Ransomware : Your Worst IT Disaster
Ransomware  Recovery ExpertsRansomware has become an escalating cyber pandemic that represents an enterprise-level danger for businesses unprepared for an assault. Different iterations of ransomware such as Dharma, WannaCry, Locky, Syskey and MongoLock cryptoworms have been circulating for many years and still cause harm. More recent versions of ransomware like Ryuk, Maze, Sodinokibi, Netwalker, Conti and Egregor, plus additional unnamed newcomers, not only perform encryption of on-line data but also infect any accessible system backups. Files synched to cloud environments can also be rendered useless. In a poorly architected data protection solution, this can make any recovery hopeless and basically sets the entire system back to square one.

Getting back online applications and data following a ransomware event becomes a race against time as the targeted organization tries its best to contain the damage, eradicate the virus, and restore enterprise-critical operations. Since crypto-ransomware requires time to replicate throughout a network, assaults are frequently sprung during nights and weekends, when penetrations tend to take more time to discover. This multiplies the difficulty of promptly assembling and organizing an experienced mitigation team.

Progent has a range of services for securing Addison businesses from ransomware attacks. Among these are team training to help recognize and not fall victim to phishing attempts, ProSight Active Security Monitoring for endpoint detection and response utilizing SentinelOne's behavior-based cyberthreat protection to detect and extinguish day-zero modern malware attacks. Progent in addition offers the services of experienced crypto-ransomware recovery professionals with the track record and commitment to rebuild a compromised network as urgently as possible.

Progent's Crypto-Ransomware Recovery Help
Following a ransomware invasion, even paying the ransom demands in cryptocurrency does not guarantee that distant criminals will return the needed codes to decrypt any or all of your data. Kaspersky Labs ascertained that seventeen percent of crypto-ransomware victims never restored their files even after having paid the ransom, resulting in additional losses. The risk is also costly. Ryuk ransoms are commonly a few hundred thousand dollars. For larger organizations, the ransom demand can reach millions. The alternative is to setup from scratch the critical parts of your IT environment. Absent access to full system backups, this calls for a wide range of skills, top notch team management, and the capability to work 24x7 until the task is done.

For twenty years, Progent has offered certified expert Information Technology services for businesses throughout the United States and has achieved Microsoft's Partnership certification status in the Datacenter and Cloud Productivity competencies. Progent's pool of subject matter experts (SMEs) includes engineers who have earned top industry certifications in important technologies like Microsoft, Cisco, VMware, and major distributions of Linux. Progent's cyber security specialists have earned internationally-recognized industry certifications including CISA, CISSP, CRISC, GIAC, and CMMC 2.0. (Visit Progent's certifications). Progent in addition has expertise with financial management and ERP application software. This breadth of expertise gives Progent the capability to rapidly understand critical systems and organize the surviving parts of your computer network system after a ransomware attack and rebuild them into a functioning network.

Progent's security team of experts has best of breed project management tools to orchestrate the sophisticated recovery process. Progent understands the urgency of working swiftly and in unison with a client's management and IT team members to prioritize tasks and to put key services back on line as soon as humanly possible.

Customer Story: A Successful Ransomware Virus Restoration
A customer contacted Progent after their network system was brought down by Ryuk ransomware. Ryuk is believed to have been launched by North Korean state hackers, suspected of using algorithms exposed from the U.S. NSA organization. Ryuk seeks specific companies with little ability to sustain operational disruption and is one of the most profitable instances of ransomware malware. Well Known organizations include Data Resolution, a California-based data warehousing and cloud computing firm, and the Chicago Tribune. Progent's customer is a small manufacturing company based in Chicago with about 500 staff members. The Ryuk intrusion had brought down all essential operations and manufacturing capabilities. Most of the client's data protection had been online at the beginning of the intrusion and were eventually encrypted. The client was evaluating paying the ransom demand (more than $200,000) and praying for the best, but ultimately made the decision to use Progent.


"I cannot thank you enough about the support Progent gave us during the most stressful period of (our) businesses survival. We would have paid the cyber criminals behind the attack if it wasn't for the confidence the Progent experts gave us. That you were able to get our e-mail and key applications back online in less than seven days was earth shattering. Every single staff member I worked with or texted at Progent was amazingly focused on getting us operational and was working breakneck pace on our behalf."

Progent worked together with the client to quickly get our arms around and assign priority to the mission critical services that had to be addressed to make it possible to restart company operations:

  • Active Directory (AD)
  • Microsoft Exchange Email
  • Accounting and Manufacturing Software
To begin, Progent adhered to Anti-virus penetration response industry best practices by halting the spread and clearing up compromised systems. Progent then started the work of restoring Windows Active Directory, the key technology of enterprise systems built upon Microsoft Windows technology. Microsoft Exchange email will not work without Windows AD, and the businesses' financials and MRP software utilized SQL Server, which requires Windows AD for access to the data.

In less than 48 hours, Progent was able to recover Windows Active Directory to its pre-intrusion state. Progent then initiated setup and hard drive recovery on mission critical systems. All Exchange Server ties and attributes were intact, which facilitated the rebuild of Exchange. Progent was able to collect intact OST files (Outlook Email Off-Line Folder Files) on various workstations in order to recover email data. A not too old offline backup of the businesses accounting/MRP systems made it possible to return these vital programs back online for users. Although significant work still had to be done to recover fully from the Ryuk event, essential systems were recovered rapidly:


"For the most part, the production line operation ran fairly normal throughout and we did not miss any customer sales."

Over the next couple of weeks key milestones in the recovery process were made in close collaboration between Progent engineers and the customer:

  • In-house web applications were restored without losing any data.
  • The MailStore Exchange Server exceeding four million historical messages was restored to operations and accessible to users.
  • CRM/Customer Orders/Invoices/AP/AR/Inventory modules were 100 percent recovered.
  • A new Palo Alto Networks 850 security appliance was installed.
  • Nearly all of the user workstations were functioning as before the incident.

"A huge amount of what was accomplished those first few days is nearly entirely a haze for me, but my management will not forget the urgency each of you put in to help get our business back. I have trusted Progent for the past ten years, possibly more, and every time I needed help Progent has impressed me and delivered as promised. This time was a life saver."

Conclusion
A possible business extinction disaster was averted by hard-working experts, a wide array of subject matter expertise, and close collaboration. Although upon completion of forensics the ransomware virus attack detailed here should have been shut down with up-to-date security systems and NIST Cybersecurity Framework best practices, staff education, and well designed incident response procedures for data protection and proper patching controls, the fact is that state-sponsored hackers from Russia, China and elsewhere are relentless and are not going away. If you do fall victim to a ransomware attack, feel confident that Progent's team of professionals has substantial experience in ransomware virus defense, remediation, and information systems recovery.


"So, to Darrin, Matt, Aaron, Dan, Claude, Jesse, Tony and Chris (along with others who were helping), thanks very much for allowing me to get rested after we got through the initial fire. All of you did an incredible effort, and if any of your team is around the Chicago area, a great meal is the least I can do!"

Download the Ransomware Removal Case Study Datasheet
To read or download a PDF version of this customer story, click:
Progent's Ryuk Virus Recovery Case Study Datasheet. (PDF - 282 KB)

Contact Progent for Ransomware Recovery Services in Addison
For ransomware cleanup consulting services in the Addison metro area, phone Progent at 800-462-8800 or go to Contact Progent.


© 2002-2026 Progent Corporation. All rights reserved.