Ransomware : Your Worst IT Nightmare
Crypto-Ransomware  Recovery ProfessionalsRansomware has become a modern cyberplague that poses an existential danger for businesses of all sizes unprepared for an assault. Multiple generations of ransomware like the Dharma, WannaCry, Locky, Syskey and MongoLock cryptoworms have been running rampant for many years and still inflict harm. Newer versions of ransomware such as Ryuk, Maze, Sodinokibi, DopplePaymer, Conti and Egregor, along with additional unnamed malware, not only encrypt online files but also infect all available system restores and backups. Information replicated to the cloud can also be corrupted. In a poorly designed system, it can render automatic recovery impossible and basically sets the datacenter back to square one.

Restoring programs and data following a crypto-ransomware attack becomes a sprint against the clock as the targeted organization tries its best to stop the spread, remove the virus, and resume mission-critical activity. Because ransomware requires time to replicate across a network, penetrations are often launched at night, when attacks tend to take more time to uncover. This compounds the difficulty of rapidly mobilizing and coordinating a knowledgeable mitigation team.

Progent has a variety of help services for protecting New Orleans businesses from crypto-ransomware penetrations. These include team member training to help identify and avoid phishing attempts, ProSight Active Security Monitoring for endpoint detection and response using SentinelOne's behavior-based threat protection to detect and disable day-zero malware attacks. Progent also can provide the services of experienced ransomware recovery consultants with the talent and commitment to reconstruct a compromised network as soon as possible.

Progent's Ransomware Recovery Services
After a ransomware attack, even paying the ransom demands in cryptocurrency does not provide any assurance that cyber criminals will provide the needed codes to decipher any or all of your information. Kaspersky Labs ascertained that seventeen percent of ransomware victims never recovered their data even after having sent off the ransom, resulting in more losses. The risk is also expensive. Ryuk ransoms are typically a few hundred thousand dollars. For larger organizations, the ransom can reach millions. The alternative is to setup from scratch the mission-critical parts of your Information Technology environment. Absent the availability of essential system backups, this requires a broad range of IT skills, professional team management, and the ability to work 24x7 until the recovery project is over.

For twenty years, Progent has offered expert IT services for businesses throughout the United States and has earned Microsoft's Partnership certification in the Datacenter and Cloud Productivity competencies. Progent's pool of subject matter experts includes professionals who have been awarded advanced industry certifications in foundation technologies like Microsoft, Cisco, VMware, and major distributions of Linux. Progent's cyber security experts have garnered internationally-renowned industry certifications including CISM, CISSP, ISACA CRISC, SANS GIAC, and CMMC 2.0. (Visit Progent's certifications). Progent also has experience in financial systems and ERP application software. This breadth of experience provides Progent the skills to quickly understand critical systems and integrate the surviving parts of your Information Technology system following a crypto-ransomware penetration and rebuild them into a functioning system.

Progent's security team deploys best of breed project management systems to coordinate the complicated restoration process. Progent understands the importance of working rapidly and in concert with a client's management and Information Technology resources to assign priority to tasks and to get the most important applications back on-line as soon as humanly possible.

Client Story: A Successful Ransomware Intrusion Restoration
A customer engaged Progent after their organization was penetrated by the Ryuk ransomware. Ryuk is believed to have been developed by North Korean government sponsored criminal gangs, possibly adopting algorithms exposed from America's National Security Agency. Ryuk attacks specific organizations with little or no tolerance for operational disruption and is among the most profitable instances of ransomware. Well Known targets include Data Resolution, a California-based info warehousing and cloud computing business, and the Chicago Tribune. Progent's client is a small manufacturer located in the Chicago metro area and has around 500 employees. The Ryuk attack had brought down all business operations and manufacturing processes. Most of the client's information backups had been directly accessible at the start of the intrusion and were eventually encrypted. The client was actively seeking loans for paying the ransom (exceeding two hundred thousand dollars) and hoping for good luck, but in the end made the decision to use Progent.


"I cannot say enough about the expertise Progent gave us during the most fearful period of (our) company's survival. We had little choice but to pay the criminal gangs if not for the confidence the Progent group afforded us. The fact that you were able to get our e-mail system and important applications back into operation in less than five days was earth shattering. Each expert I got help from or texted at Progent was laser focused on getting our system up and was working breakneck pace on our behalf."

Progent worked hand in hand the client to rapidly get our arms around and assign priority to the mission critical systems that had to be recovered to make it possible to continue company operations:

  • Windows Active Directory
  • Electronic Messaging
  • MRP System
To get going, Progent followed ransomware event response industry best practices by stopping the spread and cleaning up infected systems. Progent then began the process of rebuilding Microsoft AD, the heart of enterprise networks built upon Microsoft Windows technology. Microsoft Exchange messaging will not operate without Active Directory, and the customer's accounting and MRP system leveraged Microsoft SQL, which needs Windows AD for authentication to the data.

In less than two days, Progent was able to re-build Active Directory to its pre-virus state. Progent then completed reinstallations and hard drive recovery on the most important applications. All Exchange Server schema and attributes were usable, which greatly helped the restore of Exchange. Progent was also able to find intact OST data files (Microsoft Outlook Off-Line Data Files) on staff desktop computers to recover mail data. A not too old offline backup of the client's accounting/ERP systems made them able to recover these essential services back available to users. Although significant work needed to be completed to recover completely from the Ryuk attack, the most important systems were restored rapidly:


"For the most part, the production manufacturing operation ran fairly normal throughout and we made all customer orders."

Throughout the next couple of weeks critical milestones in the recovery project were completed in close cooperation between Progent consultants and the customer:

  • In-house web sites were restored with no loss of data.
  • The MailStore Server containing more than 4 million historical emails was restored to operations and available for users.
  • CRM/Customer Orders/Invoicing/AP/AR/Inventory Control modules were 100% restored.
  • A new Palo Alto 850 firewall was installed.
  • Nearly all of the user desktops and notebooks were functioning as before the incident.

"A huge amount of what went on in the early hours is nearly entirely a haze for me, but my management will not forget the commitment each of the team put in to help get our business back. I've trusted Progent for at least 10 years, possibly more, and every time I needed help Progent has impressed me and delivered. This time was no exception but maybe more Herculean."

Conclusion
A possible business extinction disaster was dodged by top-tier professionals, a broad array of subject matter expertise, and close teamwork. Although in retrospect the ransomware attack described here should have been identified and disabled with up-to-date cyber security solutions and best practices, user and IT administrator education, and well designed security procedures for data protection and keeping systems up to date with security patches, the reality remains that state-sponsored cyber criminals from China, Russia, North Korea and elsewhere are relentless and are not going away. If you do get hit by a crypto-ransomware virus, feel confident that Progent's team of experts has proven experience in ransomware virus defense, removal, and data restoration.


"So, to Darrin, Matt, Aaron, Claude, Jesse, Arnaud, Allen, Tony and Chris (and any others who were helping), thanks very much for making it so I could get rested after we got through the most critical parts. All of you did an fabulous effort, and if anyone is visiting the Chicago area, dinner is on me!"

Download the Crypto-Ransomware Cleanup Case Study Datasheet
To review or download a PDF version of this ransomware incident report, please click:
Progent's Ransomware Recovery Case Study Datasheet. (PDF - 282 KB)

Contact Progent for Ransomware Cleanup Services in New Orleans
For ransomware system restoration consulting services in the New Orleans metro area, call Progent at 800-462-8800 or visit Contact Progent.


© 2002-2026 Progent Corporation. All rights reserved.