Ransomware : Your Feared Information Technology Nightmare
Crypto-Ransomware  Remediation ProfessionalsRansomware has become an escalating cyber pandemic that presents an existential threat for businesses of all sizes vulnerable to an attack. Versions of ransomware like the Reveton, CryptoWall, Bad Rabbit, SamSam and MongoLock cryptoworms have been around for many years and continue to inflict harm. More recent strains of crypto-ransomware such as Ryuk, Maze, Sodinokibi, DopplePaymer, Snatch and Egregor, along with more unnamed viruses, not only encrypt on-line files but also infiltrate all available system protection mechanisms. Files synched to off-premises disaster recovery sites can also be encrypted. In a poorly designed system, it can make automated recovery useless and basically knocks the entire system back to zero.

Getting back programs and data after a crypto-ransomware intrusion becomes a sprint against time as the victim fights to stop lateral movement, remove the ransomware, and restore enterprise-critical activity. Due to the fact that ransomware requires time to replicate throughout a network, penetrations are usually sprung at night, when attacks are likely to take longer to recognize. This compounds the difficulty of rapidly assembling and organizing a knowledgeable response team.

Progent has an assortment of support services for securing Sherman Oaks organizations from ransomware penetrations. These include team member education to help recognize and avoid phishing scams, ProSight Active Security Monitoring (ASM) for endpoint detection and response (EDR) using SentinelOne's behavior-based threat protection to detect and suppress day-zero modern malware assaults. Progent also offers the services of expert ransomware recovery professionals with the track record and perseverance to reconstruct a breached system as rapidly as possible.

Progent's Ransomware Restoration Support Services
After a crypto-ransomware attack, even paying the ransom in cryptocurrency does not guarantee that cyber hackers will return the needed codes to unencrypt all your information. Kaspersky Labs determined that 17% of ransomware victims never restored their data even after having sent off the ransom, resulting in additional losses. The risk is also expensive. Ryuk ransoms are typically a few hundred thousand dollars. For larger organizations, the ransom demand can reach millions of dollars. The other path is to setup from scratch the vital parts of your IT environment. Absent the availability of essential information backups, this calls for a wide range of IT skills, top notch project management, and the willingness to work continuously until the task is completed.

For decades, Progent has offered professional IT services for businesses across the US and has earned Microsoft's Partnership certification status in the Datacenter and Cloud Productivity competencies. Progent's team of subject matter experts (SMEs) includes engineers who have been awarded high-level certifications in important technologies like Microsoft, Cisco, VMware, and popular distributions of Linux. Progent's cyber security experts have earned internationally-recognized certifications including CISA, CISSP-ISSAP, ISACA CRISC, GIAC, and CMMC 2.0. (See Progent's certifications). Progent in addition has expertise in financial systems and ERP applications. This breadth of expertise gives Progent the skills to quickly identify important systems and re-organize the surviving pieces of your network system after a crypto-ransomware event and assemble them into a functioning system.

Progent's security group deploys powerful project management tools to orchestrate the complicated recovery process. Progent knows the importance of acting rapidly and together with a customer's management and Information Technology staff to prioritize tasks and to get critical services back on-line as fast as humanly possible.

Client Case Study: A Successful Ransomware Attack Recovery
A customer sought out Progent after their network was taken over by the Ryuk crypto-ransomware. Ryuk is thought to have been deployed by North Korean state sponsored hackers, possibly adopting techniques exposed from the United States National Security Agency. Ryuk goes after specific companies with little or no room for operational disruption and is among the most profitable versions of ransomware. Major targets include Data Resolution, a California-based info warehousing and cloud computing firm, and the Chicago Tribune. Progent's customer is a regional manufacturing business headquartered in the Chicago metro area and has around 500 employees. The Ryuk penetration had disabled all business operations and manufacturing capabilities. Most of the client's data protection had been online at the beginning of the attack and were eventually encrypted. The client was pursuing financing for paying the ransom (more than $200,000) and praying for good luck, but in the end made the decision to use Progent.


"I cannot say enough about the care Progent gave us throughout the most critical period of (our) company's life. We had little choice but to pay the Hackers if not for the confidence the Progent experts afforded us. That you could get our messaging and critical servers back into operation in less than five days was beyond my wildest dreams. Each expert I got help from or texted at Progent was totally committed on getting our company operational and was working day and night on our behalf."

Progent worked together with the client to quickly get our arms around and prioritize the critical services that had to be restored to make it possible to resume departmental operations:

  • Active Directory
  • Electronic Messaging
  • Accounting/MRP
To begin, Progent followed AV/Malware Processes incident mitigation best practices by stopping the spread and performing virus removal steps. Progent then began the process of recovering Microsoft AD, the core of enterprise systems built on Microsoft technology. Exchange messaging will not work without Active Directory, and the customer's accounting and MRP software utilized SQL Server, which depends on Windows AD for authentication to the data.

In less than two days, Progent was able to restore Active Directory services to its pre-intrusion state. Progent then charged ahead with reinstallations and hard drive recovery of critical servers. All Exchange Server data and configuration information were usable, which greatly helped the restore of Exchange. Progent was able to find intact OST files (Outlook Email Off-Line Folder Files) on user workstations and laptops in order to recover email information. A not too old offline backup of the businesses manufacturing software made them able to restore these required services back on-line. Although a large amount of work needed to be completed to recover fully from the Ryuk damage, critical services were restored quickly:


"For the most part, the production line operation ran fairly normal throughout and we delivered all customer sales."

During the following month important milestones in the restoration process were accomplished in close collaboration between Progent consultants and the client:

  • Internal web applications were restored without losing any data.
  • The MailStore Server exceeding 4 million archived emails was brought online and available for users.
  • CRM/Orders/Invoicing/Accounts Payable/Accounts Receivables (AR)/Inventory functions were fully recovered.
  • A new Palo Alto Networks 850 firewall was installed.
  • 90% of the user desktops and notebooks were back into operation.

"A huge amount of what happened in the early hours is nearly entirely a blur for me, but I will not forget the care each and every one of you accomplished to give us our company back. I've been working together with Progent for the past 10 years, maybe more, and each time I needed help Progent has come through and delivered. This situation was a testament to your capabilities."

Conclusion
A potential business-ending disaster was avoided with top-tier professionals, a wide range of subject matter expertise, and tight collaboration. Although in post mortem the ransomware virus attack detailed here could have been prevented with advanced security systems and ISO/IEC 27001 best practices, user and IT administrator training, and well thought out security procedures for information backup and applying software patches, the reality is that state-sponsored hackers from China, Russia, North Korea and elsewhere are relentless and will continue. If you do get hit by a ransomware incursion, remember that Progent's team of professionals has a proven track record in ransomware virus defense, cleanup, and file restoration.


"So, to Darrin, Matt, Dan, Claude, Jesse, Arnaud, Allen, Tony and Chris (along with others that were involved), thank you for letting me get rested after we made it over the most critical parts. Everyone did an incredible effort, and if anyone is visiting the Chicago area, a great meal is the least I can do!"

Download the Ransomware Cleanup Case Study Datasheet
To review or download a PDF version of this customer story, click:
Progent's Ryuk Incident Recovery Case Study Datasheet. (PDF - 282 KB)

Contact Progent for Ransomware Recovery Services in Sherman Oaks
For ransomware cleanup services in the Sherman Oaks metro area, call Progent at 800-462-8800 or see Contact Progent.


© 2002-2026 Progent Corporation. All rights reserved.