory services for security authorization to the database.

Within 2 days, Progent was able to re-build Active Directory to its pre-virus state. Progent then charged ahead with setup and hard drive recovery on mission critical applications. All Microsoft Exchange Server schema and attributes were intact, which greatly helped the rebuild of Exchange. Progent was able to collect local OST files (Outlook Email Off-Line Data Files) on staff workstations and laptops in order to recover email information. A not too old off-line backup of the customer's financials/MRP systems made it possible to restore these vital programs back available to users. Although a lot of work still had to be done to recover totally from the Ryuk virus, critical services were returned to operations rapidly:


"For the most part, the production manufacturing operation showed little impact and we did not miss any customer sales."

During the following couple of weeks key milestones in the recovery project were achieved through close cooperation between Progent engineers and the client:

  • Self-hosted web applications were restored without losing any information.
  • The MailStore Exchange Server exceeding four million archived messages was brought on-line and available for users.
  • CRM/Orders/Invoices/Accounts Payable (AP)/AR/Inventory Control functions were fully functional.
  • A new Palo Alto 850 security appliance was set up.
  • Ninety percent of the user PCs were operational.

"So much of what was accomplished in the initial days is nearly entirely a blur for me, but my management will not forget the commitment all of the team accomplished to help get our company back. I've trusted Progent for the past ten years, possibly more, and each time I needed help Progent has outperformed my expectations and delivered. This time was the most impressive ever."

Conclusion
A likely business-killing catastrophe was avoided with hard-working professionals, a wide range of subject matter expertise, and tight teamwork. Although in analyzing the event afterwards the ransomware penetration detailed here should have been disabled with advanced cyber security technology solutions and ISO/IEC 27001 best practices, team education, and appropriate security procedures for data backup and keeping systems up to date with security patches, the reality is that state-sponsored criminal cyber gangs from Russia, North Korea and elsewhere are tireless and represent an ongoing threat. If you do get hit by a ransomware penetration, feel confident that Progent's roster of experts has extensive experience in crypto-ransomware virus defense, removal, and data recovery.


"So, to Darrin, Aaron, Dan, Claude, Jesse, Arnaud, Allen, Tony and Chris (and any others that were helping), thank you for allowing me to get some sleep after we got past the initial fire. Everyone did an amazing job, and if anyone is visiting the Chicago area, a great meal is the least I can do!"

Download the Ransomware Remediation Case Study Datasheet
To review or download a PDF version of this case study, click:
Progent's Crypto-Ransomware Recovery Case Study Datasheet. (PDF - 282 KB)

Contact Progent for Ransomware System Restoration Services in Uniondale
For ransomware cleanup consulting in the Uniondale metro area, call Progent at 800-462-8800 or go to Contact Progent.


© 2002-2026 Progent Corporation. All rights reserved.