Ransomware : Your Feared Information Technology Nightmare
Ransomware  Remediation ProfessionalsRansomware has become a too-frequent cyberplague that presents an extinction-level threat for organizations poorly prepared for an attack. Versions of ransomware such as CrySIS, Fusob, Locky, NotPetya and MongoLock cryptoworms have been out in the wild for years and still cause damage. More recent variants of ransomware such as Ryuk, Maze, Sodinokibi, Netwalker, Snatch and Egregor, along with daily as yet unnamed viruses, not only encrypt online critical data but also infect all configured system protection. Files synched to cloud environments can also be encrypted. In a poorly architected environment, it can make any recovery hopeless and basically knocks the entire system back to square one.

Restoring services and information following a crypto-ransomware attack becomes a race against the clock as the targeted business struggles to stop lateral movement, remove the crypto-ransomware, and restore mission-critical activity. Due to the fact that ransomware takes time to replicate across a targeted network, attacks are usually sprung during nights and weekends, when penetrations are likely to take longer to discover. This compounds the difficulty of rapidly marshalling and coordinating a knowledgeable response team.

Progent offers a range of solutions for protecting Rockville businesses from crypto-ransomware penetrations. These include user education to become familiar with and not fall victim to phishing attempts, ProSight Active Security Monitoring (ASM) for endpoint detection and response (EDR) utilizing SentinelOne's AI-based cyberthreat protection to detect and quarantine zero-day malware attacks. Progent also offers the services of experienced crypto-ransomware recovery engineers with the skills and commitment to re-deploy a breached network as rapidly as possible.

Progent's Crypto-Ransomware Restoration Help
Soon after a ransomware invasion, sending the ransom in cryptocurrency does not guarantee that distant criminals will provide the needed keys to unencrypt all your files. Kaspersky estimated that seventeen percent of ransomware victims never recovered their information after having sent off the ransom, resulting in more losses. The risk is also costly. Ryuk ransoms are often several hundred thousand dollars. For larger enterprises, the ransom demand can be in the millions of dollars. The alternative is to setup from scratch the key parts of your Information Technology environment. Absent access to essential information backups, this requires a broad complement of skills, well-coordinated team management, and the ability to work non-stop until the recovery project is complete.

For twenty years, Progent has made available expert IT services for companies throughout the U.S. and has earned Microsoft's Partnership certification in the Datacenter and Cloud Productivity competencies. Progent's group of subject matter experts includes engineers who have earned high-level certifications in foundation technologies such as Microsoft, Cisco, VMware, and major distributions of Linux. Progent's security engineers have earned internationally-renowned certifications including CISM, CISSP, ISACA CRISC, GIAC, and CMMC 2.0. (See Progent's certifications). Progent also has experience in financial management and ERP software solutions. This breadth of expertise affords Progent the skills to rapidly ascertain necessary systems and consolidate the remaining parts of your Information Technology environment following a crypto-ransomware event and rebuild them into an operational network.

Progent's ransomware team of experts deploys best of breed project management systems to orchestrate the complicated restoration process. Progent appreciates the importance of working swiftly and in concert with a client's management and Information Technology staff to assign priority to tasks and to put key applications back on line as fast as humanly possible.

Client Story: A Successful Ransomware Attack Restoration
A client engaged Progent after their network was brought down by Ryuk crypto-ransomware. Ryuk is generally considered to have been created by North Korean state sponsored criminal gangs, suspected of using techniques exposed from the United States NSA organization. Ryuk attacks specific businesses with little room for disruption and is among the most profitable versions of ransomware viruses. Headline victims include Data Resolution, a California-based information warehousing and cloud computing firm, and the Chicago Tribune. Progent's client is a single-location manufacturing business based in the Chicago metro area and has around 500 employees. The Ryuk event had frozen all business operations and manufacturing capabilities. The majority of the client's system backups had been on-line at the time of the attack and were eventually encrypted. The client was evaluating paying the ransom demand (exceeding two hundred thousand dollars) and hoping for the best, but ultimately engaged Progent.


"I cannot speak enough in regards to the support Progent gave us throughout the most fearful period of (our) businesses existence. We most likely would have paid the cyber criminals if not for the confidence the Progent experts provided us. That you could get our messaging and critical applications back in less than five days was earth shattering. Each expert I interacted with or texted at Progent was hell bent on getting our system up and was working 24 by 7 on our behalf."

Progent worked hand in hand the client to quickly identify and assign priority to the most important areas that had to be restored in order to restart business functions:

  • Active Directory (AD)
  • E-Mail
  • Financials/MRP
To begin, Progent adhered to AV/Malware Processes incident mitigation industry best practices by stopping the spread and clearing up compromised systems. Progent then began the task of restoring Microsoft Active Directory, the core of enterprise environments built upon Microsoft Windows Server technology. Exchange messaging will not work without Windows AD, and the businesses' accounting and MRP system utilized SQL Server, which requires Active Directory for security authorization to the databases.

In less than 2 days, Progent was able to rebuild Active Directory to its pre-intrusion state. Progent then helped perform rebuilding and storage recovery on the most important systems. All Microsoft Exchange Server ties and attributes were intact, which facilitated the rebuild of Exchange. Progent was also able to find non-encrypted OST files (Outlook Off-Line Data Files) on staff PCs in order to recover mail messages. A recent off-line backup of the customer's accounting/MRP software made them able to return these essential applications back available to users. Although a large amount of work needed to be completed to recover fully from the Ryuk virus, core systems were recovered rapidly:


"For the most part, the manufacturing operation ran fairly normal throughout and we made all customer deliverables."

During the next couple of weeks key milestones in the restoration process were achieved through tight cooperation between Progent team members and the customer:

  • In-house web sites were returned to operation without losing any data.
  • The MailStore Server exceeding 4 million archived emails was restored to operations and accessible to users.
  • CRM/Product Ordering/Invoices/Accounts Payable/Accounts Receivables/Inventory functions were fully functional.
  • A new Palo Alto 850 firewall was brought on-line.
  • 90% of the desktop computers were being used by staff.

"So much of what occurred that first week is mostly a haze for me, but we will not soon forget the care each of the team accomplished to help get our business back. I have utilized Progent for at least 10 years, possibly more, and each time Progent has outperformed my expectations and delivered as promised. This situation was no exception but maybe more Herculean."

Conclusion
A possible company-ending disaster was evaded through the efforts of results-oriented professionals, a broad spectrum of technical expertise, and tight teamwork. Although in analyzing the event afterwards the crypto-ransomware virus incident detailed here could have been blocked with current security solutions and recognized best practices, team training, and properly executed security procedures for backup and proper patching controls, the fact remains that state-sponsored cyber criminals from China, North Korea and elsewhere are tireless and are not going away. If you do fall victim to a ransomware incident, remember that Progent's team of professionals has a proven track record in ransomware virus blocking, removal, and information systems disaster recovery.


"So, to Darrin, Matt, Aaron, Dan, Jesse, Arnaud, Allen, Tony and Chris (along with others who were helping), I'm grateful for making it so I could get rested after we made it through the first week. Everyone did an amazing effort, and if anyone that helped is around the Chicago area, a great meal is my treat!"

Download the Ransomware Recovery Case Study Datasheet
To read or download a PDF version of this customer story, click:
Progent's Ransomware Recovery Case Study Datasheet. (PDF - 282 KB)

Contact Progent for Ransomware Recovery Services in Rockville
For ransomware recovery consulting services in the Rockville metro area, call Progent at 800-462-8800 or visit Contact Progent.


© 2002-2026 Progent Corporation. All rights reserved.