Ransomware : Your Crippling IT Catastrophe
Crypto-Ransomware  Recovery ExpertsCrypto-Ransomware has become a too-frequent cyberplague that represents an enterprise-level threat for businesses of all sizes vulnerable to an assault. Versions of ransomware like the Dharma, CryptoWall, Locky, NotPetya and MongoLock cryptoworms have been replicating for a long time and still inflict harm. Newer strains of ransomware such as Ryuk, Maze, Sodinokibi, DopplePaymer, Snatch and Egregor, plus daily as yet unnamed malware, not only encrypt on-line critical data but also infect any accessible system protection mechanisms. Files synched to off-premises disaster recovery sites can also be encrypted. In a vulnerable system, this can make any restoration hopeless and basically knocks the datacenter back to square one.

Getting back on-line programs and information after a crypto-ransomware outage becomes a race against the clock as the targeted organization tries its best to stop lateral movement, cleanup the crypto-ransomware, and restore business-critical operations. Due to the fact that crypto-ransomware requires time to replicate throughout a targeted network, assaults are frequently sprung during weekends and nights, when penetrations typically take more time to notice. This compounds the difficulty of rapidly assembling and coordinating a knowledgeable response team.

Progent has a range of services for securing Richmond organizations from ransomware penetrations. Among these are staff training to help recognize and avoid phishing attempts, ProSight Active Security Monitoring for endpoint detection and response (EDR) utilizing SentinelOne's behavior-based cyberthreat defense to detect and quarantine day-zero malware assaults. Progent also provides the services of veteran ransomware recovery engineers with the talent and commitment to rebuild a compromised network as rapidly as possible.

Progent's Ransomware Recovery Services
After a ransomware attack, sending the ransom in cryptocurrency does not ensure that cyber criminals will respond with the codes to decrypt all your files. Kaspersky Labs determined that 17% of crypto-ransomware victims never restored their data after having sent off the ransom, resulting in additional losses. The gamble is also costly. Ryuk ransoms are often a few hundred thousand dollars. For larger organizations, the ransom can reach millions of dollars. The fallback is to setup from scratch the key components of your IT environment. Absent the availability of essential information backups, this requires a broad range of skill sets, professional team management, and the ability to work non-stop until the task is finished.

For two decades, Progent has offered certified expert Information Technology services for businesses throughout the US and has achieved Microsoft's Partnership certification in the Datacenter and Cloud Productivity competencies. Progent's pool of subject matter experts includes engineers who have attained top industry certifications in foundation technologies including Microsoft, Cisco, VMware, and major distributions of Linux. Progent's cybersecurity specialists have earned internationally-recognized certifications including CISM, CISSP-ISSAP, CRISC, SANS GIAC, and CMMC 2.0. (Refer to Progent's certifications). Progent also has expertise in financial systems and ERP applications. This breadth of experience provides Progent the ability to quickly understand important systems and re-organize the remaining components of your IT system following a ransomware attack and assemble them into an operational network.

Progent's security team of experts has state-of-the-art project management systems to coordinate the complex restoration process. Progent understands the importance of working rapidly and together with a customer's management and IT resources to prioritize tasks and to get the most important systems back online as fast as humanly possible.

Case Study: A Successful Ransomware Virus Restoration
A customer hired Progent after their company was taken over by Ryuk ransomware. Ryuk is believed to have been deployed by North Korean state hackers, suspected of using techniques exposed from the U.S. NSA organization. Ryuk seeks specific businesses with little tolerance for operational disruption and is among the most profitable instances of ransomware. Headline organizations include Data Resolution, a California-based information warehousing and cloud computing business, and the Chicago Tribune. Progent's client is a small manufacturing business headquartered in Chicago with about 500 employees. The Ryuk event had paralyzed all company operations and manufacturing capabilities. Most of the client's data backups had been directly accessible at the beginning of the intrusion and were eventually encrypted. The client was evaluating paying the ransom demand (in excess of $200,000) and praying for good luck, but ultimately called Progent.


"I cannot thank you enough about the help Progent gave us during the most stressful time of (our) company's life. We may have had to pay the cyber criminals behind the attack if it wasn't for the confidence the Progent experts gave us. The fact that you could get our messaging and production applications back into operation quicker than 1 week was something I thought impossible. Every single consultant I spoke to or messaged at Progent was urgently focused on getting us working again and was working 24/7 to bail us out."

Progent worked hand in hand the client to quickly get our arms around and prioritize the most important services that had to be addressed to make it possible to continue business operations:

  • Microsoft Active Directory
  • Microsoft Exchange Email
  • Financials/MRP
To start, Progent followed Anti-virus event mitigation industry best practices by stopping the spread and removing active viruses. Progent then started the process of rebuilding Microsoft AD, the key technology of enterprise environments built upon Microsoft technology. Microsoft Exchange email will not function without AD, and the client's accounting and MRP applications leveraged Microsoft SQL, which needs Active Directory for authentication to the information.

Within 48 hours, Progent was able to restore Active Directory to its pre-attack state. Progent then helped perform reinstallations and hard drive recovery of mission critical applications. All Exchange Server ties and attributes were intact, which facilitated the rebuild of Exchange. Progent was able to locate local OST files (Microsoft Outlook Offline Data Files) on user desktop computers in order to recover mail messages. A not too old off-line backup of the customer's manufacturing systems made it possible to restore these required programs back available to users. Although significant work needed to be completed to recover fully from the Ryuk virus, core systems were recovered rapidly:


"For the most part, the manufacturing operation never missed a beat and we did not miss any customer orders."

Over the following couple of weeks key milestones in the restoration project were completed through tight cooperation between Progent consultants and the client:

  • In-house web applications were brought back up without losing any information.
  • The MailStore Server exceeding four million historical emails was restored to operations and available for users.
  • CRM/Customer Orders/Invoicing/Accounts Payable/Accounts Receivables (AR)/Inventory modules were 100 percent functional.
  • A new Palo Alto Networks 850 security appliance was installed and configured.
  • 90% of the user desktops were fully operational.

"A lot of what went on during the initial response is nearly entirely a blur for me, but my management will not soon forget the commitment each and every one of your team put in to help get our company back. I have trusted Progent for at least 10 years, possibly more, and every time Progent has come through and delivered as promised. This time was a Herculean accomplishment."

Conclusion
A likely business-ending catastrophe was avoided by dedicated professionals, a broad array of knowledge, and tight collaboration. Although in hindsight the ransomware penetration described here would have been blocked with up-to-date security technology and recognized best practices, staff training, and properly executed security procedures for data protection and proper patching controls, the fact remains that government-sponsored criminal cyber gangs from China, North Korea and elsewhere are relentless and represent an ongoing threat. If you do fall victim to a ransomware virus, remember that Progent's team of experts has a proven track record in crypto-ransomware virus defense, cleanup, and information systems disaster recovery.


"So, to Darrin, Matt, Aaron, Claude, Jesse, Arnaud, Allen, Tony and Chris (and any others who were contributing), I'm grateful for letting me get rested after we made it past the first week. Everyone did an impressive job, and if anyone that helped is in the Chicago area, a great meal is on me!"

Download the Crypto-Ransomware Removal Case Study Datasheet
To read or download a PDF version of this customer story, click:
Progent's Ransomware Incident Recovery Case Study Datasheet. (PDF - 282 KB)

Contact Progent for Ransomware Cleanup Consulting in Richmond
For ransomware cleanup services in the Richmond metro area, call Progent at 800-462-8800 or visit Contact Progent.


© 2002-2026 Progent Corporation. All rights reserved.